From 86820ef4bec0de1557d1dfe3f19786392b5ca640 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 22 Sep 2020 14:52:16 +0200 Subject: [PATCH 01/68] Use make macros, update flags, enable LTO, update ssleay.conf --- openwsman-2.6.8-update-ssleay-conf.patch | 15 +++++++++++++++ openwsman.spec | 21 ++++++++++++--------- 2 files changed, 27 insertions(+), 9 deletions(-) create mode 100644 openwsman-2.6.8-update-ssleay-conf.patch diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch new file mode 100644 index 0000000..15c5c74 --- /dev/null +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -0,0 +1,15 @@ +diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf +--- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 +@@ -2,10 +2,8 @@ + # SSLeay example configuration file. + # + +-RANDFILE = /dev/random +- + [ req ] +-default_bits = 1024 ++default_bits = 2048 + default_keyfile = privkey.pem + distinguished_name = req_distinguished_name + diff --git a/openwsman.spec b/openwsman.spec index 7b19ae0..8c33e99 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 16%{?dist} +Release: 17%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -22,6 +22,7 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch Patch6: openwsman-2.6.8-CVE-2019-3816.patch Patch7: openwsman-2.6.8-CVE-2019-3833.patch +Patch8: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -132,13 +133,9 @@ You can use it to send shell commands to a remote Windows hosts. %patch5 -p1 -b .libcurl-error-codes-update %patch6 -p1 -b .CVE-2019-3816 %patch7 -p1 -b .CVE-2019-3833 +%patch8 -p1 -b .update-ssleay-conf %build -# We override CFLAGS/LDFLAGS below and force PIE executables, which is generally -# fine, except that it ultimately tries to mix PIC and PIE which is a no-no -# and triggers errors with LTO -# Disable LTO -%define _lto_cflags %{nil} # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -146,8 +143,8 @@ rm -rf build mkdir build export RPM_OPT_FLAGS="$RPM_OPT_FLAGS -DFEDORA -DNO_SSL_CALLBACK" -export CFLAGS="-D_GNU_SOURCE -fPIE -DPIE" -export LDFLAGS="$LDFLAGS -Wl,-z,now -pie" +export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" +export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ -DCMAKE_INSTALL_PREFIX=/usr \ @@ -178,7 +175,7 @@ cd build # Do not install the ruby extension, we are proviging the rubygem- instead. echo -n > bindings/ruby/cmake_install.cmake -make DESTDIR=%{buildroot} install +%make_install cd .. rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la @@ -290,6 +287,12 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Sep 22 2020 Vitezslav Crhonek - 2.6.8-17 +- Use make macros, patch by Tom Stellard + (https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro) +- Update flags, enable LTO +- Remove RANDFILE and increase default bits in ssleay.conf + * Tue Jul 28 2020 Fedora Release Engineering - 2.6.8-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From ed78e5cc80bf4a4d1c9b9e1498fdee1215aada90 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 6 Jan 2021 22:35:31 +0900 Subject: [PATCH 02/68] F-34: rebuild against ruby 3.0 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8c33e99..24055e4 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 17%{?dist} +Release: 18%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -287,6 +287,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Jan 06 2021 Mamoru TASAKA - 2.6.8-18 +- F-34: rebuild against ruby 3.0 + * Tue Sep 22 2020 Vitezslav Crhonek - 2.6.8-17 - Use make macros, patch by Tom Stellard (https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro) From c9696b4337dfc044966b30e629f3c82fdf3800c1 Mon Sep 17 00:00:00 2001 From: Tom Stellard Date: Thu, 7 Jan 2021 06:43:20 +0000 Subject: [PATCH 03/68] Add BuildRequires: make https://fedoraproject.org/wiki/Changes/Remove_make_from_BuildRoot --- openwsman.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/openwsman.spec b/openwsman.spec index 24055e4..771cdec 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -23,6 +23,7 @@ Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch Patch6: openwsman-2.6.8-CVE-2019-3816.patch Patch7: openwsman-2.6.8-CVE-2019-3833.patch Patch8: openwsman-2.6.8-update-ssleay-conf.patch +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter From 421a2a247fb8062e6e15fd4136e163950156b4f8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 26 Jan 2021 22:39:09 +0000 Subject: [PATCH 04/68] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 771cdec..d9b286e 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 18%{?dist} +Release: 19%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -288,6 +288,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jan 26 2021 Fedora Release Engineering - 2.6.8-19 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Wed Jan 06 2021 Mamoru TASAKA - 2.6.8-18 - F-34: rebuild against ruby 3.0 From 2893dc05061ffddf64d572e7c209d065cfd148c5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 2 Mar 2021 16:13:08 +0100 Subject: [PATCH 05/68] Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d9b286e..178444b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 19%{?dist} +Release: 20%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -288,6 +288,10 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2.6.8-20 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + * Tue Jan 26 2021 Fedora Release Engineering - 2.6.8-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From ed117179785e4b28f5dd4a6ff5c992994895dc4f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 9 Mar 2021 11:29:15 +0100 Subject: [PATCH 06/68] Update to openwsman-2.7.0 --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 52 +++++----- ...man-2.6.5-libcurl-error-codes-update.patch | 27 ------ openwsman-2.6.8-CVE-2019-3816.patch | 79 ---------------- openwsman-2.6.8-CVE-2019-3833.patch | 94 ------------------- openwsman.spec | 17 ++-- sources | 1 + 8 files changed, 40 insertions(+), 234 deletions(-) delete mode 100644 openwsman-2.6.5-libcurl-error-codes-update.patch delete mode 100644 openwsman-2.6.8-CVE-2019-3816.patch delete mode 100644 openwsman-2.6.8-CVE-2019-3833.patch diff --git a/.gitignore b/.gitignore index 490fdf3..40748df 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.6.8.tar.gz +/v2.7.0.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 1a4e76e..6b5ebfb 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.8/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.0/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 98f6bc2..5d64644 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/src/server/shttpd/compat_unix.h ---- openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/compat_unix.h 2018-11-22 13:30:10.756423510 +0100 +diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h +--- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,10 +12,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/server/shttpd/io_ssl.c ---- openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/io_ssl.c 2018-11-22 13:30:10.757423510 +0100 -@@ -11,23 +11,6 @@ +diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c +--- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100 +@@ -11,28 +11,6 @@ #include "defs.h" #if !defined(NO_SSL) @@ -29,8 +29,13 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser - {"SSL_set_fd", {0}}, - {"SSL_new", {0}}, - {"SSL_CTX_new", {0}}, +-#if OPENSSL_VERSION_NUMBER < 0x10100000L - {"SSLv23_server_method", {0}}, - {"SSL_library_init", {0}}, +-#else +- {"TLS_server_method", {0}}, +- {"OPENSSL_init_ssl", {0}}, +-#endif - {"SSL_CTX_use_PrivateKey_file", {0}}, - {"SSL_CTX_use_certificate_file",{0}}, - {NULL, {0}} @@ -39,10 +44,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2018-11-22 13:30:41.314416695 +0100 -@@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c +--- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100 +@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -59,20 +64,20 @@ diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/ser - } - /* Initialize SSL crap */ -+ debug("Initialize SSL"); -+ SSL_load_error_strings(); -+#if OPENSSL_VERSION_NUMBER >= 0x10100000L -+ OPENSSL_init_ssl(0, NULL); -+#else - SSL_library_init(); -+#endif + #if OPENSSL_VERSION_NUMBER < 0x10100000L + SSL_library_init(); if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) + #else +- OPENSSL_init_ssl(); ++ OPENSSL_init_ssl(0, NULL); + if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) + #endif _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server/shttpd/ssl.h ---- openwsman-2.6.8/src/server/shttpd/ssl.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/ssl.h 2018-11-22 13:30:10.757423510 +0100 -@@ -12,52 +12,4 @@ +diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h +--- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100 +@@ -12,55 +12,4 @@ #include @@ -120,6 +125,9 @@ diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server -#if OPENSSL_VERSION_NUMBER < 0x10100000L -#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() -#define SSL_library_init() (* (int (*)(void)) FUNC(10))() +-#else +-#define TLS_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() +-#define OPENSSL_init_ssl() (* (int (*)(void)) FUNC(10))() #endif -#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(11))((x), (y), (z)) diff --git a/openwsman-2.6.5-libcurl-error-codes-update.patch b/openwsman-2.6.5-libcurl-error-codes-update.patch deleted file mode 100644 index 82ee51f..0000000 --- a/openwsman-2.6.5-libcurl-error-codes-update.patch +++ /dev/null @@ -1,27 +0,0 @@ -diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c ---- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2018-11-14 13:53:27.442138557 +0100 -+++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-11-14 14:11:28.508714204 +0100 -@@ -186,16 +186,23 @@ convert_to_last_error(CURLcode r) - return WS_LASTERR_SSL_CONNECT_ERROR; - case CURLE_BAD_FUNCTION_ARGUMENT: - return WS_LASTERR_CURL_BAD_FUNCTION_ARG; -+#if LIBCURL_VERSION_NUM < 0x073E00 - case CURLE_SSL_PEER_CERTIFICATE: - return WS_LASTERR_SSL_PEER_CERTIFICATE; -+#endif - case CURLE_SSL_ENGINE_NOTFOUND: - return WS_LASTERR_SSL_ENGINE_NOTFOUND; - case CURLE_SSL_ENGINE_SETFAILED: - return WS_LASTERR_SSL_ENGINE_SETFAILED; - case CURLE_SSL_CERTPROBLEM: - return WS_LASTERR_SSL_CERTPROBLEM; -+#if LIBCURL_VERSION_NUM < 0x073E00 - case CURLE_SSL_CACERT: - return WS_LASTERR_SSL_CACERT; -+#else -+ case CURLE_PEER_FAILED_VERIFICATION: -+ return WS_LASTERR_SSL_PEER_CERTIFICATE; -+#endif - #if LIBCURL_VERSION_NUM > 0x70C01 - case CURLE_SSL_ENGINE_INITFAILED: - return WS_LASTERR_SSL_ENGINE_INITFAILED; diff --git a/openwsman-2.6.8-CVE-2019-3816.patch b/openwsman-2.6.8-CVE-2019-3816.patch deleted file mode 100644 index aa8835f..0000000 --- a/openwsman-2.6.8-CVE-2019-3816.patch +++ /dev/null @@ -1,79 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 08:52:06.112090942 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:01:15.496156789 +0100 -@@ -336,10 +336,12 @@ date_to_epoch(const char *s) - } - - static void --remove_double_dots(char *s) -+remove_all_leading_dots(char *s) - { - char *p = s; - -+ while (*s != '\0' && *s == '.') s++; -+ - while (*s != '\0') { - *p++ = *s++; - if (s[-1] == '/' || s[-1] == '\\') -@@ -546,7 +548,7 @@ decide_what_to_do(struct conn *c) - *c->query++ = '\0'; - - _shttpd_url_decode(c->uri, strlen(c->uri), c->uri, strlen(c->uri) + 1); -- remove_double_dots(c->uri); -+ remove_all_leading_dots(c->uri); - - root = c->ctx->options[OPT_ROOT]; - if (strlen(c->uri) + strlen(root) >= sizeof(path)) { -@@ -556,6 +558,7 @@ decide_what_to_do(struct conn *c) - - (void) _shttpd_snprintf(path, sizeof(path), "%s%s", root, c->uri); - -+ DBG(("decide_what_to_do -> processed path: [%s]", path)); - /* User may use the aliases - check URI for mount point */ - if (is_alias(c->ctx, c->uri, &alias_uri, &alias_path) != NULL) { - (void) _shttpd_snprintf(path, sizeof(path), "%.