Compare commits

...
Sign in to create a new pull request.

9 commits

Author SHA1 Message Date
Yaakov Selkowitz
a09115fad0 Enable argon2 only in Fedora
libsodium is not included in RHEL, nor is openldap-servers shipped.
2026-01-14 14:38:58 -05:00
Simon Pichugin
24f6f7ee20 Bump version 2.6.10-5
Resolves: rhbz#2167213
Resolves: FC-2548
2026-01-12 19:35:28 -08:00
Viktor Ashirov
d2ffb52585 Add support for argon2
Resolves: rhbz#2167213
2025-10-15 13:17:44 +02:00
Simon Pichugin
96644176b3 Fix LDAP initialization does unnecessary resolution of hostname
Resolves: rhbz#2331728
2025-08-29 17:10:05 -07:00
Viktor Ashirov
b6036115c7 Convert STI tests to FMF
Resolves: rhbz#2382998 openldap: STI tests will no longer be run in F43
2025-08-28 13:23:51 +02:00
Fedora Release Engineering
529c3466fb Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-24 23:37:09 +00:00
Jitka Plesnikova
0b7f700e16 Perl 5.42 rebuild 2025-07-07 16:19:49 +02:00
Simon Pichugin
51354adeb8 Rebase to version 2.6.10
Resolves: rhbz#2368103
2025-06-10 15:35:35 -07:00
Zbigniew Jędrzejewski-Szmek
4335fd4745 Drop call to %sysusers_create_compat
After https://fedoraproject.org/wiki/Changes/RPMSuportForSystemdSysusers,
rpm will handle account creation automatically.
2025-02-11 17:44:44 +01:00
11 changed files with 240 additions and 111 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

1
.gitignore vendored
View file

@ -41,3 +41,4 @@
/openldap-2.6.7.tgz
/openldap-2.6.8.tgz
/openldap-2.6.9.tgz
/openldap-2.6.10.tgz

