diff --git a/.fmf/version b/.fmf/version deleted file mode 100644 index d00491f..0000000 --- a/.fmf/version +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/.gitignore b/.gitignore index 67bb856..490fdf3 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.8.1.tar.gz +/v2.6.8.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 2c2e25b..1a4e76e 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -1,73 +1,12 @@ ---- openwsman-2.8.1/bindings/ruby/extconf.rb.orig 2025-11-11 11:49:59.880195434 +0100 -+++ openwsman-2.8.1/bindings/ruby/extconf.rb 2025-11-11 11:50:46.870685458 +0100 -@@ -5,20 +5,41 @@ - require 'mkmf' - # $CFLAGS = "#{$CFLAGS} -Werror" - -+# libwsman requires 'int facility' to be defined by the application -+# Add syslog.h for LOG_DAEMON constant -+$CFLAGS = "#{$CFLAGS} -include syslog.h" -+ - # requires wsman, wsman_client, and libxml2 -+# Use CPATH and LIBRARY_PATH environment variables set by the build system -+if ENV['CPATH'] -+ ENV['CPATH'].split(':').each do |path| -+ $CPPFLAGS = "#{$CPPFLAGS} -I#{path}" -+ end -+end -+if ENV['LIBRARY_PATH'] -+ ENV['LIBRARY_PATH'].split(':').each do |path| -+ $LDFLAGS = "#{$LDFLAGS} -L#{path}" -+ end -+end - --unless have_library('wsman', 'wsman_create_doc') -+# Custom test for libwsman that includes facility definition -+unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsman_create_doc(\"test\");\n return 0;\n}", '-lwsman') - STDERR.puts "Cannot find wsman_create_doc() in libwsman" - STDERR.puts "Is openwsman-devel installed ?" - exit 1 - end -+# Explicitly add libwsman to linker flags since we used try_link instead of have_library -+$libs = append_library($libs, "wsman") - find_header 'wsman-xml-api.h', '/usr/include/openwsman' - --unless have_library('wsman_client', 'wsmc_create') -+# Custom test for libwsman_client that includes facility definition -+unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsmc_create(\"localhost\", 80, \"/wsman\", \"http\", \"user\", \"pass\");\n return 0;\n}", '-lwsman_client -lwsman') - STDERR.puts "Cannot find wsmc_create() in libwsman_client" - STDERR.puts "Is openwsman-devel installed ?" - exit 1 - end -+# Explicitly add libwsman_client to linker flags since we used try_link instead of have_library -+$libs = append_library($libs, "wsman_client") - find_header 'wsman-client-api.h', '/usr/include/openwsman' - - unless have_library('xml2', 'xmlNewDoc') -@@ -28,12 +49,25 @@ - end - find_header 'libxml/parser.h', '/usr/include/libxml2' - -+# Check for Ruby 3.3+ IO types -+have_type('rb_io_t', 'ruby/io.h') -+have_header 'ruby/thread.h' -+ - swig = find_executable("swig") +diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/bindings/ruby/extconf.rb +--- openwsman-2.4.12/bindings/ruby/extconf.rb.orig 2015-02-09 09:28:58.232581263 +0100 ++++ openwsman-2.4.12/bindings/ruby/extconf.rb 2015-02-09 09:38:22.836772879 +0100 +@@ -32,7 +32,7 @@ swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+ -+# Build SWIG include paths from CPATH environment variable -+swig_includes = "-I. -I/usr/include/openwsman" -+if ENV['CPATH'] -+ ENV['CPATH'].split(':').each do |path| -+ swig_includes += " -I#{path}" -+ end -+end -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} #{swig_includes} -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.8/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." - create_makefile('_openwsman') -+ diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 9322adb..98f6bc2 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/src/server/shttpd/compat_unix.h ---- openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/server/shttpd/compat_unix.h 2025-02-03 09:11:35.072818890 +0100 +diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/src/server/shttpd/compat_unix.h +--- openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/compat_unix.h 2018-11-22 13:30:10.756423510 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,10 +12,10 @@ diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/server/shttpd/io_ssl.c ---- openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/server/shttpd/io_ssl.c 2025-02-03 09:12:22.387355905 +0100 -@@ -11,28 +11,6 @@ +diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/server/shttpd/io_ssl.c +--- openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/io_ssl.c 2018-11-22 13:30:10.757423510 +0100 +@@ -11,23 +11,6 @@ #include "defs.h" #if !defined(NO_SSL) @@ -29,13 +29,8 @@ diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/ser - {"SSL_set_fd", {0}}, - {"SSL_new", {0}}, - {"SSL_CTX_new", {0}}, --#if OPENSSL_VERSION_NUMBER < 0x10100000L - {"SSLv23_server_method", {0}}, - {"SSL_library_init", {0}}, --#else -- {"TLS_server_method", {0}}, -- {"OPENSSL_init_ssl", {0}}, --#endif - {"SSL_CTX_use_PrivateKey_file", {0}}, - {"SSL_CTX_use_certificate_file",{0}}, - {NULL, {0}} @@ -44,10 +39,10 @@ diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c ---- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2025-02-03 09:13:43.415562784 +0100 -@@ -1510,25 +1510,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2018-11-22 13:30:41.314416695 +0100 +@@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -64,20 +59,20 @@ diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/ser - } - /* Initialize SSL crap */ - - #if OPENSSL_VERSION_NUMBER < 0x10100000L ++ debug("Initialize SSL"); ++ SSL_load_error_strings(); ++#if OPENSSL_VERSION_NUMBER >= 0x10100000L ++ OPENSSL_init_ssl(0, NULL); ++#else SSL_library_init(); ++#endif + if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) - #else -- OPENSSL_init_ssl(); -+ OPENSSL_init_ssl(0, NULL); - if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) - #endif - _shttpd_report_ssl_error("SSL_CTX_new failed", NULL); -diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server/shttpd/ssl.h ---- openwsman-2.8.1/src/server/shttpd/ssl.h.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/server/shttpd/ssl.h 2025-02-03 09:14:43.142975166 +0100 -@@ -12,55 +12,4 @@ + _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); +diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server/shttpd/ssl.h +--- openwsman-2.6.8/src/server/shttpd/ssl.h.