*s%s", -@@ -572,7 +575,10 @@ decide_what_to_do(struct conn *c) - if ((ruri = _shttpd_is_registered_uri(c->ctx, c->uri)) != NULL) { - _shttpd_setup_embedded_stream(c, - ruri->callback, ruri->callback_data); -- } else -+ } else { -+ _shttpd_send_server_error(c, 403, "Forbidden"); -+ } -+#if 0 - if (strstr(path, HTPASSWD)) { - /* Do not allow to view passwords files */ - _shttpd_send_server_error(c, 403, "Forbidden"); -@@ -656,6 +662,7 @@ decide_what_to_do(struct conn *c) - } else { - _shttpd_send_server_error(c, 500, "Internal Error"); - } -+#endif - } - - static int -diff -up openwsman-2.6.8/src/server/wsmand.c.orig openwsman-2.6.8/src/server/wsmand.c ---- openwsman-2.6.8/src/server/wsmand.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/wsmand.c 2019-03-13 09:03:25.919181279 +0100 -@@ -198,6 +198,10 @@ static void daemonize(void) - int fd; - char *pid; - -+ /* Change our CWD to / */ -+ i = chdir("/"); -+ assert(i == 0); -+ - if (wsmand_options_get_foreground_debug() > 0) { - return; - } -@@ -214,10 +218,6 @@ static void daemonize(void) - log_pid = 0; - setsid(); - -- /* Change our CWD to / */ -- i=chdir("/"); -- assert(i == 0); -- - /* Close all file descriptors. */ - for (i = getdtablesize(); i >= 0; --i) - close(i); diff --git a/openwsman-2.6.8-CVE-2019-3833.patch b/openwsman-2.6.8-CVE-2019-3833.patch deleted file mode 100644 index 301724f..0000000 --- a/openwsman-2.6.8-CVE-2019-3833.patch +++ /dev/null @@ -1,94 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 09:32:32.417633057 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:58:04.482486589 +0100 -@@ -705,11 +705,11 @@ parse_http_request(struct conn *c) - _shttpd_send_server_error(c, 500, "Cannot allocate request"); - } - -+ io_inc_tail(&c->rem.io, req_len); -+ - if (c->loc.flags & FLAG_CLOSED) - return; - -- io_inc_tail(&c->rem.io, req_len); -- - DBG(("Conn %d: parsing request: [%.*s]", c->rem.chan.sock, req_len, s)); - c->rem.flags |= FLAG_HEADERS_PARSED; - -@@ -975,7 +975,7 @@ write_stream(struct stream *from, struct - } - - --static void -+static int - connection_desctructor(struct llhead *lp) - { - struct conn *c = LL_ENTRY(lp, struct conn, link); -@@ -999,7 +999,8 @@ connection_desctructor(struct llhead *lp - * Check the "Connection: " header before we free c->request - * If it its 'keep-alive', then do not close the connection - */ -- do_close = (c->ch.connection.v_vec.len >= vec.len && -+ do_close = c->rem.flags & FLAG_CLOSED || -+ (c->ch.connection.v_vec.len >= vec.len && - !_shttpd_strncasecmp(vec.ptr,c->ch.connection.v_vec.ptr,vec.len)) || - (c->major_version < 1 || - (c->major_version >= 1 && c->minor_version < 1)); -@@ -1021,7 +1022,7 @@ connection_desctructor(struct llhead *lp - io_clear(&c->loc.io); - c->birth_time = _shttpd_current_time; - if (io_data_len(&c->rem.io) > 0) -- process_connection(c, 0, 0); -+ return 1; - } else { - if (c->rem.io_class != NULL) - c->rem.io_class->close(&c->rem); -@@ -1032,6 +1033,8 @@ connection_desctructor(struct llhead *lp - - free(c); - } -+ -+ return 0; - } - - static void -@@ -1039,7 +1042,7 @@ worker_destructor(struct llhead *lp) - { - struct worker *worker = LL_ENTRY(lp, struct worker, link); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - -@@ -1072,6 +1075,8 @@ add_to_set(int fd, fd_set *set, int *max - static void - process_connection(struct conn *c, int remote_ready, int local_ready) - { -+again: -+ - /* Read from remote end if it is ready */ - if (remote_ready && io_space_len(&c->rem.io)) - read_stream(&c->rem); -@@ -1100,7 +1105,11 @@ process_connection(struct conn *c, int r - if ((_shttpd_current_time > c->expire_time) || - (c->rem.flags & FLAG_CLOSED) || - ((c->loc.flags & FLAG_CLOSED) && !io_data_len(&c->loc.io))) -- connection_desctructor(&c->link); -+ if (connection_desctructor(&c->link)) { -+ remote_ready = 0; -+ local_ready = 0; -+ goto again; -+ } - } - - static int -@@ -1642,7 +1651,7 @@ worker_function(void *param) - while (worker->exit_flag == 0) - poll_worker(worker, 1000 * 10); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - diff --git a/openwsman.spec b/openwsman.spec index 178444b..7483631 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -2,8 +2,8 @@ %global gem_name %{name} Name: openwsman -Version: 2.6.8 -Release: 20%{?dist} +Version: 2.7.0 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -19,10 +19,7 @@ Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch -Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch -Patch6: openwsman-2.6.8-CVE-2019-3816.patch -Patch7: openwsman-2.6.8-CVE-2019-3833.patch -Patch8: openwsman-2.6.8-update-ssleay-conf.patch +Patch5: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -131,10 +128,7 @@ You can use it to send shell commands to a remote Windows hosts. %patch2 -p1 -b .ruby-binding-build %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line -%patch5 -p1 -b .libcurl-error-codes-update -%patch6 -p1 -b .CVE-2019-3816 -%patch7 -p1 -b .CVE-2019-3833 -%patch8 -p1 -b .update-ssleay-conf +%patch5 -p1 -b .update-ssleay-conf %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -288,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Mar 09 2021 Vitezslav Crhonek - 2.7.0-1 +- Update to openwsman-2.7.0 (thanks for a patch to Bastian Germann) + * Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2.6.8-20 - Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. diff --git a/sources b/sources index 80e25cc..d5e209f 100644 --- a/sources +++ b/sources @@ -1,2 +1,3 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 +SHA512 (v2.7.0.tar.gz) = e61792eafd09e3608c736091d2742049086adaf5fffcda9391e4712ed1dedf3a533546a6af61ea6ce49d4cf4fb3649cb168f20260c4e975797395d6e565c6c37 From 3d6dcc1673a8ed8f114b1b9041ec28162ee7438a Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 10 Mar 2021 12:23:40 +0100 Subject: [PATCH 07/68] Fix FTBFS, Remove RANDFILE and increase default bits in ssleay.conf --- openwsman-2.6.8-update-ssleay-conf.patch | 15 +++++++++++++++ openwsman.spec | 17 +++++++++-------- 2 files changed, 24 insertions(+), 8 deletions(-) create mode 100644 openwsman-2.6.8-update-ssleay-conf.patch diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch new file mode 100644 index 0000000..15c5c74 --- /dev/null +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -0,0 +1,15 @@ +diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf +--- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 +@@ -2,10 +2,8 @@ + # SSLeay example configuration file. + # + +-RANDFILE = /dev/random +- + [ req ] +-default_bits = 1024 ++default_bits = 2048 + default_keyfile = privkey.pem + distinguished_name = req_distinguished_name + diff --git a/openwsman.spec b/openwsman.spec index 7b19ae0..b8734e8 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 16%{?dist} +Release: 17%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -22,6 +22,7 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch Patch6: openwsman-2.6.8-CVE-2019-3816.patch Patch7: openwsman-2.6.8-CVE-2019-3833.patch +Patch8: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -132,13 +133,9 @@ You can use it to send shell commands to a remote Windows hosts. %patch5 -p1 -b .libcurl-error-codes-update %patch6 -p1 -b .CVE-2019-3816 %patch7 -p1 -b .CVE-2019-3833 +%patch8 -p1 -b .update-ssleay-conf %build -# We override CFLAGS/LDFLAGS below and force PIE executables, which is generally -# fine, except that it ultimately tries to mix PIC and PIE which is a no-no -# and triggers errors with LTO -# Disable LTO -%define _lto_cflags %{nil} # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -146,8 +143,8 @@ rm -rf build mkdir build export RPM_OPT_FLAGS="$RPM_OPT_FLAGS -DFEDORA -DNO_SSL_CALLBACK" -export CFLAGS="-D_GNU_SOURCE -fPIE -DPIE" -export LDFLAGS="$LDFLAGS -Wl,-z,now -pie" +export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" +export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ -DCMAKE_INSTALL_PREFIX=/usr \ @@ -290,6 +287,10 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Mar 10 2021 Vitezslav Crhonek - 2.6.8-17 +- Fix FTBFS (update flags, enable LTO) +- Remove RANDFILE and increase default bits in ssleay.conf + * Tue Jul 28 2020 Fedora Release Engineering - 2.6.8-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From 994e5efb43a0c75e86fa44fe499a374fe9843890 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Fri, 21 May 2021 12:45:21 +0200 Subject: [PATCH 08/68] Perl 5.34 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 7483631..6bb5c54 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.7.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -282,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri May 21 2021 Jitka Plesnikova - 2.7.0-2 +- Perl 5.34 rebuild + * Tue Mar 09 2021 Vitezslav Crhonek - 2.7.0-1 - Update to openwsman-2.7.0 (thanks for a patch to Bastian Germann) From 83bb22a627eb9e9a4d8da9315718fdcca935b340 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 4 Jun 2021 20:14:09 +0200 Subject: [PATCH 09/68] Rebuilt for Python 3.10 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 6bb5c54..5a8c795 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.7.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -282,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri Jun 04 2021 Python Maint - 2.7.0-3 +- Rebuilt for Python 3.10 + * Fri May 21 2021 Jitka Plesnikova - 2.7.0-2 - Perl 5.34 rebuild From 959c5926888713e417d6fd7bdf111f56743d91a9 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 13:13:35 +0200 Subject: [PATCH 10/68] Add SELinux subpackage Signed-off-by: Vitezslav Crhonek --- openwsman.fc | 7 ++++ openwsman.if | 79 +++++++++++++++++++++++++++++++++++++++++++ openwsman.spec | 81 ++++++++++++++++++++++++++++++++++++++++++++- openwsman.te | 74 +++++++++++++++++++++++++++++++++++++++++ tests/tests-DSP.yml | 37 +++++++++++++++++++++ 5 files changed, 277 insertions(+), 1 deletion(-) create mode 100644 openwsman.fc create mode 100644 openwsman.if create mode 100644 openwsman.te create mode 100644 tests/tests-DSP.yml diff --git a/openwsman.fc b/openwsman.fc new file mode 100644 index 0000000..00d0643 --- /dev/null +++ b/openwsman.fc @@ -0,0 +1,7 @@ +/usr/lib/systemd/system/openwsmand.* -- gen_context(system_u:object_r:openwsman_unit_file_t,s0) + +/usr/sbin/openwsmand -- gen_context(system_u:object_r:openwsman_exec_t,s0) + +/var/log/wsmand.* -- gen_context(system_u:object_r:openwsman_log_t,s0) + +/var/run/wsmand.