View file

@ -0,0 +1,120 @@
From 606349836109cfb201bc5b5b424dffb749150a68 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Ond=C5=99ej=20Kuzn=C3=ADk?= <ondra@mistotebe.net>
Date: Mon, 28 Apr 2025 14:36:24 +0100
Subject: [PATCH] ITS#10297 Defer hostname resolution til first use
---
libraries/libldap/init.c | 33 +++++++++++++++++++--------------
libraries/libldap/ldap-int.h | 1 +
libraries/libldap/os-ip.c | 2 ++
libraries/libldap/tls_g.c | 3 +++
libraries/libldap/tls_o.c | 3 +++
6 files changed, 28 insertions(+), 14 deletions(-)
diff --git a/libraries/libldap/init.c b/libraries/libldap/init.c
index 213276b4b5..90fc34c5a6 100644
--- a/libraries/libldap/init.c
+++ b/libraries/libldap/init.c
@@ -631,6 +631,25 @@ void ldap_int_initialize_global_options( struct ldapoptions *gopts, int *dbglvl
#if defined(HAVE_TLS) || defined(HAVE_CYRUS_SASL)
char * ldap_int_hostname = NULL;
+
+void
+ldap_int_resolve_hostname(void)
+{
+ static int resolved = 0;
+
+ LDAP_MUTEX_LOCK( &ldap_int_hostname_mutex );
+ if ( !resolved ) {
+ char *name = ldap_int_hostname;
+
+ ldap_int_hostname = ldap_pvt_get_fqdn( name );
+
+ if ( name != NULL && name != ldap_int_hostname ) {
+ LDAP_FREE( name );
+ }
+ resolved = 1;
+ }
+ LDAP_MUTEX_UNLOCK( &ldap_int_hostname_mutex );
+}
#endif
#ifdef LDAP_R_COMPILE
@@ -688,20 +707,6 @@ void ldap_int_initialize( struct ldapoptions *gopts, int *dbglvl )
}
#endif
-#if defined(HAVE_TLS) || defined(HAVE_CYRUS_SASL)
- LDAP_MUTEX_LOCK( &ldap_int_hostname_mutex );
- {
- char *name = ldap_int_hostname;
-
- ldap_int_hostname = ldap_pvt_get_fqdn( name );
-
- if ( name != NULL && name != ldap_int_hostname ) {
- LDAP_FREE( name );
- }
- }
- LDAP_MUTEX_UNLOCK( &ldap_int_hostname_mutex );
-#endif
-
#ifndef HAVE_POLL
if ( ldap_int_tblsize == 0 ) ldap_int_ip_init();
#endif
diff --git a/libraries/libldap/ldap-int.h b/libraries/libldap/ldap-int.h
index 7e754775e8..435b859066 100644
--- a/libraries/libldap/ldap-int.h
+++ b/libraries/libldap/ldap-int.h
@@ -743,6 +743,7 @@ LDAP_F (int) ldap_int_poll( LDAP *ld, ber_socket_t s,
#if defined(HAVE_TLS) || defined(HAVE_CYRUS_SASL)
LDAP_V (char *) ldap_int_hostname;
+LDAP_F (void) ldap_int_resolve_hostname(void);
LDAP_F (char *) ldap_host_connected_to( Sockbuf *sb,
const char *host );
#endif
diff --git a/libraries/libldap/os-ip.c b/libraries/libldap/os-ip.c
index 6c86edd055..629b540352 100644
--- a/libraries/libldap/os-ip.c
+++ b/libraries/libldap/os-ip.c
@@ -890,6 +890,8 @@ ldap_host_connected_to( Sockbuf *sb, const char *host )
* this is necessary for kerberos to work right, since the official
* hostname is used as the kerberos instance.
*/
+ if ( !ldap_int_hostname )
+ ldap_int_resolve_hostname();
switch (sa->sa_family) {
#ifdef LDAP_PF_LOCAL
diff --git a/libraries/libldap/tls_g.c b/libraries/libldap/tls_g.c
index de5b7f7c84..d4e7ee0bf7 100644
--- a/libraries/libldap/tls_g.c
+++ b/libraries/libldap/tls_g.c
@@ -597,6 +597,9 @@ tlsg_session_chkhost( LDAP *ld, tls_session *session, const char *name_in )
int len1 = 0, len2 = 0;
int ntype = IS_DNS;
+ if ( !ldap_int_hostname )
+ ldap_int_resolve_hostname();
+
if( ldap_int_hostname &&
( !name_in || !strcasecmp( name_in, "localhost" ) ) )
{
diff --git a/libraries/libldap/tls_o.c b/libraries/libldap/tls_o.c
index 71677847a9..155f685c99 100644
--- a/libraries/libldap/tls_o.c
+++ b/libraries/libldap/tls_o.c
@@ -830,6 +830,9 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
struct in_addr addr;
#endif
+ if ( !ldap_int_hostname )
+ ldap_int_resolve_hostname();
+
if( ldap_int_hostname &&
( !name_in || !strcasecmp( name_in, "localhost" ) ) )
{
--
GitLab