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/ssl.h 2018-11-22 13:30:10.757423510 +0100 +@@ -12,52 +12,4 @@ #include @@ -125,9 +120,6 @@ diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server -#if OPENSSL_VERSION_NUMBER < 0x10100000L -#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() -#define SSL_library_init() (* (int (*)(void)) FUNC(10))() --#else --#define TLS_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() --#define OPENSSL_init_ssl() (* (int (*)(void)) FUNC(10))() #endif -#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(11))((x), (y), (z)) diff --git a/openwsman-2.6.5-libcurl-error-codes-update.patch b/openwsman-2.6.5-libcurl-error-codes-update.patch new file mode 100644 index 0000000..82ee51f --- /dev/null +++ b/openwsman-2.6.5-libcurl-error-codes-update.patch @@ -0,0 +1,27 @@ +diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c +--- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2018-11-14 13:53:27.442138557 +0100 ++++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-11-14 14:11:28.508714204 +0100 +@@ -186,16 +186,23 @@ convert_to_last_error(CURLcode r) + return WS_LASTERR_SSL_CONNECT_ERROR; + case CURLE_BAD_FUNCTION_ARGUMENT: + return WS_LASTERR_CURL_BAD_FUNCTION_ARG; ++#if LIBCURL_VERSION_NUM < 0x073E00 + case CURLE_SSL_PEER_CERTIFICATE: + return WS_LASTERR_SSL_PEER_CERTIFICATE; ++#endif + case CURLE_SSL_ENGINE_NOTFOUND: + return WS_LASTERR_SSL_ENGINE_NOTFOUND; + case CURLE_SSL_ENGINE_SETFAILED: + return WS_LASTERR_SSL_ENGINE_SETFAILED; + case CURLE_SSL_CERTPROBLEM: + return WS_LASTERR_SSL_CERTPROBLEM; ++#if LIBCURL_VERSION_NUM < 0x073E00 + case CURLE_SSL_CACERT: + return WS_LASTERR_SSL_CACERT; ++#else ++ case CURLE_PEER_FAILED_VERIFICATION: ++ return WS_LASTERR_SSL_PEER_CERTIFICATE; ++#endif + #if LIBCURL_VERSION_NUM > 0x70C01 + case CURLE_SSL_ENGINE_INITFAILED: + return WS_LASTERR_SSL_ENGINE_INITFAILED; diff --git a/openwsman-2.6.8-CVE-2019-3816.patch b/openwsman-2.6.8-CVE-2019-3816.patch new file mode 100644 index 0000000..aa8835f --- /dev/null +++ b/openwsman-2.6.8-CVE-2019-3816.patch @@ -0,0 +1,79 @@ +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 08:52:06.112090942 +0100 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:01:15.496156789 +0100 +@@ -336,10 +336,12 @@ date_to_epoch(const char *s) + } + + static void +-remove_double_dots(char *s) ++remove_all_leading_dots(char *s) + { + char *p = s; + ++ while (*s != '\0' && *s == '.') s++; ++ + while (*s != '\0') { + *p++ = *s++; + if (s[-1] == '/' || s[-1] == '\\') +@@ -546,7 +548,7 @@ decide_what_to_do(struct conn *c) + *c->query++ = '\0'; + + _shttpd_url_decode(c->uri, strlen(c->uri), c->uri, strlen(c->uri) + 1); +- remove_double_dots(c->uri); ++ remove_all_leading_dots(c->uri); + + root = c->ctx->options[OPT_ROOT]; + if (strlen(c->uri) + strlen(root) >= sizeof(path)) { +@@ -556,6 +558,7 @@ decide_what_to_do(struct conn *c) + + (void) _shttpd_snprintf(path, sizeof(path), "%s%s", root, c->uri); + ++ DBG(("decide_what_to_do -> processed path: [%s]", path)); + /* User may use the aliases - check URI for mount point */ + if (is_alias(c->ctx, c->uri, &alias_uri, &alias_path) != NULL) { + (void) _shttpd_snprintf(path, sizeof(path), "%.*s%s", +@@ -572,7 +575,10 @@ decide_what_to_do(struct conn *c) + if ((ruri = _shttpd_is_registered_uri(c->ctx, c->uri)) != NULL) { + _shttpd_setup_embedded_stream(c, + ruri->callback, ruri->callback_data); +- } else ++ } else { ++ _shttpd_send_server_error(c, 403, "Forbidden"); ++ } ++#if 0 + if (strstr(path, HTPASSWD)) { + /* Do not allow to view passwords files */ + _shttpd_send_server_error(c, 403, "Forbidden"); +@@ -656,6 +662,7 @@ decide_what_to_do(struct conn *c) + } else { + _shttpd_send_server_error(c, 500, "Internal Error"); + } ++#endif + } + + static int +diff -up openwsman-2.6.8/src/server/wsmand.c.orig openwsman-2.6.8/src/server/wsmand.c +--- openwsman-2.6.8/src/server/wsmand.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/wsmand.c 2019-03-13 09:03:25.919181279 +0100 +@@ -198,6 +198,10 @@ static void daemonize(void) + int fd; + char *pid; + ++ /* Change our CWD to / */ ++ i = chdir("/"); ++ assert(i == 0); ++ + if (wsmand_options_get_foreground_debug() > 0) { + return; + } +@@ -214,10 +218,6 @@ static void daemonize(void) + log_pid = 0; + setsid(); + +- /* Change our CWD to / */ +- i=chdir("/"); +- assert(i == 0); +- + /* Close all file descriptors. */ + for (i = getdtablesize(); i >= 0; --i) + close(i); diff --git a/openwsman-2.6.8-CVE-2019-3833.patch b/openwsman-2.6.8-CVE-2019-3833.patch new file mode 100644 index 0000000..301724f --- /dev/null +++ b/openwsman-2.6.8-CVE-2019-3833.patch @@ -0,0 +1,94 @@ +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 09:32:32.417633057 +0100 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:58:04.482486589 +0100 +@@ -705,11 +705,11 @@ parse_http_request(struct conn *c) + _shttpd_send_server_error(c, 500, "Cannot allocate request"); + } + ++ io_inc_tail(&c->rem.io, req_len); ++ + if (c->loc.flags & FLAG_CLOSED) + return; + +- io_inc_tail(&c->rem.io, req_len); +- + DBG(("Conn %d: parsing request: [%.*s]", c->rem.chan.sock, req_len, s)); + c->rem.flags |= FLAG_HEADERS_PARSED; + +@@ -975,7 +975,7 @@ write_stream(struct stream *from, struct + } + + +-static void ++static int + connection_desctructor(struct llhead *lp) + { + struct conn *c = LL_ENTRY(lp, struct conn, link); +@@ -999,7 +999,8 @@ connection_desctructor(struct llhead *lp + * Check the "Connection: " header before we free c->request + * If it its 'keep-alive', then do not close the connection + */ +- do_close = (c->ch.connection.v_vec.len >= vec.len && ++ do_close = c->rem.flags & FLAG_CLOSED || ++ (c->ch.connection.v_vec.len >= vec.len && + !