* -- gen_context(system_u:object_r:openwsman_run_t,s0) diff --git a/openwsman.if b/openwsman.if new file mode 100644 index 0000000..747853a --- /dev/null +++ b/openwsman.if @@ -0,0 +1,79 @@ +## WS-Management Server + +######################################## +## +## Execute openwsman in the openwsman domin. +## +## +## +## Domain allowed to transition. +## +## +# +interface(`openwsman_domtrans',` + gen_require(` + type openwsman_t, openwsman_exec_t; + ') + + corecmd_search_bin($1) + domtrans_pattern($1, openwsman_exec_t, openwsman_t) +') +######################################## +## +## Execute openwsman server in the openwsman domain. +## +## +## +## Domain allowed to transition. +## +## +# +interface(`openwsman_systemctl',` + gen_require(` + type openwsman_t; + type openwsman_unit_file_t; + ') + + systemd_exec_systemctl($1) + init_reload_services($1) + systemd_read_fifo_file_passwd_run($1) + allow $1 openwsman_unit_file_t:file read_file_perms; + allow $1 openwsman_unit_file_t:service manage_service_perms; + + ps_process_pattern($1, openwsman_t) +') + + +######################################## +## +## All of the rules required to administrate +## an openwsman environment +## +## +## +## Domain allowed access. +## +## +## +# +interface(`openwsman_admin',` + gen_require(` + type openwsman_t; + type openwsman_unit_file_t; + ') + + allow $1 openwsman_t:process { signal_perms }; + ps_process_pattern($1, openwsman_t) + + tunable_policy(`deny_ptrace',`',` + allow $1 openwsman_t:process ptrace; + ') + + openwsman_systemctl($1) + admin_pattern($1, openwsman_unit_file_t) + allow $1 openwsman_unit_file_t:service all_service_perms; + optional_policy(` + systemd_passwd_agent_exec($1) + systemd_read_fifo_file_passwd_run($1) + ') +') diff --git a/openwsman.spec b/openwsman.spec index 5a8c795..4518aad 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,9 +1,15 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} +# defining macros needed by SELinux +%global with_selinux 1 +%global selinuxtype targeted +%global moduletype contrib +%global modulename openwsman + Name: openwsman Version: 2.7.0 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -15,6 +21,11 @@ Source1: openwsmand.8.gz Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre Source3: owsmantestcert.sh +# Source100-102: selinux policy for openwsman, extracted +# from https://github.com/fedora-selinux/selinux-policy +Source100: %{modulename}.te +Source101: %{modulename}.if +Source102: %{modulename}.fc Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch @@ -72,6 +83,11 @@ Openwsman Client libraries. License: BSD Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} +%if 0%{?with_selinux} +# This ensures that the *-selinux package and all it’s dependencies are not pulled +# into containers and other systems that do not use SELinux +Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) +%endif %description server Openwsman Server and service libraries. @@ -121,6 +137,20 @@ Requires: rubygem-%{gem_name} = %{version}-%{release} This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. +%if 0%{?with_selinux} +# SELinux subpackage +%package selinux +Summary: openwsman SELinux policy +BuildArch: noarch +Requires: selinux-policy-%{selinuxtype} +Requires(post): selinux-policy-%{selinuxtype} +BuildRequires: selinux-policy-devel +%{?selinux_requires} + +%description selinux +Custom SELinux policy module +%endif + %prep %setup -q @@ -164,6 +194,15 @@ export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem +%if 0%{?with_selinux} +# SELinux policy (originally from selinux-policy-contrib) +# this policy module will override the production module +mkdir selinux +cp -p %{SOURCE100} %{SOURCE101} %{SOURCE102} selinux/ +make -f %{_datadir}/selinux/devel/Makefile %{modulename}.pp +bzip2 -9 %{modulename}.pp +%endif + %install cd build @@ -201,6 +240,11 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%if 0%{?with_selinux} +install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 +install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}/%{name}.if +%endif + %ldconfig_scriptlets -n libwsman1 %post server @@ -217,6 +261,30 @@ rm -f /var/log/wsmand.log %ldconfig_scriptlets client +%if 0%{?with_selinux} +# SELinux contexts are saved so that only affected files can be +# relabeled after the policy module installation +%pre selinux +%selinux_relabel_pre -s %{selinuxtype} + +%post selinux +%selinux_modules_install -s %{selinuxtype} %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 +%selinux_relabel_post -s %{selinuxtype} + +if [ "$1" -le "1" ]; then # First install + # the service needs to be restarted for the custom label to be applied + %systemd_postun_with_restart openwsmand.service +fi + +%postun selinux +if [ $1 -eq 0 ]; then + %selinux_modules_uninstall -s %{selinuxtype} %{modulename} + %selinux_relabel_post -s %{selinuxtype} + # the service needs to be restarted for the custom label to be removed + %systemd_postun_with_restart openwsmand.service +fi +%endif + %files -n libwsman1 %doc AUTHORS COPYING ChangeLog README.md TODO %{_libdir}/libwsman.so.* @@ -281,7 +349,18 @@ rm -f /var/log/wsmand.log %files winrs %{_bindir}/winrs +%if 0%{?with_selinux} +%files selinux +%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* +%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if +%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} +%endif + %changelog +* Tue Jun 08 2021 Vitezslav Crhonek - 2.7.0-4 +- Incorporate -selinux subpackage + See https://fedoraproject.org/wiki/SELinux/IndependentPolicy + * Fri Jun 04 2021 Python Maint - 2.7.0-3 - Rebuilt for Python 3.10 diff --git a/openwsman.te b/openwsman.te new file mode 100644 index 0000000..3bcd32c --- /dev/null +++ b/openwsman.te @@ -0,0 +1,74 @@ +policy_module(openwsman, 1.0.0) + +######################################## +# +# Declarations +# + +type openwsman_t; +type openwsman_exec_t; +init_daemon_domain(openwsman_t, openwsman_exec_t) + +type openwsman_tmp_t; +files_tmp_file(openwsman_tmp_t) + +type openwsman_tmpfs_t; +files_tmpfs_file(openwsman_tmpfs_t) + +type openwsman_log_t; +logging_log_file(openwsman_log_t) + +type openwsman_run_t; +files_pid_file(openwsman_run_t) + +type openwsman_unit_file_t; +systemd_unit_file(openwsman_unit_file_t) + +######################################## +# +# openwsman local policy +# + +allow openwsman_t self:capability setuid; + +allow openwsman_t self:process { fork }; +allow openwsman_t self:fifo_file rw_fifo_file_perms; +allow openwsman_t self:unix_stream_socket create_stream_socket_perms; +allow openwsman_t self:tcp_socket { create_socket_perms accept listen }; + +manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) +manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) +files_tmp_filetrans(openwsman_t, openwsman_tmp_t, { dir file }) + +manage_files_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) +manage_dirs_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) +fs_tmpfs_filetrans(openwsman_t, openwsman_tmpfs_t, { dir file }) + +manage_files_pattern(openwsman_t, openwsman_log_t, openwsman_log_t) +logging_log_filetrans(openwsman_t, openwsman_log_t, { file }) + +manage_files_pattern(openwsman_t, openwsman_run_t, openwsman_run_t) +files_pid_filetrans(openwsman_t, openwsman_run_t, { file }) + +auth_use_nsswitch(openwsman_t) +auth_domtrans_chkpwd(openwsman_t) + +corenet_tcp_connect_pegasus_https_port(openwsman_t) +corenet_tcp_bind_vnc_port(openwsman_t) +corenet_tcp_bind_http_port(openwsman_t) + +dev_read_urand(openwsman_t) + +logging_send_syslog_msg(openwsman_t) +logging_send_audit_msgs(openwsman_t) + +optional_policy(` + sblim_stream_connect_sfcbd(openwsman_t) + sblim_rw_semaphores_sfcbd(openwsman_t) + sblim_getattr_exec_sfcbd(openwsman_t) +') + +optional_policy(` + unconfined_domain(openwsman_t) +') + diff --git a/tests/tests-DSP.yml b/tests/tests-DSP.yml new file mode 100644 index 0000000..ec2c494 --- /dev/null +++ b/tests/tests-DSP.yml @@ -0,0 +1,37 @@ +- hosts: localhost + + roles: + - role: standard-test-beakerlib + tags: + - classic + repositories: + - repo: https://pagure.io/DSP_test.git + dest: DSP_test + version: master + + tests: + - DSP_test + environment: + # RPM package containing the policy module + TEST_RPM: openwsman-selinux + # policy module name + TEST_POLICY: openwsman + # policy sources will be extracted from corresponding .src.rpm + # policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz") + # or empty string if policy sources are not inside a tar archive + POLICY_TAR: '' + # path to policy sources (in of the tar archive) -- //.(te|if|fc) + # or path in the src.rpm if there is no tar archive -- //.(te|if|fc) + # can contain wildcards (e.g. for versions etc.) + POLICY_PATH: . + + required_packages: + - policycoreutils + - selinux-policy + - selinux-policy-targeted + - setools-console + - libselinux-utils + - rpm + - tar + - git + - openwsman-server From 7553f989a3654b480c6d766265c885b900ed2fcd Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 14:09:19 +0200 Subject: [PATCH 11/68] selinux: order permissions in av rule as per refpolicy style guide https://github.com/SELinuxProject/refpolicy/wiki/StyleGuide Signed-off-by: Vitezslav Crhonek --- openwsman.te | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.te b/openwsman.te index 3bcd32c..e00816c 100644 --- a/openwsman.te +++ b/openwsman.te @@ -34,7 +34,7 @@ allow openwsman_t self:capability setuid; allow openwsman_t self:process { fork }; allow openwsman_t self:fifo_file rw_fifo_file_perms; allow openwsman_t self:unix_stream_socket create_stream_socket_perms; -allow openwsman_t self:tcp_socket { create_socket_perms accept listen }; +allow openwsman_t self:tcp_socket { accept create_socket_perms listen }; manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) From b7c1ef00391897b46bd129a720b694b59a4314ef Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 14:55:12 +0200 Subject: [PATCH 12/68] selinux: update path for interface file Signed-off-by: Vitezslav Crhonek --- openwsman.spec | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 4518aad..400576a 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -4,7 +4,6 @@ # defining macros needed by SELinux %global with_selinux 1 %global selinuxtype targeted -%global moduletype contrib %global modulename openwsman Name: openwsman @@ -242,7 +241,7 @@ cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdi %if 0%{?with_selinux} install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 -install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}/%{name}.if +install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/distributed/%{name}.if %endif %ldconfig_scriptlets -n libwsman1 @@ -352,7 +351,7 @@ fi %if 0%{?with_selinux} %files selinux %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* -%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if +%{_datadir}/selinux/devel/include/distributed/%{modulename}.if %ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} %endif From 07c9612e44c7c28e69d23a4472dda4a8505c68e8 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 22 Jun 2021 10:24:24 +0200 Subject: [PATCH 13/68] Remove %systemd_postun_with_restart from %postun Signed-off-by: Vitezslav Crhonek --- openwsman.spec | 2 -- 1 file changed, 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 400576a..2809a1b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -279,8 +279,6 @@ fi if [ $1 -eq 0 ]; then %selinux_modules_uninstall -s %{selinuxtype} %{modulename} %selinux_relabel_post -s %{selinuxtype} - # the service needs to be restarted for the custom label to be removed - %systemd_postun_with_restart openwsmand.service fi %endif From 22933028149d76c74456404c0ee5ee34ea9a3d11 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 22 Jul 2021 17:23:40 +0000 Subject: [PATCH 14/68] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 2809a1b..1284357 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.0 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jul 22 2021 Fedora Release Engineering - 2.7.0-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Tue Jun 08 2021 Vitezslav Crhonek - 2.7.0-4 - Incorporate -selinux subpackage See https://fedoraproject.org/wiki/SELinux/IndependentPolicy From 7be7155ec263c5e9ab48a28c0ece9b012f7b47a6 Mon Sep 17 00:00:00 2001 From: Sahana Prasad Date: Tue, 14 Sep 2021 19:10:16 +0200 Subject: [PATCH 15/68] Rebuilt with OpenSSL 3.0.0 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1284357..f16bb95 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.0 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Tue Sep 14 2021 Sahana Prasad - 2.7.0-6 +- Rebuilt with OpenSSL 3.0.0 + * Thu Jul 22 2021 Fedora Release Engineering - 2.7.