View file

@ -1,35 +1,20 @@
Various manual pages changes:
* removes LIBEXECDIR from slapd.8
* removes references to non-existing manpages (bz 624616)
diff --git a/doc/man/man1/ldapmodify.1 b/doc/man/man1/ldapmodify.1
index 353b075..cf37856 100644
--- a/doc/man/man1/ldapmodify.1
+++ b/doc/man/man1/ldapmodify.1
@@ -382,8 +382,7 @@ exit status and a diagnostic message being written to standard error.
.BR ldap_add_ext (3),
.BR ldap_delete_ext (3),
.BR ldap_modify_ext (3),
-.BR ldap_modrdn_ext (3),
-.BR ldif (5).
+.BR ldif (5)
.SH AUTHOR
The OpenLDAP Project <http://www.openldap.org/>
.SH ACKNOWLEDGEMENTS
diff --git a/doc/man/man5/ldap.conf.5 b/doc/man/man5/ldap.conf.5
index 17b7154..6084298 100644
index d47481d6ed..ff86fc52ca 100644
--- a/doc/man/man5/ldap.conf.5
+++ b/doc/man/man5/ldap.conf.5
@@ -338,6 +338,7 @@ certificates in separate individual files. The
@@ -341,6 +341,7 @@ be specified, separated by a semi-colon. The
.B TLS_CACERT
is always used before
.B TLS_CACERTDIR.
.BR TLS_CACERTDIR .
+The specified directory must be managed with the OpenSSL c_rehash utility.
.TP
.B TLS_CERT <filename>
Specifies the file that contains the client certificate.
diff --git a/doc/man/man8/slapd.8 b/doc/man/man8/slapd.8
index 8504b37..f02f1fa 100644
index 807634e52d..a06110687b 100644
--- a/doc/man/man8/slapd.8
+++ b/doc/man/man8/slapd.8
@@ -5,7 +5,7 @@
@ -41,16 +26,16 @@ index 8504b37..f02f1fa 100644
[\c
.BR \-V [ V [ V ]]
[\c
@@ -332,7 +332,7 @@ the LDAP databases defined in the default config file, just type:
@@ -333,7 +333,7 @@ the LDAP databases defined in the default config file, just type:
.LP
.nf
.ft tt
- LIBEXECDIR/slapd
+ slapd
+ slapd
.ft
.fi
.LP
@@ -343,7 +343,7 @@ on voluminous debugging which will be printed on standard error, type:
@@ -344,7 +344,7 @@ on voluminous debugging which will be printed on standard error, type:
.LP
.nf
.ft tt
@ -59,7 +44,7 @@ index 8504b37..f02f1fa 100644
.ft
.fi
.LP
@@ -351,7 +351,7 @@ To test whether the configuration file is correct or not, type:
@@ -352,7 +352,7 @@ To test whether the configuration file is correct or not, type:
.LP
.nf
.ft tt