_shttpd_strncasecmp(vec.ptr,c->ch.connection.v_vec.ptr,vec.len)) || + (c->major_version < 1 || + (c->major_version >= 1 && c->minor_version < 1)); +@@ -1021,7 +1022,7 @@ connection_desctructor(struct llhead *lp + io_clear(&c->loc.io); + c->birth_time = _shttpd_current_time; + if (io_data_len(&c->rem.io) > 0) +- process_connection(c, 0, 0); ++ return 1; + } else { + if (c->rem.io_class != NULL) + c->rem.io_class->close(&c->rem); +@@ -1032,6 +1033,8 @@ connection_desctructor(struct llhead *lp + + free(c); + } ++ ++ return 0; + } + + static void +@@ -1039,7 +1042,7 @@ worker_destructor(struct llhead *lp) + { + struct worker *worker = LL_ENTRY(lp, struct worker, link); + +- free_list(&worker->connections, connection_desctructor); ++ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); + free(worker); + } + +@@ -1072,6 +1075,8 @@ add_to_set(int fd, fd_set *set, int *max + static void + process_connection(struct conn *c, int remote_ready, int local_ready) + { ++again: ++ + /* Read from remote end if it is ready */ + if (remote_ready && io_space_len(&c->rem.io)) + read_stream(&c->rem); +@@ -1100,7 +1105,11 @@ process_connection(struct conn *c, int r + if ((_shttpd_current_time > c->expire_time) || + (c->rem.flags & FLAG_CLOSED) || + ((c->loc.flags & FLAG_CLOSED) && !io_data_len(&c->loc.io))) +- connection_desctructor(&c->link); ++ if (connection_desctructor(&c->link)) { ++ remote_ready = 0; ++ local_ready = 0; ++ goto again; ++ } + } + + static int +@@ -1642,7 +1651,7 @@ worker_function(void *param) + while (worker->exit_flag == 0) + poll_worker(worker, 1000 * 10); + +- free_list(&worker->connections, connection_desctructor); ++ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); + free(worker); + } + diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch index c312af5..15c5c74 100644 --- a/openwsman-2.6.8-update-ssleay-conf.patch +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -1,9 +1,12 @@ -diff -up openwsman-2.7.1/etc/ssleay.cnf.orig openwsman-2.7.1/etc/ssleay.cnf ---- openwsman-2.7.1/etc/ssleay.cnf.orig 2021-11-09 08:27:48.577749509 +0100 -+++ openwsman-2.7.1/etc/ssleay.cnf 2021-11-09 08:28:10.499967010 +0100 -@@ -3,7 +3,7 @@ +diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf +--- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 +@@ -2,10 +2,8 @@ + # SSLeay example configuration file. # +-RANDFILE = /dev/random +- [ req ] -default_bits = 1024 +default_bits = 2048 diff --git a/openwsman-2.7.2-gcc15-fix.patch b/openwsman-2.7.2-gcc15-fix.patch deleted file mode 100644 index 590ff14..0000000 --- a/openwsman-2.7.2-gcc15-fix.patch +++ /dev/null @@ -1,24 +0,0 @@ -diff -up openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig openwsman-2.8.1/src/plugins/swig/src/target_ruby.c ---- openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/plugins/swig/src/target_ruby.c 2025-02-03 09:30:36.905616375 +0100 -@@ -49,7 +49,7 @@ - */ - - static VALUE --load_module() -+load_module(VALUE) - { - ruby_script(PLUGIN_FILE); - return rb_require(PLUGIN_FILE); -diff -up openwsman-2.8.1/src/server/CMakeLists.txt.orig openwsman-2.8.1/src/server/CMakeLists.txt ---- openwsman-2.8.1/src/server/CMakeLists.txt.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/src/server/CMakeLists.txt 2025-02-03 09:31:15.258241237 +0100 -@@ -48,7 +48,7 @@ IF( HAVE_LIBDL ) - TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) - ENDIF( HAVE_LIBDL ) - --INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin) -+INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin) - - # - # diff --git a/openwsman-2.7.2-ssl-certs-gen-changes.patch b/openwsman-2.7.2-ssl-certs-gen-changes.patch deleted file mode 100644 index 0f0b96a..0000000 --- a/openwsman-2.7.2-ssl-certs-gen-changes.patch +++ /dev/null @@ -1,102 +0,0 @@ -diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/owsmangencert.sh.cmake ---- openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/etc/owsmangencert.sh.cmake 2025-10-17 10:16:34.482996406 +0200 -@@ -1,10 +1,74 @@ --#!/bin/sh -- - #!/bin/sh -e - - CERTFILE=@WSMANCONF_DIR@/servercert.pem - KEYFILE=@WSMANCONF_DIR@/serverkey.pem - CNFFILE=@WSMANCONF_DIR@/ssleay.cnf -+CAFILE=@WSMANCONF_DIR@/ca.crt -+DAYS=365 -+ -+function create_ssl_cnf -+{ -+ # Get minimum RSA key length at current security level -+ # This workarounds openssl not enforcing min. key length enforced by current security level -+ KEYSIZE=`grep min_rsa_size /etc/crypto-policies/state/CURRENT.pol | cut -d ' ' -f 3` -+ -+ # Create OpenSSL configuration files for generating certificates -+ echo "[ req ]" > $CNFFILE -+ echo "default_bits = $KEYSIZE" >> $CNFFILE -+ echo "default_keyfile = privkey.pem" >> $CNFFILE -+ echo "distinguished_name = req_distinguished_name" >> $CNFFILE -+ -+ echo "[ req_distinguished_name ]" >> $CNFFILE -+ echo "countryName = Country Name (2 letter code)" >> $CNFFILE -+ echo "countryName_default = GB" >> $CNFFILE -+ echo "countryName_min = 2" >> $CNFFILE -+ echo "countryName_max = 2" >> $CNFFILE -+ -+ echo "stateOrProvinceName = State or Province Name (full name)" >> $CNFFILE -+ echo "stateOrProvinceName_default = Some-State" >> $CNFFILE -+ -+ echo "localityName = Locality Name (eg, city)" >> $CNFFILE -+ -+ echo "organizationName = Organization Name (eg, company; recommended)" >> $CNFFILE -+ echo "organizationName_max = 64" >> $CNFFILE -+ -+ echo "organizationalUnitName = Organizational Unit Name (eg, section)" >> $CNFFILE -+ echo "organizationalUnitName_max = 64" >> $CNFFILE -+ -+ echo "commonName = server name (eg. ssl.domain.tld; required!!!)" >> $CNFFILE -+ echo "commonName_max = 80" >> $CNFFILE -+ -+ echo "emailAddress = Email Address" >> $CNFFILE -+ echo "emailAddress_max = 85" >> $CNFFILE -+} -+ -+function selfsign_sscg() -+{ -+ sscg --quiet \ -+ --lifetime "$DAYS" \ -+ --cert-key-file "$KEYFILE" \ -+ --cert-file "$CERTFILE" \ -+ --ca-file "$CAFILE" -+} -+ -+function selfsign_openssl() -+{ -+ -+ echo -+ echo creating selfsigned certificate -+ echo "replace it with one signed by a certification authority (CA)" -+ echo -+ echo enter your ServerName at the Common Name prompt -+ echo -+ -+ # use special .cnf, because with normal one no valid selfsigned -+ # certificate is created -+ -+ openssl req -days $DAYS $@ -config $CNFFILE \ -+ -new -x509 -nodes -out $CERTFILE \ -+ -keyout $KEYFILE -+ chmod 600 $KEYFILE -+} - - if [ "$1" != "--force" -a -f $KEYFILE ]; then - echo "$KEYFILE exists! Use \"$0 --force.