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From 4af778748b31036a25f113328e31e730b355b05f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 11 Nov 2021 12:01:58 +0100 Subject: [PATCH 16/68] Update to openwsman-2.7.1 Signed-off-by: Vitezslav Crhonek --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.8-update-ssleay-conf.patch | 11 ++++------- openwsman.spec | 7 +++++-- sources | 3 +-- 5 files changed, 12 insertions(+), 13 deletions(-) diff --git a/.gitignore b/.gitignore index 40748df..98ec9b4 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.0.tar.gz +/v2.7.1.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 6b5ebfb..1689eb8 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.0/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.1/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch index 15c5c74..c312af5 100644 --- a/openwsman-2.6.8-update-ssleay-conf.patch +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -1,12 +1,9 @@ -diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf ---- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 -@@ -2,10 +2,8 @@ - # SSLeay example configuration file. +diff -up openwsman-2.7.1/etc/ssleay.cnf.orig openwsman-2.7.1/etc/ssleay.cnf +--- openwsman-2.7.1/etc/ssleay.cnf.orig 2021-11-09 08:27:48.577749509 +0100 ++++ openwsman-2.7.1/etc/ssleay.cnf 2021-11-09 08:28:10.499967010 +0100 +@@ -3,7 +3,7 @@ # --RANDFILE = /dev/random -- [ req ] -default_bits = 1024 +default_bits = 2048 diff --git a/openwsman.spec b/openwsman.spec index f16bb95..eba91eb 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -7,8 +7,8 @@ %global modulename openwsman Name: openwsman -Version: 2.7.0 -Release: 6%{?dist} +Version: 2.7.1 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Nov 11 2021 Vitezslav Crhonek - 2.7.1-1 +- Update to openwsman-2.7.1 + * Tue Sep 14 2021 Sahana Prasad - 2.7.0-6 - Rebuilt with OpenSSL 3.0.0 diff --git a/sources b/sources index d5e209f..0675e6c 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 -SHA512 (v2.7.0.tar.gz) = e61792eafd09e3608c736091d2742049086adaf5fffcda9391e4712ed1dedf3a533546a6af61ea6ce49d4cf4fb3649cb168f20260c4e975797395d6e565c6c37 +SHA512 (v2.7.1.tar.gz) = 37738bc5be7b1c3fa961587fca4db74b8e7714fc0641a550682275fbe925b2c8e18a683cf493f4740e479f7461cc98392d3d675f4769f5cf04e7249f1e9ee880 From 407d3e089bb63974ce4d41b87fe49bc7abbfbf00 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jan 2022 22:32:31 +0000 Subject: [PATCH 17/68] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index eba91eb..9e14061 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jan 20 2022 Fedora Release Engineering - 2.7.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Thu Nov 11 2021 Vitezslav Crhonek - 2.7.1-1 - Update to openwsman-2.7.1 From 38d5a113e7c91052dcc3e849dbff9bddfacbf6c5 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Thu, 27 Jan 2022 11:49:31 +0900 Subject: [PATCH 18/68] F-36: rebuild against ruby31 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 9e14061..65b472b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.1 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jan 27 2022 Mamoru TASAKA - 2.7.1-3 +- F-36: rebuild against ruby31 + * Thu Jan 20 2022 Fedora Release Engineering - 2.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From ab115b7b54465fc5b04ed4fa5b55e18f7aacdf5b Mon Sep 17 00:00:00 2001 From: Jay W Date: Wed, 9 Feb 2022 12:21:38 +0000 Subject: [PATCH 19/68] Modify openwsman.spec to allow flatpak builds --- openwsman.spec | 66 +++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 62 insertions(+), 4 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 65b472b..1d4fc61 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -2,9 +2,26 @@ %global gem_name %{name} # defining macros needed by SELinux +# unless running a flatpak build. +%if 0%{?flatpak} +%global with_selinux 0 +%else %global with_selinux 1 %global selinuxtype targeted %global modulename openwsman +%endif + +# Bindings install in the wrong path for a flatpak build; this could be fixed, but +# we don't currently need the bindings for any Flatpak'ed application +%if 0%{?flatpak} +%global with_ruby 0 +%global with_perl 0 +%global with_python 0 +%else +%global with_ruby 1 +%global with_perl 1 +%global with_python 1 +%endif Name: openwsman Version: 2.7.1 @@ -22,19 +39,29 @@ Source2: openwsmand.service Source3: owsmantestcert.sh # Source100-102: selinux policy for openwsman, extracted # from https://github.com/fedora-selinux/selinux-policy +%if 0%{with_selinux} Source100: %{modulename}.te Source101: %{modulename}.if Source102: %{modulename}.fc +%endif Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -BuildRequires: make +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter -BuildRequires: perl-devel perl-generators pkgconfig openssl-devel +%if %{with_python} +BuildRequires: python3 python3-devel +%endif +%if %{with_ruby} +BuildRequires: ruby ruby-devel rubygems-devel +%endif +%if %{with_perl} +BuildRequires: perl-interpreter perl-devel perl-generators +%endif +BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ @@ -91,6 +118,7 @@ Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) %description server Openwsman Server and service libraries. +%if %{with_python} %package python3 License: BSD Summary: Python bindings for openwsman client API @@ -100,7 +128,9 @@ Requires: libwsman1 = %{version}-%{release} %description python3 This package provides Python3 bindings to access the openwsman client API. +%endif +%if %{with_ruby} %package -n rubygem-%{gem_name} License: BSD Summary: Ruby client bindings for Openwsman @@ -118,7 +148,9 @@ BuildArch: noarch %description -n rubygem-%{gem_name}-doc Documentation for rubygem-%{gem_name} +%endif +%if %{with_perl} %package perl License: BSD Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) @@ -127,6 +159,7 @@ Requires: libwsman1 = %{version}-%{release} %description perl This package provides Perl bindings to access the openwsman client API. +%endif %package winrs Summary: Windows Remote Shell @@ -171,7 +204,7 @@ export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ - -DCMAKE_INSTALL_PREFIX=/usr \ + -DCMAKE_INSTALL_PREFIX=%{_prefix} \ -DCMAKE_VERBOSE_MAKEFILE=TRUE \ -DCMAKE_BUILD_TYPE=Release \ -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ @@ -181,10 +214,20 @@ cmake \ -DLIB=%{_lib} \ -DBUILD_JAVA=no \ -DBUILD_PYTHON=no \ +%if ! %{with_python} + -DBUILD_PYTHON3=no \ +%endif +%if ! %{with_perl} + -DBUILD_PERL=no \ +%endif +%if ! %{with_ruby} + -DBUILD_RUBY=no \ +%endif .. make +%if %{with_ruby} # Make the freshly build openwsman libraries available to build the gem's # binary extension. export LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib @@ -192,6 +235,7 @@ export CPATH=%{_builddir}/%{name}-%{version}/include/ export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem +%endif %if 0%{?with_selinux} # SELinux policy (originally from selinux-policy-contrib) @@ -205,16 +249,20 @@ bzip2 -9 %{modulename}.pp %install cd build +%if %{with_ruby} # Do not install the ruby extension, we are proviging the rubygem- instead. echo -n > bindings/ruby/cmake_install.cmake +%endif %make_install cd .. rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la +%if %{with_ruby} [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb +%endif mkdir -p %{buildroot}%{_sysconfdir}/init.d install -m 644 etc/openwsman.conf %{buildroot}/%{_sysconfdir}/openwsman install -m 644 etc/openwsman_client.conf %{buildroot}/%{_sysconfdir}/openwsman @@ -230,6 +278,7 @@ install -m 644 include/wsman-xml.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-xml-binding.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-dispatcher.h %{buildroot}/%{_includedir}/openwsman +%if %{with_ruby} mkdir -p %{buildroot}%{gem_dir} cp -pa ./build%{gem_dir}/* \ %{buildroot}%{gem_dir}/ @@ -238,6 +287,7 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%endif %if 0%{?with_selinux} install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 @@ -294,12 +344,15 @@ fi %{_libdir}/pkgconfig/* %{_libdir}/*.so +%if %{with_python} %files python3 %doc AUTHORS COPYING ChangeLog README.md %{python3_sitearch}/*.so %{python3_sitearch}/*.py %{python3_sitearch}/__pycache__/* +%endif +%if %{with_ruby} %files -n rubygem-%{gem_name} %doc AUTHORS COPYING ChangeLog README.md %dir %{gem_instdir} @@ -307,14 +360,19 @@ fi %{gem_extdir_mri} %exclude %{gem_cache} %{gem_spec} +%endif +%if %{with_ruby} %files -n rubygem-%{gem_name}-doc %doc %{gem_docdir} +%endif +%if %{with_perl} %files perl %doc AUTHORS COPYING ChangeLog README.md %{perl_vendorarch}/openwsman.so %{perl_vendorlib}/openwsman.pm +%endif %files server %doc AUTHORS COPYING ChangeLog README.md From 856f24f020b8a4459d4d77e27cf2b1ca69d9bcea Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 30 May 2022 20:12:50 +0200 Subject: [PATCH 20/68] Perl 5.36 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1d4fc61..d96f843 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -412,6 +412,9 @@ fi %endif %changelog +* Mon May 30 2022 Jitka Plesnikova - 2.7.1-4 +- Perl 5.36 rebuild + * Thu Jan 27 2022 Mamoru TASAKA - 2.7.1-3 - F-36: rebuild against ruby31 From 54805781bcca865d2046ac22ce54636f4cc44377 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 15 Jun 2022 18:15:51 +0200 Subject: [PATCH 21/68] Rebuilt for Python 3.11 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d96f843..b5bd85d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -412,6 +412,9 @@ fi %endif %changelog +* Wed Jun 15 2022 Python Maint - 2.7.1-5 +- Rebuilt for Python 3.11 + * Mon May 30 2022 Jitka Plesnikova - 2.7.1-4 - Perl 5.36 rebuild From 586aec19b11a97ce3a13d97470df136d36f6dda7 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 20 Jul 2022 08:37:49 +0200 Subject: [PATCH 22/68] Improve handling of HTTP 401 Unauthorized Signed-off-by: Vitezslav Crhonek --- ...sman-2.7.1-http-unauthorized-improve.patch | 56 +++++++++++++++++++ openwsman.spec | 7 ++- 2 files changed, 62 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.1-http-unauthorized-improve.patch diff --git a/openwsman-2.7.1-http-unauthorized-improve.patch b/openwsman-2.7.1-http-unauthorized-improve.patch new file mode 100644 index 0000000..2351ada --- /dev/null +++ b/openwsman-2.7.1-http-unauthorized-improve.patch @@ -0,0 +1,56 @@ +diff -up openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig openwsman-2.7.1/src/lib/wsman-curl-client-transport.c +--- openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig 2021-04-07 17:25:55.000000000 +0200 ++++ openwsman-2.7.1/src/lib/wsman-curl-client-transport.c 2022-07-19 09:25:22.435355610 +0200 +@@ -459,6 +459,7 @@ wsmc_handler( WsManClient *cl, + long http_code; + long auth_avail = 0; + char *_user = NULL, *_pass = NULL; ++ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */ + u_buf_t *response = NULL; + //char *soapaction; + char *tmp_str = NULL; +@@ -564,6 +565,7 @@ wsmc_handler( WsManClient *cl, + _user = wsmc_get_user(cl); + _pass = wsmc_get_password(cl); + if (_user && _pass && cl->data.auth_set) { ++ _no_auth = 0; + r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set); + if (r != CURLE_OK) { + cl->fault_string = u_strdup(curl_easy_strerror(r)); +@@ -584,6 +586,11 @@ wsmc_handler( WsManClient *cl, + curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed"); + goto DONE; + } ++ } else { ++ /* request without user credentials, remember this for ++ * later use when it might become necessary to print an error message ++ */ ++ _no_auth = 1; + } + + if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) { +@@ -616,6 +623,24 @@ wsmc_handler( WsManClient *cl, + break; + case 401: + // The server requires authentication. ++ /* RFC 2616 states: ++ * ++ * If the request already included Authorization credentials, then the 401 ++ * response indicates that authorization has been refused for those ++ * credentials. If the 401 response contains the same challenge as the ++ * prior response, and the user agent has already attempted ++ * authentication at least once, then the user SHOULD be presented the ++ * entity that was given in the response, since that entity might ++ * include relevant diagnostic information. ++ */ ++ if (_no_auth == 0) { ++ /* no authentication credentials were used. It is only ++ * possible to write a message about the current situation. There ++ * is no information about the last attempt to access the resource. ++ * Maybe at a later point in time I will implement more state information. ++ */ ++ fprintf(stdout,"Authentication failed, please retry\n"); ++ } + break; + default: + // The status code does not indicate success. diff --git a/openwsman.spec b/openwsman.spec index b5bd85d..04da9cf 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -49,6 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch +Patch6: openwsman-2.7.1-http-unauthorized-improve.