View file

@ -9,6 +9,9 @@
# Build openldap-servers package and its libslapi in openldap-devel and openldap-compat
%bcond servers 1
# Build with argon2 support
%bcond argon2 %{undefined rhel}
# When you change "Version: " to the new major version, remember to change this value too
%global major_version 2.6
@ -16,8 +19,8 @@
%global __brp_remove_la_files %nil
Name: openldap
Version: 2.6.9
Release: 4%{?dist}
Version: 2.6.10
Release: 6%{?dist}
Summary: LDAP support libraries
License: OLDAP-2.8
URL: http://www.openldap.org/
@ -50,6 +53,7 @@ Patch6: openldap-switch-to-lt_dlopenadvise-to-get-RTLD_GLOBAL-set.patch
Patch7: openldap-openssl-manpage-defaultCA.patch
Patch8: openldap-add-export-symbols-LDAP_CONNECTIONLESS.patch
Patch9: openldap-libldap-avoid-SSL-context-cleanup-during-library-des.patch
Patch10: openldap-ITS-10297-Defer-hostname-resolution-til-first-use.patch
# check-password module specific patches
Patch90: check-password-makefile.patch
@ -73,7 +77,9 @@ BuildRequires: unixODBC-devel
BuildRequires: cracklib-devel
BuildRequires: systemd
BuildRequires: systemd-rpm-macros
%{?sysusers_requires_compat}
%if %{with argon2}
BuildRequires: libsodium-devel
%endif
%description
OpenLDAP is an open source suite of LDAP (Lightweight Directory Access
@ -132,7 +138,6 @@ and are available for compatibility reasons.
Summary: LDAP server
Requires: openldap%{?_isa} = %{version}-%{release}
%{?systemd_requires}
Requires(pre): shadow-utils
# migrationtools (slapadd functionality):
Provides: ldif2ldbm
@ -172,6 +177,7 @@ pushd openldap-%{version}
%patch -P7 -p1
%patch -P8 -p1
%patch -P9 -p1
%patch -P10 -p1
# build smbk5pwd with other overlays
ln -s ../../../contrib/slapd-modules/smbk5pwd/smbk5pwd.c servers/slapd/overlays
@ -221,6 +227,9 @@ pushd openldap-%{version}
--enable-rlookups \
%if %{with servers}
--enable-slapi \
%if %{with argon2}
--enable-argon2 \
%endif
%endif
--disable-slp \
\
@ -393,10 +402,6 @@ rm %{buildroot}%{_libdir}/*.la # because we do not want files in %{_libdir}/ope
%ldconfig_scriptlets
%if %{with servers}
%pre servers
# create ldap user and group
# sysusers.d format https://fedoraproject.org/wiki/Changes/Adopting_sysusers.d_format
%sysusers_create_compat %{SOURCE6}
%post servers
%systemd_post slapd.service
@ -464,6 +469,12 @@ exit 0
%{_datadir}/openldap-servers/
%{_libdir}/openldap/accesslog*
%{_libdir}/openldap/allop*
%if %{with argon2}
%{_libdir}/openldap/argon2*
%{_mandir}/man5/slappw-argon2.5*
%else
%exclude %{_mandir}/man5/slappw-argon2.5*
%endif
%{_libdir}/openldap/auditlog*
%{_libdir}/openldap/autoca*
%{_libdir}/openldap/back_asyncmeta*
@ -506,7 +517,6 @@ exit 0
%{_mandir}/man8/lloadd.8*
%{_mandir}/man5/slapd*.5*
%{_mandir}/man5/slapo-*.5*
%{_mandir}/man5/slappw-argon2.5*
%{_mandir}/man8/slap*.8*
%{_sysusersdir}/openldap.conf
# obsolete configuration
@ -555,6 +565,29 @@ exit 0
%endif
%changelog
* Wed Jan 14 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 2.6.10-6
- Enable argon2 only in Fedora
* Tue Jan 13 2026 Simon Pichugin <spichugi@redhat.com> - 2.6.10-5
- Add support for argon2 (rhbz#2229405)
- Bump version 2.6.10-5
* Fri Aug 29 2025 Simon Pichugin <spichugi@redhat.com> - 2.6.10-4
- Fix LDAP initialization does unnecessary resolution of hostname (rhbz#2331728)
- Convert STI tests to FMF (rhbz#2382998)
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2.6.10-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 07 2025 Jitka Plesnikova <jplesnik@redhat.com> - 2.6.10-2
- Perl 5.42 rebuild
* Tue Jun 10 2025 Simon Pichugin <spichugi@redhat.com> - 2.6.10-1
- Rebase to version 2.6.10 (rhbz#2368103)
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 2.6.9-5
- Drop call to %sysusers_create_compat
* Sat Feb 01 2025 Björn Esser <besser82@fedoraproject.org> - 2.6.9-4
- Add explicit BR: libxcrypt-devel

8
plans/gating.fmf Normal file
View file

@ -0,0 +1,8 @@
summary: Test plan for openldap
discover:
how: fmf
execute:
how: tmt

View file

@ -1,2 +1,2 @@
SHA512 (openldap-ppolicy-check-password-1.1.tar.gz) = a92854d7438cb95fac361da80a49d084d502155e8ce0ad2ea679db9529bbe0182aa4354e6139793c775e496349375d8f017678941d23315ff1c20fefc9573cdc
SHA512 (openldap-2.6.9.tgz) = d3f839d3cf1030caa410e54f968e9c0caf3bc371c06ea0f64cf3a6ece6d31013c9dbfb08a3a63ea9137a2062aa6edc6e0bc542b365fe4ad66608df4cdbe94a4e
SHA512 (openldap-2.6.10.tgz) = 18129ad9a385457941e3203de5f130fe2571701abf24592c5beffb01361aae3182c196b2cd48ffeecb792b9b0e5f82c8d92445a7ec63819084757bdedba63b20