\"" -@@ -15,18 +79,7 @@ if [ "$1" = "--force" ]; then - shift - fi - --echo --echo creating selfsigned certificate --echo "replace it with one signed by a certification authority (CA)" --echo --echo enter your ServerName at the Common Name prompt --echo -- --# use special .cnf, because with normal one no valid selfsigned --# certificate is created -- --openssl req -days 365 $@ -config $CNFFILE \ -- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ -- -keyout $KEYFILE --chmod 600 $KEYFILE -+create_ssl_cnf - -+# If sscg fails, try openssl -+selfsign_sscg || selfsign_openssl diff --git a/openwsman-2.8.1-fix-ruby-io.patch b/openwsman-2.8.1-fix-ruby-io.patch deleted file mode 100644 index 605bf91..0000000 --- a/openwsman-2.8.1-fix-ruby-io.patch +++ /dev/null @@ -1,33 +0,0 @@ -diff -up openwsman-2.8.1/bindings/openwsman.i.orig openwsman-2.8.1/bindings/openwsman.i ---- openwsman-2.8.1/bindings/openwsman.i.orig 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/bindings/openwsman.i 2025-10-21 16:56:01.025576984 +0200 -@@ -105,15 +105,8 @@ SWIGINTERNINLINE SV *SWIG_From_double S - #if HAVE_RUBY_THREAD_H /* New threading model */ - #include - #endif --#if RUBY_VERSION > 18 -- #if HAVE_RB_IO_T -- #define rb_fptr_t rb_io_t -- #else -- #define rb_fptr_t struct rb_io -- #endif --#else -- #define rb_fptr_t struct OpenFile --#endif -+/* Use rb_io_t for Ruby 1.9+ */ -+#define rb_fptr_t rb_io_t - %} - - %typemap(in) FILE* { -@@ -122,11 +115,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S - Check_Type($input, T_FILE); - GetOpenFile($input, fptr); - /*rb_io_check_writable(fptr);*/ --#if RUBY_VERSION > 18 - $1 = rb_io_stdio_file(fptr); --#else -- $1 = GetReadFile(fptr); --#endif - } - - #endif /* SWIGRUBY */ diff --git a/openwsman-2.8.1-post-quantum.patch b/openwsman-2.8.1-post-quantum.patch deleted file mode 100644 index 0b9b7bb..0000000 --- a/openwsman-2.8.1-post-quantum.patch +++ /dev/null @@ -1,101 +0,0 @@ -diff -up openwsman-2.7.2/etc/openwsman.conf.orig openwsman-2.7.2/etc/openwsman.conf ---- openwsman-2.7.2/etc/openwsman.conf.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/etc/openwsman.conf 2025-05-27 08:03:57.890057721 +0200 -@@ -32,8 +32,12 @@ ipv6 = yes - - # the openwsman server certificate file, in .pem format - ssl_cert_file = /etc/openwsman/servercert.pem -+# the openwsman server certificate fallback file, in .pem format -+#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem - # the openwsman server private key, in .pem format - ssl_key_file = /etc/openwsman/serverkey.pem -+# the openwsman server private key fallback, in .pem format -+#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem - - # space-separated list of SSL protocols to *dis*able - # possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2 -diff -up openwsman-2.7.2/src/server/shttpd/shttpd.c.orig openwsman-2.7.2/src/server/shttpd/shttpd.c ---- openwsman-2.7.2/src/server/shttpd/shttpd.c.orig 2025-05-21 10:07:40.404532496 +0200 -+++ openwsman-2.7.2/src/server/shttpd/shttpd.c 2025-06-12 12:27:44.785904555 +0200 -@@ -1491,7 +1491,6 @@ set_ssl(struct shttpd_ctx *ctx, const ch - char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); - char *ssl_cipher_list = wsmand_options_get_ssl_cipher_list(); - int retval = FALSE; -- EC_KEY* key; - - /* Initialize SSL crap */ - -@@ -1510,11 +1509,15 @@ set_ssl(struct shttpd_ctx *ctx, const ch - else - retval = TRUE; - -- /* This enables ECDH Perfect Forward secrecy. Currently with just the most generic p256 prime curve */ -- key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); -- if (key != NULL) { -- SSL_CTX_set_tmp_ecdh(CTX, key); -- EC_KEY_free(key); -+ /* Add fall back certificate/key pair */ -+ if (wsmand_options_get_ssl_cert_fallback_file() && -+ wsmand_options_get_ssl_key_fallback_file()) { -+ if (SSL_CTX_use_certificate_file(CTX, wsmand_options_get_ssl_cert_fallback_file(), SSL_FILETYPE_PEM) != 1) -+ _shttpd_elog(E_LOG, NULL, "cannot open certificate fallback file %s", pem); -+ else if (SSL_CTX_use_PrivateKey_file(CTX, wsmand_options_get_ssl_key_fallback_file(), SSL_FILETYPE_PEM) != 1) -+ _shttpd_elog(E_LOG, NULL, "cannot open fallback PrivateKey %s", pem); -+ else -+ retval = TRUE; - } - - while (ssl_disabled_protocols) { -diff -up openwsman-2.7.2/src/server/wsmand-daemon.c.orig openwsman-2.7.2/src/server/wsmand-daemon.c ---- openwsman-2.7.2/src/server/wsmand-daemon.c.orig 2025-05-27 07:18:16.878974761 +0200 -+++ openwsman-2.7.2/src/server/wsmand-daemon.c 2025-05-27 07:22:06.832235764 +0200 -@@ -76,8 +76,10 @@ static int use_ipv6 = 0; - #endif - static int use_digest = 0; - static char *ssl_key_file = NULL; -+static char *ssl_key_fallback_file = NULL; - static char *service_path = DEFAULT_SERVICE_PATH; - static char *ssl_cert_file = NULL; -+static char *ssl_cert_fallback_file = NULL; - static char *ssl_disabled_protocols = NULL; - static char *ssl_cipher_list = NULL; - static char *pid_file = DEFAULT_PID_PATH; -@@ -186,7 +188,9 @@ int wsmand_read_config(dictionary * ini) - service_path = - iniparser_getstring(ini, "server:service_path", "/wsman"); - ssl_key_file = iniparser_getstr(ini, "server:ssl_key_file"); -+ ssl_key_fallback_file = iniparser_getstr(ini, "server:ssl_key_fallback_file"); - ssl_cert_file = iniparser_getstr(ini, "server:ssl_cert_file"); -+ ssl_cert_fallback_file = iniparser_getstr(ini, "server:ssl_cert_fallback_file"); - ssl_disabled_protocols = iniparser_getstr(ini, "server:ssl_disabled_protocols"); - ssl_cipher_list = iniparser_getstr(ini, "server:ssl_cipher_list"); - use_ipv4 = iniparser_getboolean(ini, "server:ipv4", 1); -@@ -364,6 +368,16 @@ char *wsmand_options_get_ssl_cert_file(v - return ssl_cert_file; - } - -+char *wsmand_options_get_ssl_key_fallback_file(void) -+{ -+ return ssl_key_fallback_file; -+} -+ -+char *wsmand_options_get_ssl_cert_fallback_file(void) -+{ -+ return ssl_cert_fallback_file; -+} -+ - char *wsmand_options_get_ssl_disabled_protocols(void) - { - return ssl_disabled_protocols; -diff -up openwsman-2.7.2/src/server/wsmand-daemon.h.orig openwsman-2.7.2/src/server/wsmand-daemon.h ---- openwsman-2.7.2/src/server/wsmand-daemon.h.orig 2025-05-27 07:15:56.869002037 +0200 -+++ openwsman-2.7.2/src/server/wsmand-daemon.h 2025-05-27 07:18:06.429846617 +0200 -@@ -76,6 +76,8 @@ int wsmand_options_get_server_port(void) - int wsmand_options_get_server_ssl_port(void); - char *wsmand_options_get_ssl_key_file(void); - char *wsmand_options_get_ssl_cert_file(void); -+char *wsmand_options_get_ssl_key_fallback_file(void); -+char *wsmand_options_get_ssl_cert_fallback_file(void); - char *wsmand_options_get_ssl_disabled_protocols(void); - char *wsmand_options_get_ssl_cipher_list(void); - int wsmand_options_get_digest(void); diff --git a/openwsman-2.8.1-rdoc-6_16.patch b/openwsman-2.8.1-rdoc-6_16.patch deleted file mode 100644 index c0dc8b4..0000000 --- a/openwsman-2.8.1-rdoc-6_16.patch +++ /dev/null @@ -1,18 +0,0 @@ -diff -urp '--exclude=*~' openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb ---- openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:43:41.804273994 +0900 -+++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:56:06.991238037 +0900 -@@ -377,7 +377,13 @@ class RDoc::Parser::SWIG < RDoc::Parser - find_modifiers comment, meth_obj if comment - - #meth_obj.params = params -- meth_obj.start_collecting_tokens -+ # https://github.com/ruby/rdoc/pull/1471 changes the parameter for -+ # RDoc::TokenStream.start_collecting_tokens -+ if meth_obj.method(:start_collecting_tokens).arity == 1 -+ meth_obj.start_collecting_tokens :ruby -+ else -+ meth_obj.start_collecting_tokens -+ end - begin - RDoc::const_get "RubyToken" - tk = RDoc::RubyToken::Token.new nil, 1, 1 diff --git a/openwsman-2.8.1-rdoc-ruby34.patch b/openwsman-2.8.1-rdoc-ruby34.patch deleted file mode 100644 index de30428..0000000 --- a/openwsman-2.8.1-rdoc-ruby34.patch +++ /dev/null @@ -1,29 +0,0 @@ ---- openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-01-23 10:23:52.000000000 +0100 -+++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-11-10 15:00:00.000000000 +0100 -@@ -108,10 +108,24 @@ class RDoc::Parser::SWIG < RDoc::Parser - ## - # Prepare to parse a SWIG file - -- def initialize(top_level, file_name, content, options, stats) -- super -+ def initialize(top_level, file_name, content, options, stats = nil) -+ # RDoc 6.6+ (Ruby 3.3+) removed the stats parameter from Parser.initialize -+ # Check the arity of the parent class initialize method to determine which API we're using -+ parent_arity = RDoc::Parser.instance_method(:initialize).arity -+ -+ if parent_arity == 4 || parent_arity == -5 -+ # RDoc 6.6+: only pass 4 arguments to super -+ super(top_level, file_name, content, options) -+ # Create a dummy stats object for compatibility -+ @stats = Object.new -+ def @stats.method_missing(m, *args); end -+ else -+ # Older RDoc: pass all 5 arguments including stats -+ super(top_level, file_name, content, options, stats) -+ @stats = stats -+ end - - @known_classes = RDoc::KNOWN_CLASSES.dup - @content = handle_tab_width handle_ifdefs_in(@content) - @renames = {} # maps old_name => [ new_name, args ] - @aliases = {} # maps name => [ alias_name, args ] diff --git a/openwsman.fc b/openwsman.fc deleted file mode 100644 index 00d0643..0000000 --- a/openwsman.fc +++ /dev/null @@ -1,7 +0,0 @@ -/usr/lib/systemd/system/openwsmand.* -- gen_context(system_u:object_r:openwsman_unit_file_t,s0) - -/usr/sbin/openwsmand -- gen_context(system_u:object_r:openwsman_exec_t,s0) - -/var/log/wsmand.* -- gen_context(system_u:object_r:openwsman_log_t,s0) - -/var/run/wsmand.* -- gen_context(system_u:object_r:openwsman_run_t,s0) diff --git a/openwsman.if b/openwsman.if deleted file mode 100644 index 747853a..0000000 --- a/openwsman.if +++ /dev/null @@ -1,79 +0,0 @@ -## WS-Management Server - -######################################## -## -## Execute openwsman in the openwsman domin. -## -## -## -## Domain allowed to transition. -## -## -# -interface(`openwsman_domtrans',` - gen_require(` - type openwsman_t, openwsman_exec_t; - ') - - corecmd_search_bin($1) - domtrans_pattern($1, openwsman_exec_t, openwsman_t) -') -######################################## -## -## Execute openwsman server in the openwsman domain. -## -## -## -## Domain allowed to transition. -## -## -# -interface(`openwsman_systemctl',` - gen_require(` - type openwsman_t; - type openwsman_unit_file_t; - ') - - systemd_exec_systemctl($1) - init_reload_services($1) - systemd_read_fifo_file_passwd_run($1) - allow $1 openwsman_unit_file_t:file read_file_perms; - allow $1 openwsman_unit_file_t:service manage_service_perms; - - ps_process_pattern($1, openwsman_t) -') - - -######################################## -## -## All of the rules required to administrate -## an openwsman environment -## -## -## -## Domain allowed access. -## -## -## -# -interface(`openwsman_admin',` - gen_require(` - type openwsman_t; - type openwsman_unit_file_t; - ') - - allow $1 openwsman_t:process { signal_perms }; - ps_process_pattern($1, openwsman_t) - - tunable_policy(`deny_ptrace',`',` - allow $1 openwsman_t:process ptrace; - ') - - openwsman_systemctl($1) - admin_pattern($1, openwsman_unit_file_t) - allow $1 openwsman_unit_file_t:service all_service_perms; - optional_policy(` - systemd_passwd_agent_exec($1) - systemd_read_fifo_file_passwd_run($1) - ') -') diff --git a/openwsman.spec b/openwsman.spec index 1a56b52..b8734e8 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,34 +1,12 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} -# defining macros needed by SELinux -# unless running a flatpak build. -%if 0%{?flatpak} -%global with_selinux 0 -%else -%global with_selinux 1 -%global selinuxtype targeted -%global modulename openwsman -%endif - -# Bindings install in the wrong path for a flatpak build; this could be fixed, but -# we don't currently need the bindings for any Flatpak'ed application -%if 0%{?flatpak} -%global with_ruby 0 -%global with_perl 0 -%global with_python 0 -%else -%global with_ruby 1 -%global with_perl 1 -%global with_python 1 -%endif - Name: openwsman -Version: 2.8.1 -Release: 13%{?dist} +Version: 2.6.8 +Release: 17%{?dist} Summary: Open source Implementation of WS-Management -License: BSD-3-Clause AND MIT +License: BSD URL: http://www.openwsman.org/ Source0: https://github.com/Openwsman/openwsman/archive/v%{version}.tar.gz # help2man generated manpage for openwsmand binary @@ -37,41 +15,21 @@ Source1: openwsmand.8.gz Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre Source3: owsmantestcert.sh -# Source100-102: selinux policy for openwsman, extracted -# from https://github.com/fedora-selinux/selinux-policy -%if 0%{with_selinux} -Source100: %{modulename}.te -Source101: %{modulename}.if -Source102: %{modulename}.fc -%endif Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch -Patch5: openwsman-2.6.8-update-ssleay-conf.patch -Patch6: openwsman-2.7.2-gcc15-fix.patch -Patch7: openwsman-2.8.1-post-quantum.patch -Patch8: openwsman-2.7.2-ssl-certs-gen-changes.patch -Patch9: openwsman-2.8.1-rdoc-ruby34.patch -Patch10: openwsman-2.8.1-fix-ruby-io.patch -Patch11: openwsman-2.8.1-rdoc-6_16.patch -BuildRequires: make +Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch +Patch6: openwsman-2.6.8-CVE-2019-3816.patch +Patch7: openwsman-2.6.8-CVE-2019-3833.patch +Patch8: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -%if %{with_python} -BuildRequires: python3 python3-devel -%endif -%if %{with_ruby} -BuildRequires: ruby ruby-devel rubygems-devel -%endif -%if %{with_perl} -BuildRequires: perl-interpreter perl-devel perl-generators -%endif -BuildRequires: pkgconfig openssl-devel +BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter +BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ -BuildRequires: libxcrypt-devel %description Openwsman is a project intended to provide an open-source @@ -83,7 +41,7 @@ requirements that exposes a set of operations focused on and covers all system management aspects. %package -n libwsman1 -License: BSD-3-Clause AND MIT +License: BSD Summary: Open source Implementation of WS-Management Provides: %{name} = %{version}-%{release} Obsoletes: %{name} < %{version}-%{release} @@ -92,7 +50,7 @@ Obsoletes: %{name} < %{version}-%{release} Openwsman library for packages dependent on openwsman. %package -n libwsman-devel -License: BSD-3-Clause AND MIT +License: BSD Summary: Open source Implementation of WS-Management Provides: %{name}-devel = %{version}-%{release} Obsoletes: %{name}-devel < %{version}-%{release} @@ -106,28 +64,22 @@ Requires: libcurl-devel Development files for openwsman. %package client -License: BSD-3-Clause AND MIT +License: BSD Summary: Openwsman Client libraries %description client Openwsman Client libraries. %package server -License: BSD-3-Clause AND MIT +License: BSD Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} -%if 0%{?with_selinux} -# This ensures that the *-selinux package and all it’s dependencies are not pulled -# into containers and other systems that do not use SELinux -Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) -%endif %description server Openwsman Server and service libraries. -%if %{with_python} %package python3 -License: BSD-3-Clause AND MIT +License: BSD Summary: Python bindings for openwsman client API Requires: %{__python3} Requires: libwsman1 = %{version}-%{release} @@ -135,11 +87,9 @@ Requires: libwsman1 = %{version}-%{release} %description python3 This package provides Python3 bindings to access the openwsman client API. -%endif -%if %{with_ruby} %package -n rubygem-%{gem_name} -License: BSD-3-Clause AND MIT +License: BSD Summary: Ruby client bindings for Openwsman Obsoletes: %{name}-ruby < %{version}-%{release} Requires: libwsman1 = %{version}-%{release} @@ -155,19 +105,16 @@ BuildArch: noarch %description -n rubygem-%{gem_name}-doc Documentation for rubygem-%{gem_name} -%endif -%if %{with_perl} %package perl -License: BSD-3-Clause AND MIT +License: BSD +Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) Summary: Perl bindings for openwsman client API Requires: libwsman1 = %{version}-%{release} %description perl This package provides Perl bindings to access the openwsman client API. -%endif -%if %{with_ruby} %package winrs Summary: Windows Remote Shell Requires: rubygem-%{gem_name} = %{version}-%{release} @@ -175,26 +122,18 @@ Requires: rubygem-%{gem_name} = %{version}-%{release} %description winrs This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. -%endif - -%if 0%{?with_selinux} -# SELinux subpackage -%package selinux -Summary: openwsman SELinux policy -BuildArch: noarch -Requires: selinux-policy-%{selinuxtype} -Requires(post): selinux-policy-%{selinuxtype} -BuildRequires: selinux-policy-devel -%{?selinux_requires} - -%description selinux -Custom SELinux policy module -%endif %prep %setup -q -%autopatch -p1 +%patch1 -p1 -b .pamsetup +%patch2 -p1 -b .ruby-binding-build +%patch3 -p1 -b .openssl-1.1-fix +%patch4 -p1 -b .http-status-line +%patch5 -p1 -b .libcurl-error-codes-update +%patch6 -p1 -b .CVE-2019-3816 +%patch7 -p1 -b .CVE-2019-3833 +%patch8 -p1 -b .update-ssleay-conf %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -208,7 +147,7 @@ export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ - -DCMAKE_INSTALL_PREFIX=%{_prefix} \ + -DCMAKE_INSTALL_PREFIX=/usr \ -DCMAKE_VERBOSE_MAKEFILE=TRUE \ -DCMAKE_BUILD_TYPE=Release \ -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ @@ -218,20 +157,10 @@ cmake \ -DLIB=%{_lib} \ -DBUILD_JAVA=no \ -DBUILD_PYTHON=no \ -%if ! %{with_python} - -DBUILD_PYTHON3=no \ -%endif -%if ! %{with_perl} - -DBUILD_PERL=no \ -%endif -%if ! %{with_ruby} - -DBUILD_RUBY=no \ -%endif .. make -%if %{with_ruby} # Make the freshly build openwsman libraries available to build the gem's # binary extension. export LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib @@ -239,35 +168,20 @@ export CPATH=%{_builddir}/%{name}-%{version}/include/ export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem -%endif - -%if 0%{?with_selinux} -# SELinux policy (originally from selinux-policy-contrib) -# this policy module will override the production module -mkdir selinux -cp -p %{SOURCE100} %{SOURCE101} %{SOURCE102} selinux/ -make -f %{_datadir}/selinux/devel/Makefile %{modulename}.pp -bzip2 -9 %{modulename}.pp -%endif %install cd build -%if %{with_ruby} # Do not install the ruby extension, we are proviging the rubygem- instead. echo -n > bindings/ruby/cmake_install.cmake -%endif -%make_install +make DESTDIR=%{buildroot} install cd .. rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la -%if %{with_ruby} [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb -[ -d %{buildroot}/%{ruby_sitelibdir} ] && rm -f %{buildroot}/%{ruby_sitelibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb -%endif mkdir -p %{buildroot}%{_sysconfdir}/init.d install -m 644 etc/openwsman.conf %{buildroot}/%{_sysconfdir}/openwsman install -m 644 etc/openwsman_client.conf %{buildroot}/%{_sysconfdir}/openwsman @@ -283,7 +197,6 @@ install -m 644 include/wsman-xml.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-xml-binding.