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -191,6 +192,7 @@ Custom SELinux policy module %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line %patch5 -p1 -b .update-ssleay-conf +%patch6 -p1 -b .http-unauthorized-improve %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -412,6 +414,9 @@ fi %endif %changelog +* Wed Jul 20 2022 Vitezslav Crhonek - 2.7.1-6 +- Improve handling of HTTP 401 Unauthorized + * Wed Jun 15 2022 Python Maint - 2.7.1-5 - Rebuilt for Python 3.11 From 28fe0b0300d558cb9f3c9e22f54034673901a7a8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 22 Jul 2022 02:18:49 +0000 Subject: [PATCH 23/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 04da9cf..91f530f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -414,6 +414,9 @@ fi %endif %changelog +* Fri Jul 22 2022 Fedora Release Engineering - 2.7.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Wed Jul 20 2022 Vitezslav Crhonek - 2.7.1-6 - Improve handling of HTTP 401 Unauthorized From ebc4ead18b074854b39064ea8ec05c3e70778c20 Mon Sep 17 00:00:00 2001 From: Nikola Knazekova Date: Mon, 26 Sep 2022 17:59:21 +0200 Subject: [PATCH 24/68] selinux: Exclude installed policy module file from RPM verification Update based on latest packaging guide: https://fedoraproject.org/wiki/SELinux/IndependentPolicy Signed-off-by: Nikola Knazekova --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 91f530f..daa8736 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -410,7 +410,7 @@ fi %files selinux %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* %{_datadir}/selinux/devel/include/distributed/%{modulename}.if -%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} +%ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} %endif %changelog From d81a62d50bd6e14f84975b6c255b7db6c15314bd Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 21 Oct 2022 08:56:44 +0200 Subject: [PATCH 25/68] Fix Ruby bindings for swig 4.1 Signed-off-by: Vitezslav Crhonek --- ...sman-2.7.1-fix-ruby-bindings-for-swig-41.patch | 12 ++++++++++++ openwsman.spec | 15 +++++++++++---- 2 files changed, 23 insertions(+), 4 deletions(-) create mode 100644 openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch diff --git a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch new file mode 100644 index 0000000..de7a199 --- /dev/null +++ b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.1/bindings/ruby/helpers.h.orig openwsman-2.7.1/bindings/ruby/helpers.h +--- openwsman-2.7.1/bindings/ruby/helpers.h.orig 2021-04-07 17:25:55.000000000 +0200 ++++ openwsman-2.7.1/bindings/ruby/helpers.h 2022-10-21 08:36:24.901459057 +0200 +@@ -47,7 +47,7 @@ + * + */ + +-#if SWIGVERSION > 0x020004 ++#if SWIG_VERSION > 0x020004 + #define KLASS_DECL(k,t) swig_class *k = (swig_class *)(t->clientdata) + #define KLASS_OF(x) x->klass + #else diff --git a/openwsman.spec b/openwsman.spec index daa8736..05e2110 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -50,17 +50,18 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.1-http-unauthorized-improve.patch -BuildRequires: make +Patch7: openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel %if %{with_python} BuildRequires: python3 python3-devel %endif %if %{with_ruby} -BuildRequires: ruby ruby-devel rubygems-devel +BuildRequires: ruby ruby-devel rubygems-devel %endif %if %{with_perl} -BuildRequires: perl-interpreter perl-devel perl-generators +BuildRequires: perl-interpreter perl-devel perl-generators %endif BuildRequires: pkgconfig openssl-devel BuildRequires: cmake @@ -193,6 +194,7 @@ Custom SELinux policy module %patch4 -p1 -b .http-status-line %patch5 -p1 -b .update-ssleay-conf %patch6 -p1 -b .http-unauthorized-improve +%patch7 -p1 -b .fix-ruby-bindings-for-swig-41 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -414,6 +416,11 @@ fi %endif %changelog +* Fri Oct 21 2022 Vitezslav Crhonek - 2.7.1-8 +- Fix Ruby bindings for swig 4.1 (backported from upstream) + Resolves: #2136510 +- Remove mixed use of spaces and tabs from spec file + * Fri Jul 22 2022 Fedora Release Engineering - 2.7.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From e38142b56779ccc20d2ddbbbcd6b9752f1aa6484 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 4 Jan 2023 14:57:56 +0900 Subject: [PATCH 26/68] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 05e2110..df6a11b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -416,6 +416,9 @@ fi %endif %changelog +* Wed Jan 04 2023 Mamoru TASAKA - 2.7.1-9 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 + * Fri Oct 21 2022 Vitezslav Crhonek - 2.7.1-8 - Fix Ruby bindings for swig 4.1 (backported from upstream) Resolves: #2136510 From d661b6107722dfbf32f702f1983872d9c62969e9 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Fri, 13 Jan 2023 09:53:10 +0100 Subject: [PATCH 27/68] Remove perl(MODULE_COMPAT), it will be replaced by generators --- openwsman.spec | 1 - 1 file changed, 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index df6a11b..b824ecc 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -155,7 +155,6 @@ Documentation for rubygem-%{gem_name} %if %{with_perl} %package perl License: BSD -Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) Summary: Perl bindings for openwsman client API Requires: libwsman1 = %{version}-%{release} From 7c91375304f8fc1b899ef7953a5834718019698d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 19 Jan 2023 23:01:43 +0000 Subject: [PATCH 28/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index b824ecc..bb20ea6 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -415,6 +415,9 @@ fi %endif %changelog +* Thu Jan 19 2023 Fedora Release Engineering - 2.7.1-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Wed Jan 04 2023 Mamoru TASAKA - 2.7.1-9 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 From 768470808f66e51078d4fcc6284ecf40de0de0e9 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 14 Feb 2023 15:52:09 +0100 Subject: [PATCH 29/68] SPDX migration --- openwsman.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index bb20ea6..f0aba66 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,10 +25,10 @@ Name: openwsman Version: 2.7.1 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management -License: BSD +License: BSD-3-Clause AND MIT URL: http://www.openwsman.org/ Source0: https://github.com/Openwsman/openwsman/archive/v%{version}.tar.gz # help2man generated manpage for openwsmand binary @@ -415,6 +415,9 @@ fi %endif %changelog +* Tue Feb 14 2023 Vitezslav Crhonek - 2.7.1-11 +- SPDX migration + * Thu Jan 19 2023 Fedora Release Engineering - 2.7.1-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From f5e4d0862f3740911db1f662e2d620c980c36111 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 14 Jun 2023 23:08:01 +0200 Subject: [PATCH 30/68] Rebuilt for Python 3.12 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index f0aba66..f5b36b7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Wed Jun 14 2023 Python Maint - 2.7.1-12 +- Rebuilt for Python 3.12 + * Tue Feb 14 2023 Vitezslav Crhonek - 2.7.1-11 - SPDX migration From d06bc607f88879eee316332fbd0c90959bd8a394 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Tue, 11 Jul 2023 15:32:34 +0200 Subject: [PATCH 31/68] Perl 5.38 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index f5b36b7..c353677 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Tue Jul 11 2023 Jitka Plesnikova - 2.7.1-13 +- Perl 5.38 rebuild + * Wed Jun 14 2023 Python Maint - 2.7.1-12 - Rebuilt for Python 3.12 From 82ef81bd164ccf4ae6a959cbe29715213e216dbe Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jul 2023 18:16:04 +0000 Subject: [PATCH 32/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c353677..b1e7d55 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 13%{?dist} +Release: 14%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Thu Jul 20 2023 Fedora Release Engineering - 2.7.1-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Tue Jul 11 2023 Jitka Plesnikova - 2.7.1-13 - Perl 5.38 rebuild From 25ae2ebc1409893f79acd719cc288c2ddcc60e75 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 31 Aug 2023 09:50:31 +0200 Subject: [PATCH 33/68] Update to openwsman-2.7.2, replace deprecated patchN Signed-off-by: Vitezslav Crhonek --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 8 +-- ...-2.7.1-fix-ruby-bindings-for-swig-41.patch | 12 ---- ...sman-2.7.1-http-unauthorized-improve.patch | 56 ------------------- openwsman.spec | 17 ++---- sources | 2 +- 6 files changed, 12 insertions(+), 85 deletions(-) delete mode 100644 openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch delete mode 100644 openwsman-2.7.1-http-unauthorized-improve.patch diff --git a/.gitignore b/.gitignore index 98ec9b4..b3868d7 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.1.tar.gz +/v2.7.2.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 1689eb8..87c890d 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -1,12 +1,12 @@ -diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/bindings/ruby/extconf.rb ---- openwsman-2.4.12/bindings/ruby/extconf.rb.orig 2015-02-09 09:28:58.232581263 +0100 -+++ openwsman-2.4.12/bindings/ruby/extconf.rb 2015-02-09 09:38:22.836772879 +0100 +diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ruby/extconf.rb +--- openwsman-2.7.2/bindings/ruby/extconf.rb.