View file

@ -46,7 +46,7 @@ clean:
include /usr/share/rhts/lib/rhts-make.include
$(METADATA): Makefile
@echo "Owner: Ondrej Moris <omoris@redhat.com>" > $(METADATA)
@echo "Owner: Viktor Ashirov <vashirov@redhat.com>" > $(METADATA)
@echo "Name: $(TEST)" >> $(METADATA)
@echo "TestVersion: $(TESTVERSION)" >> $(METADATA)
@echo "Path: $(TEST_DIR)" >> $(METADATA)
@ -57,25 +57,23 @@ $(METADATA): Makefile
@echo "Requires: openldap" >> $(METADATA)
@echo "Requires: openldap-clients" >> $(METADATA)
@echo "Requires: openldap-servers" >> $(METADATA)
@echo "Requires: nss-devel" >> $(METADATA)
@echo "Requires: cracklib-devel" >> $(METADATA)
@echo "Requires: cyrus-sasl-devel" >> $(METADATA)
@echo "Requires: gdbm-devel" >> $(METADATA)
@echo "Requires: libtool" >> $(METADATA)
@echo "Requires: groff" >> $(METADATA)
@echo "Requires: krb5-devel" >> $(METADATA)
@echo "Requires: libdb-devel" >> $(METADATA)
@echo "Requires: libtool" >> $(METADATA)
@echo "Requires: libtool-ltdl-devel" >> $(METADATA)
@echo "Requires: nfs-utils" >> $(METADATA)
@echo "Requires: openssl-devel" >> $(METADATA)
@echo "Requires: pam-devel" >> $(METADATA)
@echo "Requires: perl" >> $(METADATA)
@echo "Requires: pkgconfig" >> $(METADATA)
@echo "Requires: tcp_wrappers-devel" >> $(METADATA)
@echo "Requires: bind-libbind-devel" >> $(METADATA)
@echo "Requires: unixODBC-devel" >> $(METADATA)
@echo "Requires: libtool-ltdl-devel" >> $(METADATA)
@echo "Requires: nfs-utils" >> $(METADATA)
@echo "Requires: rpm-build" >> $(METADATA)
@echo "Requires: nss-devel" >> $(METADATA)
@echo "Requires: libdb-devel" >> $(METADATA)
@echo "Requires: groff" >> $(METADATA)
@echo "Requires: cracklib-devel" >> $(METADATA)
@echo "Requires: perl-ExtUtils-Embed" >> $(METADATA)
@echo "Requires: pkgconfig" >> $(METADATA)
@echo "Requires: rpm-build" >> $(METADATA)
@echo "Requires: unixODBC-devel" >> $(METADATA)
@echo "Requires: yum-utils" >> $(METADATA)
@echo "Priority: Normal" >> $(METADATA)
@echo "License: GPLv2" >> $(METADATA)

31
tests/smoke-test/main.fmf Normal file
View file

@ -0,0 +1,31 @@
summary: Test calls upstream test suite
description: Test calls upstream test suite
contact: Viktor Ashirov <vashirov@redhat.com>
component:
- openldap
test: ./runtest.sh
framework: beakerlib
recommend:
- openldap
- openldap-clients
- openldap-servers
- cracklib-devel
- cyrus-sasl-devel
- gdbm-devel
- groff
- krb5-devel
- libdb-devel
- libtool
- libtool-ltdl-devel
- nfs-utils
- nss-devel
- openssl-devel
- pam-devel
- perl
- perl-ExtUtils-Embed
- pkgconf-pkg-config
- pkgconfig
- rpm-build
- unixODBC-devel
- yum-utils
duration: 3h