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-dispatcher.h %{buildroot}/%{_includedir}/openwsman -%if %{with_ruby} mkdir -p %{buildroot}%{gem_dir} cp -pa ./build%{gem_dir}/* \ %{buildroot}%{gem_dir}/ @@ -292,14 +205,6 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ -%else -rm -f %{buildroot}%{_bindir}/winrs -%endif - -%if 0%{?with_selinux} -install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 -install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/distributed/%{name}.if -%endif %ldconfig_scriptlets -n libwsman1 @@ -317,28 +222,6 @@ rm -f /var/log/wsmand.log %ldconfig_scriptlets client -%if 0%{?with_selinux} -# SELinux contexts are saved so that only affected files can be -# relabeled after the policy module installation -%pre selinux -%selinux_relabel_pre -s %{selinuxtype} - -%post selinux -%selinux_modules_install -s %{selinuxtype} %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 -%selinux_relabel_post -s %{selinuxtype} - -if [ "$1" -le "1" ]; then # First install - # the service needs to be restarted for the custom label to be applied - %systemd_postun_with_restart openwsmand.service -fi - -%postun selinux -if [ $1 -eq 0 ]; then - %selinux_modules_uninstall -s %{selinuxtype} %{modulename} - %selinux_relabel_post -s %{selinuxtype} -fi -%endif - %files -n libwsman1 %doc AUTHORS COPYING ChangeLog README.md TODO %{_libdir}/libwsman.so.* @@ -351,15 +234,12 @@ fi %{_libdir}/pkgconfig/* %{_libdir}/*.so -%if %{with_python} %files python3 %doc AUTHORS COPYING ChangeLog README.md %{python3_sitearch}/*.so %{python3_sitearch}/*.py %{python3_sitearch}/__pycache__/* -%endif -%if %{with_ruby} %files -n rubygem-%{gem_name} %doc AUTHORS COPYING ChangeLog README.md %dir %{gem_instdir} @@ -367,19 +247,14 @@ fi %{gem_extdir_mri} %exclude %{gem_cache} %{gem_spec} -%endif -%if %{with_ruby} %files -n rubygem-%{gem_name}-doc %doc %{gem_docdir} -%endif -%if %{with_perl} %files perl %doc AUTHORS COPYING ChangeLog README.md %{perl_vendorarch}/openwsman.so %{perl_vendorlib}/openwsman.pm -%endif %files server %doc AUTHORS COPYING ChangeLog README.md @@ -399,7 +274,7 @@ fi %dir %{_libdir}/openwsman/plugins %{_libdir}/openwsman/plugins/*.so %{_libdir}/openwsman/plugins/*.so.* -%{_bindir}/openwsmand +%{_sbindir}/openwsmand %{_libdir}/libwsman_server.so.* %{_mandir}/man8/* @@ -408,186 +283,12 @@ fi %{_libdir}/libwsman_clientpp.so.* %config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf -%if %{with_ruby} %files winrs %{_bindir}/winrs -%endif - -%if 0%{?with_selinux} -%files selinux -%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* -%{_datadir}/selinux/devel/include/distributed/%{modulename}.if -%ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} -%endif %changelog -* Thu Jan 08 2026 Vitezslav Crhonek - 2.8.1-13 -- Fix bogus 'sscg' arguments - -* Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 -- Support rdoc 6.16 and above (for ruby4.0) - -* Wed Nov 12 2025 Vitezslav Crhonek - 2.8.1-11 -- Update OpenSSL certificates set up -- Fix ruby binding, enable it - -* Fri Sep 19 2025 Python Maint - 2.8.1-10 -- Rebuilt for Python 3.14.0rc3 bytecode - -* Fri Aug 15 2025 Python Maint - 2.8.1-9 -- Rebuilt for Python 3.14.0rc2 bytecode - -* Thu Jul 24 2025 Fedora Release Engineering - 2.8.1-8 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Jul 07 2025 Jitka Plesnikova - 2.8.1-7 -- Perl 5.42 rebuild - -* Tue Jun 17 2025 Vitezslav Crhonek - 2.8.1-6 -- Update to better support post-quantum cryptography - -* Mon Jun 09 2025 Python Maint - 2.8.1-5 -- Rebuilt for Python 3.14 - -* Mon Jun 09 2025 Vitezslav Crhonek - 2.8.1-4 -- Remove deprecated path from systemd service file - -* Tue Jun 03 2025 Python Maint - 2.8.1-3 -- Rebuilt for Python 3.14 - -* Thu Apr 10 2025 Vitezslav Crhonek - 2.8.1-2 -- Build winrs only when ruby binding is enabled - -* Mon Apr 07 2025 Vitezslav Crhonek - 2.8.1-1 -- Update to openwsman-2.8.1 - -* Fri Feb 28 2025 Vitezslav Crhonek - 2.7.2-16 -- Update minimum required cmake version - -* Sat Feb 01 2025 Björn Esser - 2.7.2-15 -- Add explicit BR: libxcrypt-devel - -* Thu Jan 23 2025 Vitezslav Crhonek - 2.7.2-14 -- Fix FTBFS with GCC 15, bin and sbin unification - -* Fri Jan 17 2025 Fedora Release Engineering - 2.7.2-13 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Wed Jan 08 2025 Mamoru TASAKA - 2.7.2-12 -- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 - -* Thu Jul 18 2024 Fedora Release Engineering - 2.7.2-11 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Tue Jun 25 2024 Vitezslav Crhonek - 2.7.2-10 -- Rebuild - Resolves: #2290726 - -* Tue Jun 18 2024 Python Maint - 2.7.2-9 -- Rebuilt for Python 3.13 - -* Wed Jun 12 2024 Jitka Plesnikova - 2.7.2-8 -- Perl 5.40 rebuild - -* Fri Jun 07 2024 Python Maint - 2.7.2-7 -- Rebuilt for Python 3.13 - -* Fri May 10 2024 Vitezslav Crhonek - 2.7.2-6 -- Update license tags in subpackages to SPDX format - -* Thu Jan 25 2024 Fedora Release Engineering - 2.7.2-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Mon Jan 22 2024 Vitezslav Crhonek - 2.7.2-4 -- Fix FTBFS - Resolves: #2259165 - -* Sun Jan 21 2024 Fedora Release Engineering - 2.7.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Wed Jan 03 2024 Mamoru TASAKA - 2.7.2-2 -- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 - -* Thu Aug 31 2023 Vitezslav Crhonek - 2.7.2-1 -- Update to openwsman-2.7.2 - -* Thu Jul 20 2023 Fedora Release Engineering - 2.7.1-14 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Tue Jul 11 2023 Jitka Plesnikova - 2.7.1-13 -- Perl 5.38 rebuild - -* Wed Jun 14 2023 Python Maint - 2.7.1-12 -- Rebuilt for Python 3.12 - -* Tue Feb 14 2023 Vitezslav Crhonek - 2.7.1-11 -- SPDX migration - -* Thu Jan 19 2023 Fedora Release Engineering - 2.7.1-10 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Wed Jan 04 2023 Mamoru TASAKA - 2.7.1-9 -- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 - -* Fri Oct 21 2022 Vitezslav Crhonek - 2.7.1-8 -- Fix Ruby bindings for swig 4.1 (backported from upstream) - Resolves: #2136510 -- Remove mixed use of spaces and tabs from spec file - -* Fri Jul 22 2022 Fedora Release Engineering - 2.7.1-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Wed Jul 20 2022 Vitezslav Crhonek - 2.7.1-6 -- Improve handling of HTTP 401 Unauthorized - -* Wed Jun 15 2022 Python Maint - 2.7.1-5 -- Rebuilt for Python 3.11 - -* Mon May 30 2022 Jitka Plesnikova - 2.7.1-4 -- Perl 5.36 rebuild - -* Thu Jan 27 2022 Mamoru TASAKA - 2.7.1-3 -- F-36: rebuild against ruby31 - -* Thu Jan 20 2022 Fedora Release Engineering - 2.7.