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/bindings/ruby/extconf.rb 2023-08-09 12:50:21.361216733 +0200 @@ -32,7 +32,7 @@ swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.1/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch deleted file mode 100644 index de7a199..0000000 --- a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.1/bindings/ruby/helpers.h.orig openwsman-2.7.1/bindings/ruby/helpers.h ---- openwsman-2.7.1/bindings/ruby/helpers.h.orig 2021-04-07 17:25:55.000000000 +0200 -+++ openwsman-2.7.1/bindings/ruby/helpers.h 2022-10-21 08:36:24.901459057 +0200 -@@ -47,7 +47,7 @@ - * - */ - --#if SWIGVERSION > 0x020004 -+#if SWIG_VERSION > 0x020004 - #define KLASS_DECL(k,t) swig_class *k = (swig_class *)(t->clientdata) - #define KLASS_OF(x) x->klass - #else diff --git a/openwsman-2.7.1-http-unauthorized-improve.patch b/openwsman-2.7.1-http-unauthorized-improve.patch deleted file mode 100644 index 2351ada..0000000 --- a/openwsman-2.7.1-http-unauthorized-improve.patch +++ /dev/null @@ -1,56 +0,0 @@ -diff -up openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig openwsman-2.7.1/src/lib/wsman-curl-client-transport.c ---- openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig 2021-04-07 17:25:55.000000000 +0200 -+++ openwsman-2.7.1/src/lib/wsman-curl-client-transport.c 2022-07-19 09:25:22.435355610 +0200 -@@ -459,6 +459,7 @@ wsmc_handler( WsManClient *cl, - long http_code; - long auth_avail = 0; - char *_user = NULL, *_pass = NULL; -+ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */ - u_buf_t *response = NULL; - //char *soapaction; - char *tmp_str = NULL; -@@ -564,6 +565,7 @@ wsmc_handler( WsManClient *cl, - _user = wsmc_get_user(cl); - _pass = wsmc_get_password(cl); - if (_user && _pass && cl->data.auth_set) { -+ _no_auth = 0; - r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set); - if (r != CURLE_OK) { - cl->fault_string = u_strdup(curl_easy_strerror(r)); -@@ -584,6 +586,11 @@ wsmc_handler( WsManClient *cl, - curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed"); - goto DONE; - } -+ } else { -+ /* request without user credentials, remember this for -+ * later use when it might become necessary to print an error message -+ */ -+ _no_auth = 1; - } - - if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) { -@@ -616,6 +623,24 @@ wsmc_handler( WsManClient *cl, - break; - case 401: - // The server requires authentication. -+ /* RFC 2616 states: -+ * -+ * If the request already included Authorization credentials, then the 401 -+ * response indicates that authorization has been refused for those -+ * credentials. If the 401 response contains the same challenge as the -+ * prior response, and the user agent has already attempted -+ * authentication at least once, then the user SHOULD be presented the -+ * entity that was given in the response, since that entity might -+ * include relevant diagnostic information. -+ */ -+ if (_no_auth == 0) { -+ /* no authentication credentials were used. It is only -+ * possible to write a message about the current situation. There -+ * is no information about the last attempt to access the resource. -+ * Maybe at a later point in time I will implement more state information. -+ */ -+ fprintf(stdout,"Authentication failed, please retry\n"); -+ } - break; - default: - // The status code does not indicate success. diff --git a/openwsman.spec b/openwsman.spec index b1e7d55..a058e19 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -24,8 +24,8 @@ %endif Name: openwsman -Version: 2.7.1 -Release: 14%{?dist} +Version: 2.7.2 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,8 +49,6 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -Patch6: openwsman-2.7.1-http-unauthorized-improve.patch -Patch7: openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -187,13 +185,7 @@ Custom SELinux policy module %prep %setup -q -%patch1 -p1 -b .pamsetup -%patch2 -p1 -b .ruby-binding-build -%patch3 -p1 -b .openssl-1.1-fix -%patch4 -p1 -b .http-status-line -%patch5 -p1 -b .update-ssleay-conf -%patch6 -p1 -b .http-unauthorized-improve -%patch7 -p1 -b .fix-ruby-bindings-for-swig-41 +%autopatch -p1 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -415,6 +407,9 @@ fi %endif %changelog +* Thu Aug 31 2023 Vitezslav Crhonek - 2.7.2-1 +- Update to openwsman-2.7.2 + * Thu Jul 20 2023 Fedora Release Engineering - 2.7.1-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild diff --git a/sources b/sources index 0675e6c..250b1fa 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.7.1.tar.gz) = 37738bc5be7b1c3fa961587fca4db74b8e7714fc0641a550682275fbe925b2c8e18a683cf493f4740e479f7461cc98392d3d675f4769f5cf04e7249f1e9ee880 +SHA512 (v2.7.2.tar.gz) = ffd6a0d00a00b00e321b2b55e0c77326f5943ca3224eee74c706e53a1c5c44ef0e8b1cfde5d631966769eefd4e567b0db8713085b7a8b386c2871ab4ada83046 From 1d9613dae754e8b9201dd873735375e4ea52cbb9 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 3 Jan 2024 23:27:00 +0900 Subject: [PATCH 34/68] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index a058e19..629cc52 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -407,6 +407,9 @@ fi %endif %changelog +* Wed Jan 03 2024 Mamoru TASAKA - 2.7.2-2 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 + * Thu Aug 31 2023 Vitezslav Crhonek - 2.7.2-1 - Update to openwsman-2.7.2 From 7c23549251ef299057ab33fd28030db442ab06f3 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 21 Jan 2024 11:26:56 +0000 Subject: [PATCH 35/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 629cc52..b927214 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -407,6 +407,9 @@ fi %endif %changelog +* Sun Jan 21 2024 Fedora Release Engineering - 2.7.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Wed Jan 03 2024 Mamoru TASAKA - 2.7.2-2 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 From 049821cecda67a7aafd88d4eaa7ad5122eb52976 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 22 Jan 2024 11:02:23 +0100 Subject: [PATCH 36/68] Fix FTBFS --- openwsman-2.7.2-fix-ftbfs.patch | 12 ++++++++++++ openwsman.spec | 7 ++++++- 2 files changed, 18 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.2-fix-ftbfs.patch diff --git a/openwsman-2.7.2-fix-ftbfs.patch b/openwsman-2.7.2-fix-ftbfs.patch new file mode 100644 index 0000000..b30b3cf --- /dev/null +++ b/openwsman-2.7.2-fix-ftbfs.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.2/bindings/openwsman.i.orig openwsman-2.7.2/bindings/openwsman.i +--- openwsman-2.7.2/bindings/openwsman.i.orig 2024-01-22 09:36:42.764721705 +0100 ++++ openwsman-2.7.2/bindings/openwsman.i 2024-01-22 09:37:29.970817151 +0100 +@@ -109,7 +109,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S + + %typemap(in) FILE* { + #if RUBY_VERSION > 18 +- struct rb_io_t *fptr; ++ struct rb_io *fptr; + #else + struct OpenFile *fptr; + #endif diff --git a/openwsman.spec b/openwsman.spec index b927214..cdd8bb0 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,6 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch +Patch6: openwsman-2.7.2-fix-ftbfs.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -407,6 +408,10 @@ fi %endif %changelog +* Mon Jan 22 2024 Vitezslav Crhonek - 2.7.2-4 +- Fix FTBFS + Resolves: #2259165 + * Sun Jan 21 2024 Fedora Release Engineering - 2.7.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From ba629d7155d27d1af28b9e573454f008d1e80d6a Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 25 Jan 2024 11:33:40 +0000 Subject: [PATCH 37/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index cdd8bb0..93339aa 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Thu Jan 25 2024 Fedora Release Engineering - 2.7.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Mon Jan 22 2024 Vitezslav Crhonek - 2.7.2-4 - Fix FTBFS Resolves: #2259165 From b606719aa298cd4920ae7964e56f170d9777eac1 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 10 May 2024 09:04:19 +0200 Subject: [PATCH 38/68] Update license tags in subpackages to SPDX format --- openwsman.spec | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 93339aa..58c7772 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -77,7 +77,7 @@ requirements that exposes a set of operations focused on and covers all system management aspects. %package -n libwsman1 -License: BSD +License: BSD-3-Clause AND MIT Summary: Open source Implementation of WS-Management Provides: %{name} = %{version}-%{release} Obsoletes: %{name} < %{version}-%{release} @@ -86,7 +86,7 @@ Obsoletes: %{name} < %{version}-%{release} Openwsman library for packages dependent on openwsman. %package -n libwsman-devel -License: BSD +License: BSD-3-Clause AND MIT Summary: Open source Implementation of WS-Management Provides: %{name}-devel = %{version}-%{release} Obsoletes: %{name}-devel < %{version}-%{release} @@ -100,14 +100,14 @@ Requires: libcurl-devel Development files for openwsman. %package client -License: BSD +License: BSD-3-Clause AND MIT Summary: Openwsman Client libraries %description client Openwsman Client libraries. %package server -License: BSD +License: BSD-3-Clause AND MIT Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} %if 0%{?with_selinux} @@ -121,7 +121,7 @@ Openwsman Server and service libraries. %if %{with_python} %package python3 -License: BSD +License: BSD-3-Clause AND MIT Summary: Python bindings for openwsman client API Requires: %{__python3} Requires: libwsman1 = %{version}-%{release} @@ -133,7 +133,7 @@ This package provides Python3 bindings to access the openwsman client API. %if %{with_ruby} %package -n rubygem-%{gem_name} -License: BSD +License: BSD-3-Clause AND MIT Summary: Ruby client bindings for Openwsman Obsoletes: %{name}-ruby < %{version}-%{release} Requires: libwsman1 = %{version}-%{release} @@ -153,7 +153,7 @@ Documentation for rubygem-%{gem_name} %if %{with_perl} %package perl -License: BSD +License: BSD-3-Clause AND MIT Summary: Perl bindings for openwsman client API Requires: libwsman1 = %{version}-%{release} @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri May 10 2024 Vitezslav Crhonek - 2.7.2-6 +- Update license tags in subpackages to SPDX format + * Thu Jan 25 2024 Fedora Release Engineering - 2.7.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 4fd758ebc8e0aaa1259e8e7245eae4fff59c32ff Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 7 Jun 2024 18:57:17 +0200 Subject: [PATCH 39/68] Rebuilt for Python 3.13 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 58c7772..fd6401d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri Jun 07 2024 Python Maint - 2.7.2-7 +- Rebuilt for Python 3.13 + * Fri May 10 2024 Vitezslav Crhonek - 2.7.2-6 - Update license tags in subpackages to SPDX format From b4f95a4140a568c6b4835eac3ba3d35a520af089 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Wed, 12 Jun 2024 13:06:09 +0200 Subject: [PATCH 40/68] Perl 5.40 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index fd6401d..1ed52ef 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Wed Jun 12 2024 Jitka Plesnikova - 2.7.2-8 +- Perl 5.40 rebuild + * Fri Jun 07 2024 Python Maint - 2.7.2-7 - Rebuilt for Python 3.13 From d0cea79dae8fa8bb068709ec382fe8a9c2ece0ba Mon Sep 17 00:00:00 2001 From: Python Maint Date: Tue, 18 Jun 2024 09:37:36 +0200 Subject: [PATCH 41/68] Rebuilt for Python 3.13 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1ed52ef..c3c8151 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Tue Jun 18 2024 Python Maint - 2.7.2-9 +- Rebuilt for Python 3.13 + * Wed Jun 12 2024 Jitka Plesnikova - 2.7.2-8 - Perl 5.40 rebuild From 12519f950e1acb89cb5e5523685cb43cd2145ab4 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Sun, 23 Jun 2024 14:12:10 -0400 Subject: [PATCH 42/68] Fix build with RPM 4.20 %_builddir now contains a build-specific path: https://github.com/rpm-software-management/rpm/issues/2078 --- openwsman-2.4.12-ruby-binding-build.