View file

@ -27,7 +27,6 @@
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# Include rhts environment
. /usr/bin/rhts-environment.sh
. /usr/share/beakerlib/beakerlib.sh || exit 1
PACKAGE="openldap"
@ -45,58 +44,46 @@ PACKAGES=("openldap" \
"unixODBC-devel" \
"libtool-ltdl-devel" \
"nfs-utils" \
"rpm-build" )
"rpm-build" \
"nss-devel" \
"libdb-devel" \
"groff" \
"cracklib-devel" \
"perl-ExtUtils-Embed"\
"pkgconf-pkg-config" )
if rlIsRHEL 5; then
PACKAGES=( ${PACKAGES[@]} "bind-libbind-devel" )
elif rlIsRHEL 6; then
PACKAGES=( ${PACKAGES[@]} "tcp_wrappers-devel" )
else
PACKAGES=( ${PACKAGES[@]} "tcp_wrappers-devel" "nss-devel" "libdb-devel" "groff" "cracklib-devel" "perl-ExtUtils-Embed" )
fi
if rlIsFedora; then
PACKAGES=( ${PACKAGES[@]} "pkgconf-pkg-config" )
else
PACKAGES=( ${PACKAGES[@]} "pkgconfig" )
fi
if rlIsRHEL 5; then
LDAP_SERVICE='ldap'
else
LDAP_SERVICE='slapd'
fi
LDAP_SERVICE='slapd'
rlJournalStart
rlPhaseStartSetup "General Setup"
rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"
rlRun "TmpDir=$(mktemp -d)" 0 "Creating tmp directory"
rlRun "pushd $TmpDir"
for P in "${PACKAGES[@]}"; do rlCheckRpm $P || rlDie; done
rlFetchSrcForInstalled $PACKAGE
rlRun "yum-builddep -y openldap*src.rpm" 0
rlRun "rpm -ihv *.rpm" 0
rlServiceStop $LDAP_SERVICE
rlServiceStop $LDAP_SERVICE
rlPhaseEnd
rlPhaseStartTest
TOPDIR=`rpm --eval %_topdir`
TOPDIR=$(rpm --eval %_topdir)
rlRun "pushd $TOPDIR" 0
rlRun "rpmbuild -vv -bc SPECS/openldap.spec >build.log 2>&1" 0
[[ $? -ne 0 ]] && cat build.log
VERSION=`rpm -q --qf "%{VERSION}\n" openldap | tail -1`
rlRun "pushd BUILD/openldap-${VERSION}/openldap-${VERSION}" 0
VERSION=$(rpm -q --qf "%{VERSION}\n" openldap | tail -1)
rlRun "pushd BUILD/openldap-${VERSION}-build/openldap-${VERSION}/openldap-${VERSION}" 0
# workaround for failing test, it tests unsupported configuration
# see http://www.openldap.org/lists/openldap-technical/201204/msg00080.html for upstream reply
# change of check after test is not enough because run of all tests with hdb is skipped if test058 fails with bdb
rm -f tests/scripts/test058-syncrepl-asymmetric
rlIsRHEL 5 6 && rlRun "pushd build-servers" 0
#rm -f tests/scripts/test058-syncrepl-asymmetric
rlRun "make check > make_check.out 2>&1" 0
@ -107,15 +94,14 @@ rlJournalStart
rlAssertNotGrep "failed" make_check.results
rlIsRHEL 5 6 && rlRun "popd" 0
rlRun "popd" 0
rlRun "popd" 0
rlPhaseEnd
rlPhaseStartCleanup
rlServiceRestore $LDAP_SERVICE
rlRun "rm -rf BUILD/opendap-`rpm -q --qf "%{VERSION}" openldap`" 0
rlServiceRestore $LDAP_SERVICE
rlRun "rm -rf BUILD/opendap-$(rpm -q --qf "%{VERSION}" openldap)" 0
rlRun "popd"
rlRun "rm -r $TmpDir" 0 "Removing tmp directory"

View file

@ -1,34 +0,0 @@
---
# Tests that run in all contexts
- hosts: localhost
roles:
- role: standard-test-beakerlib
tags:
- classic
tests:
- smoke-test
required_packages:
- openldap # Required for smoke-test
- openldap-clients # Required for smoke-test
- openldap-servers # Required for smoke-test
- cyrus-sasl-devel # Required for smoke-test
- gdbm-devel # Required for smoke-test
- libtool # Required for smoke-test
- krb5-devel # Required for smoke-test
- openssl-devel # Required for smoke-test
- pam-devel # Required for smoke-test
- perl # Required for smoke-test
- pkgconfig # Required for smoke-test
- tcp_wrappers-devel # Required for smoke-test
- bind-libbind-devel # Required for smoke-test
- unixODBC-devel # Required for smoke-test
- nfs-utils # Required for smoke-test
- rpm-build # Required for smoke-test
- nss-devel # Required for smoke-test
- libdb-devel # Required for smoke-test
- groff # Required for smoke-test
- cracklib-devel # Required for smoke-test
- perl-ExtUtils-Embed # Required for smoke-test
- yum-utils # Required for smoke-test
- libtool-ltdl-devel # Required for smoke-test
- wget # Required for smoke-test