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Thu Nov 11 2021 Vitezslav Crhonek - 2.7.1-1 -- Update to openwsman-2.7.1 - -* Tue Sep 14 2021 Sahana Prasad - 2.7.0-6 -- Rebuilt with OpenSSL 3.0.0 - -* Thu Jul 22 2021 Fedora Release Engineering - 2.7.0-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Tue Jun 08 2021 Vitezslav Crhonek - 2.7.0-4 -- Incorporate -selinux subpackage - See https://fedoraproject.org/wiki/SELinux/IndependentPolicy - -* Fri Jun 04 2021 Python Maint - 2.7.0-3 -- Rebuilt for Python 3.10 - -* Fri May 21 2021 Jitka Plesnikova - 2.7.0-2 -- Perl 5.34 rebuild - -* Tue Mar 09 2021 Vitezslav Crhonek - 2.7.0-1 -- Update to openwsman-2.7.0 (thanks for a patch to Bastian Germann) - -* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2.6.8-20 -- Rebuilt for updated systemd-rpm-macros - See https://pagure.io/fesco/issue/2583. - -* Tue Jan 26 2021 Fedora Release Engineering - 2.6.8-19 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Wed Jan 06 2021 Mamoru TASAKA - 2.6.8-18 -- F-34: rebuild against ruby 3.0 - -* Tue Sep 22 2020 Vitezslav Crhonek - 2.6.8-17 -- Use make macros, patch by Tom Stellard - (https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro) -- Update flags, enable LTO +* Wed Mar 10 2021 Vitezslav Crhonek - 2.6.8-17 +- Fix FTBFS (update flags, enable LTO) - Remove RANDFILE and increase default bits in ssleay.conf * Tue Jul 28 2020 Fedora Release Engineering - 2.6.8-16 diff --git a/openwsman.te b/openwsman.te deleted file mode 100644 index e00816c..0000000 --- a/openwsman.te +++ /dev/null @@ -1,74 +0,0 @@ -policy_module(openwsman, 1.0.0) - -######################################## -# -# Declarations -# - -type openwsman_t; -type openwsman_exec_t; -init_daemon_domain(openwsman_t, openwsman_exec_t) - -type openwsman_tmp_t; -files_tmp_file(openwsman_tmp_t) - -type openwsman_tmpfs_t; -files_tmpfs_file(openwsman_tmpfs_t) - -type openwsman_log_t; -logging_log_file(openwsman_log_t) - -type openwsman_run_t; -files_pid_file(openwsman_run_t) - -type openwsman_unit_file_t; -systemd_unit_file(openwsman_unit_file_t) - -######################################## -# -# openwsman local policy -# - -allow openwsman_t self:capability setuid; - -allow openwsman_t self:process { fork }; -allow openwsman_t self:fifo_file rw_fifo_file_perms; -allow openwsman_t self:unix_stream_socket create_stream_socket_perms; -allow openwsman_t self:tcp_socket { accept create_socket_perms listen }; - -manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) -manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) -files_tmp_filetrans(openwsman_t, openwsman_tmp_t, { dir file }) - -manage_files_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) -manage_dirs_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) -fs_tmpfs_filetrans(openwsman_t, openwsman_tmpfs_t, { dir file }) - -manage_files_pattern(openwsman_t, openwsman_log_t, openwsman_log_t) -logging_log_filetrans(openwsman_t, openwsman_log_t, { file }) - -manage_files_pattern(openwsman_t, openwsman_run_t, openwsman_run_t) -files_pid_filetrans(openwsman_t, openwsman_run_t, { file }) - -auth_use_nsswitch(openwsman_t) -auth_domtrans_chkpwd(openwsman_t) - -corenet_tcp_connect_pegasus_https_port(openwsman_t) -corenet_tcp_bind_vnc_port(openwsman_t) -corenet_tcp_bind_http_port(openwsman_t) - -dev_read_urand(openwsman_t) - -logging_send_syslog_msg(openwsman_t) -logging_send_audit_msgs(openwsman_t) - -optional_policy(` - sblim_stream_connect_sfcbd(openwsman_t) - sblim_rw_semaphores_sfcbd(openwsman_t) - sblim_getattr_exec_sfcbd(openwsman_t) -') - -optional_policy(` - unconfined_domain(openwsman_t) -') - diff --git a/openwsmand.service b/openwsmand.service index a42b11f..e10c75d 100644 --- a/openwsmand.service +++ b/openwsmand.service @@ -6,7 +6,7 @@ After=syslog.target Type=forking ExecStart=/usr/sbin/openwsmand -S ExecStartPre=/etc/openwsman/owsmantestcert.sh -PIDFile=/run/wsmand.pid +PIDFile=/var/run/wsmand.pid [Install] WantedBy=multi-user.target diff --git a/plans/basic.fmf b/plans/basic.fmf deleted file mode 100644 index efb100f..0000000 --- a/plans/basic.fmf +++ /dev/null @@ -1,9 +0,0 @@ -summary: Basic test plan -prepare: - how: install - package: - - openwsman-server -discover: - how: fmf -execute: - how: tmt diff --git a/rpminspect.yaml b/rpminspect.yaml deleted file mode 100644 index 765cfc9..0000000 --- a/rpminspect.yaml +++ /dev/null @@ -1,5 +0,0 @@ ---- -badfuncs: - allowed: - /usr/sbin/openwsmand: - - inet_ntoa diff --git a/sources b/sources index 383285d..80e25cc 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.8.1.tar.gz) = 3c72b6778269186108e48203a9c37f1e4ea8ff532013a80be6af3c6e8d2bf89343233287bc4eb2e955b8db4b7cf6d20818f77423781f6fdb52a6317a7e8bc972 +SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 diff --git a/tests/post-quantum-cryptography/main.fmf b/tests/post-quantum-cryptography/main.fmf deleted file mode 100644 index 51ba4e2..0000000 --- a/tests/post-quantum-cryptography/main.fmf +++ /dev/null @@ -1,6 +0,0 @@ -summary: Post-quantum cryptography support test -author: Vitezslav Crhonek -contact: Vitezslav Crhonek -require: patch -duration: 10m -test: ./runtest.sh diff --git a/tests/post-quantum-cryptography/runtest.sh b/tests/post-quantum-cryptography/runtest.sh deleted file mode 100755 index a09dda5..0000000 --- a/tests/post-quantum-cryptography/runtest.sh +++ /dev/null @@ -1,92 +0,0 @@ -#!/bin/sh -eux - -function check_key_and_cert() -{ - echo -e "\n===== key info" - ssh-keygen -l -f /etc/openwsman/serverkey.pem || : - file /etc/openwsman/serverkey.pem - echo -e "\n\n\n" - - echo -e "\n===== cert info" - openssl x509 -in /etc/openwsman/servercert.pem --text --noout - echo -e "\n\n\n" -} - -function test_key_exchange() -{ - echo -e "\n===== check that it uses TLS 1.3 and the X25519MLKEM768 key exchange by default if the peer supports it" - openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert.pem -contact: Vitezslav Crhonek -require: sscg -duration: 10m -test: ./runtest.sh diff --git a/tests/sscg-generated-certificates/runtest.sh b/tests/sscg-generated-certificates/runtest.sh deleted file mode 100755 index 459ba4b..0000000 --- a/tests/sscg-generated-certificates/runtest.sh +++ /dev/null @@ -1,17 +0,0 @@ -#!/bin/sh -ux - -# remove previously generated SSL files -rm -rf /etc/openwsman/{servercert,serverkey}*.pem /etc/openwsman/ca.crt - -# remove SSL fallback to relly really just on sscg -cp /etc/openwsman/owsmangencert.sh /etc/openwsman/test-script.sh -sed -i 's/^selfsign_sscg ||.*/selfsign_sscg/' /etc/openwsman/test-script.sh - -# generate new SSL files using sscg -/etc/openwsman/test-script.sh - -# check that SSL files were generated -[ -f /etc/openwsman/servercert.pem ] && [ -f /etc/openwsman/serverkey.pem ] || { echo "Error: SSL files missing"; exit 1; } - -# try to start the service -systemctl start openwsmand