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 87c890d..eb52678 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2-build/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." From 613e85663e0ac14622a5f8d5a453fdaeff77d89f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 25 Jun 2024 13:08:46 +0200 Subject: [PATCH 43/68] Rebuild --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c3c8151..042d506 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,10 @@ fi %endif %changelog +* Tue Jun 25 2024 Vitezslav Crhonek - 2.7.2-10 +- Rebuild + Resolves: #2290726 + * Tue Jun 18 2024 Python Maint - 2.7.2-9 - Rebuilt for Python 3.13 From 1d0094977b201dc1c28090228955dff13a3852c8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 18 Jul 2024 21:04:40 +0000 Subject: [PATCH 44/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 042d506..12af969 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Thu Jul 18 2024 Fedora Release Engineering - 2.7.2-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Tue Jun 25 2024 Vitezslav Crhonek - 2.7.2-10 - Rebuild Resolves: #2290726 From 053236801c43a40453faf3c15973e6e79419ef36 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 30 Aug 2024 13:50:15 +0200 Subject: [PATCH 45/68] Add rpminspect.yaml --- rpminspect.yaml | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 rpminspect.yaml diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..765cfc9 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,5 @@ +--- +badfuncs: + allowed: + /usr/sbin/openwsmand: + - inet_ntoa From d5765d29775a9e409b291aebcec24b95a75cfed5 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 8 Jan 2025 11:07:07 +0900 Subject: [PATCH 46/68] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 12af969..8121b65 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Wed Jan 08 2025 Mamoru TASAKA - 2.7.2-12 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 + * Thu Jul 18 2024 Fedora Release Engineering - 2.7.2-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From c98dedc9447a7aab4c756c3e3f9052d8596c4a63 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jan 2025 21:55:13 +0000 Subject: [PATCH 47/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8121b65..87c9846 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri Jan 17 2025 Fedora Release Engineering - 2.7.2-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Jan 08 2025 Mamoru TASAKA - 2.7.2-12 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 From 531f9577de2ad94453385bd79510ce2238821648 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 23 Jan 2025 12:52:51 +0100 Subject: [PATCH 48/68] Fix FTBFS with GCC 15, bin and sbin unification --- openwsman-2.7.2-gcc15-fix.patch | 24 ++++++++++++++++++++++++ openwsman.spec | 8 ++++++-- 2 files changed, 30 insertions(+), 2 deletions(-) create mode 100644 openwsman-2.7.2-gcc15-fix.patch diff --git a/openwsman-2.7.2-gcc15-fix.patch b/openwsman-2.7.2-gcc15-fix.patch new file mode 100644 index 0000000..6dc4078 --- /dev/null +++ b/openwsman-2.7.2-gcc15-fix.patch @@ -0,0 +1,24 @@ +diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2/src/plugins/swig/src/target_ruby.c +--- openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/src/plugins/swig/src/target_ruby.c 2025-01-23 11:53:58.082946042 +0100 +@@ -49,7 +49,7 @@ + */ + + static VALUE +-load_module() ++load_module(VALUE) + { + ruby_script(PLUGIN_FILE); + return rb_require(PLUGIN_FILE); +diff -up openwsman-2.7.2/src/server/CMakeLists.txt.orig openwsman-2.7.2/src/server/CMakeLists.txt +--- openwsman-2.7.2/src/server/CMakeLists.txt.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/src/server/CMakeLists.txt 2025-01-23 12:08:44.042639395 +0100 +@@ -47,7 +47,7 @@ if( HAVE_LIBDL ) + TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) + endif( HAVE_LIBDL ) + +-INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin) ++INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin) + + # + # diff --git a/openwsman.spec b/openwsman.spec index 87c9846..324a1dd 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 13%{?dist} +Release: 14%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -50,6 +50,7 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-fix-ftbfs.patch +Patch7: openwsman-2.7.2-gcc15-fix.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -388,7 +389,7 @@ fi %dir %{_libdir}/openwsman/plugins %{_libdir}/openwsman/plugins/*.so %{_libdir}/openwsman/plugins/*.so.* -%{_sbindir}/openwsmand +%{_bindir}/openwsmand %{_libdir}/libwsman_server.so.* %{_mandir}/man8/* @@ -408,6 +409,9 @@ fi %endif %changelog +* Thu Jan 23 2025 Vitezslav Crhonek - 2.7.2-14 +- Fix FTBFS with GCC 15, bin and sbin unification + * Fri Jan 17 2025 Fedora Release Engineering - 2.7.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 6862d70ca029052ba6bad839a5e9e18dafbe4316 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 1 Feb 2025 19:56:20 +0100 Subject: [PATCH 49/68] Add explicit BR: libxcrypt-devel MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Björn Esser --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 324a1dd..8f2b45e 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 14%{?dist} +Release: 15%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -67,6 +67,7 @@ BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ +BuildRequires: libxcrypt-devel %description Openwsman is a project intended to provide an open-source @@ -409,6 +410,9 @@ fi %endif %changelog +* Sat Feb 01 2025 Björn Esser - 2.7.2-15 +- Add explicit BR: libxcrypt-devel + * Thu Jan 23 2025 Vitezslav Crhonek - 2.7.2-14 - Fix FTBFS with GCC 15, bin and sbin unification From d6df136fc0005c0176c598fd3a021accfe9155d2 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 28 Feb 2025 13:34:54 +0100 Subject: [PATCH 50/68] Fix mixed use of tabs and spaces in specfile --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8f2b45e..9595f66 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -67,7 +67,7 @@ BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ -BuildRequires: libxcrypt-devel +BuildRequires: libxcrypt-devel %description Openwsman is a project intended to provide an open-source From 8a58111e8d2f7b1cae5794e53371be5136ad1015 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 28 Feb 2025 14:27:25 +0100 Subject: [PATCH 51/68] Update minimum required cmake version --- openwsman-2.7.2-cmake-minimum.patch | 12 ++++++++++++ openwsman.spec | 6 +++++- 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.2-cmake-minimum.patch diff --git a/openwsman-2.7.2-cmake-minimum.patch b/openwsman-2.7.2-cmake-minimum.patch new file mode 100644 index 0000000..fdf9a1f --- /dev/null +++ b/openwsman-2.7.2-cmake-minimum.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.2/CMakeLists.txt.orig openwsman-2.7.2/CMakeLists.txt +--- openwsman-2.7.2/CMakeLists.txt.orig 2025-02-28 13:39:53.472585928 +0100 ++++ openwsman-2.7.2/CMakeLists.txt 2025-02-28 13:41:25.004762276 +0100 +@@ -6,7 +6,7 @@ PROJECT(openwsman) + + # 2.6 minimum because of CMP0005 (escaping defines) + # 2.8.12 minimum because CMake 3.19.7 says so +-cmake_minimum_required(VERSION 2.8.12) ++cmake_minimum_required(VERSION 3.12) + + include(CTest) + enable_testing() diff --git a/openwsman.spec b/openwsman.spec index 9595f66..32dcc79 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 15%{?dist} +Release: 16%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -51,6 +51,7 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-fix-ftbfs.patch Patch7: openwsman-2.7.2-gcc15-fix.patch +Patch8: openwsman-2.7.2-cmake-minimum.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -410,6 +411,9 @@ fi %endif %changelog +* Fri Feb 28 2025 Vitezslav Crhonek - 2.7.2-16 +- Update minimum required cmake version + * Sat Feb 01 2025 Björn Esser - 2.7.2-15 - Add explicit BR: libxcrypt-devel From 98cf5bcd843d02c3b246b32cc366b9a7be6da740 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 7 Apr 2025 13:38:27 +0200 Subject: [PATCH 52/68] Update to openwsman-2.8.1 --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 28 +++++++++++------------ openwsman-2.7.2-cmake-minimum.patch | 12 ---------- openwsman-2.7.2-fix-ftbfs.patch | 12 ---------- openwsman-2.7.2-gcc15-fix.patch | 18 +++++++-------- openwsman.spec | 14 +++++++----- sources | 2 +- 8 files changed, 34 insertions(+), 56 deletions(-) delete mode 100644 openwsman-2.7.2-cmake-minimum.patch delete mode 100644 openwsman-2.7.2-fix-ftbfs.patch diff --git a/.gitignore b/.gitignore index b3868d7..67bb856 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.2.tar.gz +/v2.8.1.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index eb52678..20f3b47 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2-build/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.8.1-build/openwsman-2.8.1/include -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 5d64644..9322adb 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h ---- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100 +diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/src/server/shttpd/compat_unix.h +--- openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/compat_unix.h 2025-02-03 09:11:35.072818890 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,9 +12,9 @@ diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c ---- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100 +diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/server/shttpd/io_ssl.c +--- openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/io_ssl.c 2025-02-03 09:12:22.387355905 +0100 @@ -11,28 +11,6 @@ #include "defs.h" @@ -44,10 +44,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c ---- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100 -@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c +--- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2025-02-03 09:13:43.415562784 +0100 +@@ -1510,25 +1510,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -73,10 +73,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/ser + OPENSSL_init_ssl(0, NULL); if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) #endif - _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h ---- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100 + _shttpd_report_ssl_error("SSL_CTX_new failed", NULL); +diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server/shttpd/ssl.h +--- openwsman-2.8.1/src/server/shttpd/ssl.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/ssl.h 2025-02-03 09:14:43.142975166 +0100 @@ -12,55 +12,4 @@ #include diff --git a/openwsman-2.7.2-cmake-minimum.patch b/openwsman-2.7.2-cmake-minimum.patch deleted file mode 100644 index fdf9a1f..0000000 --- a/openwsman-2.7.2-cmake-minimum.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.2/CMakeLists.txt.orig openwsman-2.7.2/CMakeLists.txt ---- openwsman-2.7.2/CMakeLists.txt.orig 2025-02-28 13:39:53.472585928 +0100 -+++ openwsman-2.7.2/CMakeLists.txt 2025-02-28 13:41:25.004762276 +0100 -@@ -6,7 +6,7 @@ PROJECT(openwsman) - - # 2.6 minimum because of CMP0005 (escaping defines) - # 2.8.12 minimum because CMake 3.19.7 says so --cmake_minimum_required(VERSION 2.8.12) -+cmake_minimum_required(VERSION 3.12) - - include(CTest) - enable_testing() diff --git a/openwsman-2.7.2-fix-ftbfs.patch b/openwsman-2.7.2-fix-ftbfs.patch deleted file mode 100644 index b30b3cf..0000000 --- a/openwsman-2.7.2-fix-ftbfs.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.2/bindings/openwsman.i.orig openwsman-2.7.2/bindings/openwsman.i ---- openwsman-2.7.2/bindings/openwsman.i.orig 2024-01-22 09:36:42.764721705 +0100 -+++ openwsman-2.7.2/bindings/openwsman.i 2024-01-22 09:37:29.970817151 +0100 -@@ -109,7 +109,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S - - %typemap(in) FILE* { - #if RUBY_VERSION > 18 -- struct rb_io_t *fptr; -+ struct rb_io *fptr; - #else - struct OpenFile *fptr; - #endif diff --git a/openwsman-2.7.2-gcc15-fix.patch b/openwsman-2.7.2-gcc15-fix.patch index 6dc4078..590ff14 100644 --- a/openwsman-2.7.2-gcc15-fix.patch +++ b/openwsman-2.7.2-gcc15-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2/src/plugins/swig/src/target_ruby.c ---- openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/src/plugins/swig/src/target_ruby.c 2025-01-23 11:53:58.082946042 +0100 +diff -up openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig openwsman-2.8.1/src/plugins/swig/src/target_ruby.c +--- openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/plugins/swig/src/target_ruby.c 2025-02-03 09:30:36.905616375 +0100 @@ -49,7 +49,7 @@ */ @@ -10,12 +10,12 @@ diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2 { ruby_script(PLUGIN_FILE); return rb_require(PLUGIN_FILE); -diff -up openwsman-2.7.2/src/server/CMakeLists.txt.orig openwsman-2.7.2/src/server/CMakeLists.txt ---- openwsman-2.7.2/src/server/CMakeLists.txt.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/src/server/CMakeLists.txt 2025-01-23 12:08:44.042639395 +0100 -@@ -47,7 +47,7 @@ if( HAVE_LIBDL ) - TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) - endif( HAVE_LIBDL ) +diff -up openwsman-2.8.1/src/server/CMakeLists.txt.orig openwsman-2.8.1/src/server/CMakeLists.txt +--- openwsman-2.8.1/src/server/CMakeLists.txt.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/CMakeLists.txt 2025-02-03 09:31:15.258241237 +0100 +@@ -48,7 +48,7 @@ IF( HAVE_LIBDL ) + TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) + ENDIF( HAVE_LIBDL ) -INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin) +INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin) diff --git a/openwsman.spec b/openwsman.spec index 32dcc79..c65645f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -18,14 +18,14 @@ %global with_perl 0 %global with_python 0 %else -%global with_ruby 1 +%global with_ruby 0 %global with_perl 1 %global with_python 1 %endif Name: openwsman -Version: 2.7.2 -Release: 16%{?dist} +Version: 2.8.1 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,9 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -Patch6: openwsman-2.7.2-fix-ftbfs.patch -Patch7: openwsman-2.7.2-gcc15-fix.patch -Patch8: openwsman-2.7.2-cmake-minimum.patch +Patch6: openwsman-2.7.2-gcc15-fix.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -260,6 +258,7 @@ rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la %if %{with_ruby} [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb +[ -d %{buildroot}/%{ruby_sitelibdir} ] && rm -f %{buildroot}/%{ruby_sitelibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb %endif mkdir -p %{buildroot}%{_sysconfdir}/init.d @@ -411,6 +410,9 @@ fi %endif %changelog +* Mon Apr 07 2025 Vitezslav Crhonek - 2.8.1-1 +- Update to openwsman-2.8.1 + * Fri Feb 28 2025 Vitezslav Crhonek - 2.7.2-16 - Update minimum required cmake version diff --git a/sources b/sources index 250b1fa..383285d 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.7.2.tar.gz) = ffd6a0d00a00b00e321b2b55e0c77326f5943ca3224eee74c706e53a1c5c44ef0e8b1cfde5d631966769eefd4e567b0db8713085b7a8b386c2871ab4ada83046 +SHA512 (v2.8.1.tar.gz) = 3c72b6778269186108e48203a9c37f1e4ea8ff532013a80be6af3c6e8d2bf89343233287bc4eb2e955b8db4b7cf6d20818f77423781f6fdb52a6317a7e8bc972 From 47117d833d7268863141dea9d0195dfccad99c43 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 10 Apr 2025 14:31:06 +0200 Subject: [PATCH 53/68] Build winrs only when ruby binding is enabled --- openwsman.spec | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c65645f..c7908dd 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -162,6 +162,7 @@ Requires: libwsman1 = %{version}-%{release} This package provides Perl bindings to access the openwsman client API. %endif +%if %{with_ruby} %package winrs Summary: Windows Remote Shell Requires: rubygem-%{gem_name} = %{version}-%{release} @@ -169,6 +170,7 @@ Requires: rubygem-%{gem_name} = %{version}-%{release} %description winrs This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. +%endif %if 0%{?with_selinux} # SELinux subpackage @@ -285,6 +287,8 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%else +rm -f %{buildroot}%{_bindir}/winrs %endif %if 0%{?with_selinux} @@ -399,8 +403,10 @@ fi %{_libdir}/libwsman_clientpp.so.* %config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf +%if %{with_ruby} %files winrs %{_bindir}/winrs +%endif %if 0%{?with_selinux} %files selinux @@ -410,6 +416,9 @@ fi %endif %changelog +* Thu Apr 10 2025 Vitezslav Crhonek - 2.8.1-2 +- Build winrs only when ruby binding is enabled + * Mon Apr 07 2025 Vitezslav Crhonek - 2.8.1-1 - Update to openwsman-2.8.1 From d5b12f392fafe0e0de8069239e86fdb473e83091 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Tue, 3 Jun 2025 12:20:17 +0200 Subject: [PATCH 54/68] Rebuilt for Python 3.14 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c7908dd..d06a310 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Tue Jun 03 2025 Python Maint - 2.8.1-3 +- Rebuilt for Python 3.14 + * Thu Apr 10 2025 Vitezslav Crhonek - 2.8.1-2 - Build winrs only when ruby binding is enabled From e7504d677c87dbfc2f265ab5a9b4c55081e414a7 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 9 Jun 2025 09:49:40 +0200 Subject: [PATCH 55/68] Remove deprecated path from systemd service file --- openwsman.spec | 5 ++++- openwsmand.service | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index d06a310..62b8780 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Mon Jun 09 2025 Vitezslav Crhonek - 2.8.1-4 +- Remove deprecated path from systemd service file + * Tue Jun 03 2025 Python Maint - 2.8.1-3 - Rebuilt for Python 3.14 diff --git a/openwsmand.service b/openwsmand.service index e10c75d..a42b11f 100644 --- a/openwsmand.service +++ b/openwsmand.service @@ -6,7 +6,7 @@ After=syslog.target Type=forking ExecStart=/usr/sbin/openwsmand -S ExecStartPre=/etc/openwsman/owsmantestcert.sh -PIDFile=/var/run/wsmand.pid +PIDFile=/run/wsmand.pid [Install] WantedBy=multi-user.target From a15c71912aa31e8269192ba6bdd8b614ba050f69 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Mon, 9 Jun 2025 11:44:53 +0200 Subject: [PATCH 56/68] Rebuilt for Python 3.14 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 62b8780..9d8e2d7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Mon Jun 09 2025 Python Maint - 2.8.1-5 +- Rebuilt for Python 3.14 + * Mon Jun 09 2025 Vitezslav Crhonek - 2.8.1-4 - Remove deprecated path from systemd service file From f7085bf7cf35c7c94ffcd5c48af2167645c36911 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 17 Jun 2025 14:40:11 +0200 Subject: [PATCH 57/68] Update to better support post-quantum cryptography --- openwsman-2.8.1-post-quantum.patch | 101 +++++++++++++++++++++++++++++ openwsman.spec | 6 +- 2 files changed, 106 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.8.1-post-quantum.patch diff --git a/openwsman-2.8.1-post-quantum.patch b/openwsman-2.8.1-post-quantum.patch new file mode 100644 index 0000000..0b9b7bb --- /dev/null +++ b/openwsman-2.8.1-post-quantum.patch @@ -0,0 +1,101 @@ +diff -up openwsman-2.7.2/etc/openwsman.conf.orig openwsman-2.7.2/etc/openwsman.conf +--- openwsman-2.7.2/etc/openwsman.conf.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/etc/openwsman.conf 2025-05-27 08:03:57.890057721 +0200 +@@ -32,8 +32,12 @@ ipv6 = yes + + # the openwsman server certificate file, in .pem format + ssl_cert_file = /etc/openwsman/servercert.pem ++# the openwsman server certificate fallback file, in .pem format ++#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem + # the openwsman server private key, in .pem format + ssl_key_file = /etc/openwsman/serverkey.pem ++# the openwsman server private key fallback, in .pem format ++#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem + + # space-separated list of SSL protocols to *dis*able + # possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2 +diff -up openwsman-2.7.2/src/server/shttpd/shttpd.c.orig openwsman-2.7.2/src/server/shttpd/shttpd.c +--- openwsman-2.7.2/src/server/shttpd/shttpd.c.orig 2025-05-21 10:07:40.404532496 +0200 ++++ openwsman-2.7.2/src/server/shttpd/shttpd.c 2025-06-12 12:27:44.785904555 +0200 +@@ -1491,7 +1491,6 @@ set_ssl(struct shttpd_ctx *ctx, const ch + char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); + char *ssl_cipher_list = wsmand_options_get_ssl_cipher_list(); + int retval = FALSE; +- EC_KEY* key; + + /* Initialize SSL crap */ + +@@ -1510,11 +1509,15 @@ set_ssl(struct shttpd_ctx *ctx, const ch + else + retval = TRUE; + +- /* This enables ECDH Perfect Forward secrecy. Currently with just the most generic p256 prime curve */ +- key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); +- if (key != NULL) { +- SSL_CTX_set_tmp_ecdh(CTX, key); +- EC_KEY_free(key); ++ /* Add fall back certificate/key pair */ ++ if (wsmand_options_get_ssl_cert_fallback_file() && ++ wsmand_options_get_ssl_key_fallback_file()) { ++ if (SSL_CTX_use_certificate_file(CTX, wsmand_options_get_ssl_cert_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open certificate fallback file %s", pem); ++ else if (SSL_CTX_use_PrivateKey_file(CTX, wsmand_options_get_ssl_key_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open fallback PrivateKey %s", pem); ++ else ++ retval = TRUE; + } + + while (ssl_disabled_protocols) { +diff -up openwsman-2.7.2/src/server/wsmand-daemon.c.orig openwsman-2.7.2/src/server/wsmand-daemon.c +--- openwsman-2.7.2/src/server/wsmand-daemon.c.orig 2025-05-27 07:18:16.878974761 +0200 ++++ openwsman-2.7.2/src/server/wsmand-daemon.c 2025-05-27 07:22:06.832235764 +0200 +@@ -76,8 +76,10 @@ static int use_ipv6 = 0; + #endif + static int use_digest = 0; + static char *ssl_key_file = NULL; ++static char *ssl_key_fallback_file = NULL; + static char *service_path = DEFAULT_SERVICE_PATH; + static char *ssl_cert_file = NULL; ++static char *ssl_cert_fallback_file = NULL; + static char *ssl_disabled_protocols = NULL; + static char *ssl_cipher_list = NULL; + static char *pid_file = DEFAULT_PID_PATH; +@@ -186,7 +188,9 @@ int wsmand_read_config(dictionary * ini) + service_path = + iniparser_getstring(ini, "server:service_path", "/wsman"); + ssl_key_file = iniparser_getstr(ini, "server:ssl_key_file"); ++ ssl_key_fallback_file = iniparser_getstr(ini, "server:ssl_key_fallback_file"); + ssl_cert_file = iniparser_getstr(ini, "server:ssl_cert_file"); ++ ssl_cert_fallback_file = iniparser_getstr(ini, "server:ssl_cert_fallback_file"); + ssl_disabled_protocols = iniparser_getstr(ini, "server:ssl_disabled_protocols"); + ssl_cipher_list = iniparser_getstr(ini, "server:ssl_cipher_list"); + use_ipv4 = iniparser_getboolean(ini, "server:ipv4", 1); +@@ -364,6 +368,16 @@ char *wsmand_options_get_ssl_cert_file(v + return ssl_cert_file; + } + ++char *wsmand_options_get_ssl_key_fallback_file(void) ++{ ++ return ssl_key_fallback_file; ++} ++ ++char *wsmand_options_get_ssl_cert_fallback_file(void) ++{ ++ return ssl_cert_fallback_file; ++} ++ + char *wsmand_options_get_ssl_disabled_protocols(void) + { + return ssl_disabled_protocols; +diff -up openwsman-2.7.2/src/server/wsmand-daemon.h.orig openwsman-2.7.2/src/server/wsmand-daemon.h +--- openwsman-2.7.2/src/server/wsmand-daemon.h.orig 2025-05-27 07:15:56.869002037 +0200 ++++ openwsman-2.7.2/src/server/wsmand-daemon.h 2025-05-27 07:18:06.429846617 +0200 +@@ -76,6 +76,8 @@ int wsmand_options_get_server_port(void) + int wsmand_options_get_server_ssl_port(void); + char *wsmand_options_get_ssl_key_file(void); + char *wsmand_options_get_ssl_cert_file(void); ++char *wsmand_options_get_ssl_key_fallback_file(void); ++char *wsmand_options_get_ssl_cert_fallback_file(void); + char *wsmand_options_get_ssl_disabled_protocols(void); + char *wsmand_options_get_ssl_cipher_list(void); + int wsmand_options_get_digest(void); diff --git a/openwsman.spec b/openwsman.spec index 9d8e2d7..7ce8a06 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -50,6 +50,7 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-gcc15-fix.patch +Patch7: openwsman-2.8.1-post-quantum.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -416,6 +417,9 @@ fi %endif %changelog +* Tue Jun 17 2025 Vitezslav Crhonek - 2.8.1-6 +- Update to better support post-quantum cryptography + * Mon Jun 09 2025 Python Maint - 2.8.1-5 - Rebuilt for Python 3.14 From 94e2a92bdcd11a2fe8863ca28cf16d610891a585 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 17 Jun 2025 14:42:02 +0200 Subject: [PATCH 58/68] Add post-quantum support test --- .fmf/version | 1 + plans/basic.fmf | 9 +++ tests/post-quantum-cryptography/main.fmf | 6 ++ tests/post-quantum-cryptography/runtest.sh | 92 ++++++++++++++++++++++ 4 files changed, 108 insertions(+) create mode 100644 .fmf/version create mode 100644 plans/basic.fmf create mode 100644 tests/post-quantum-cryptography/main.fmf create mode 100755 tests/post-quantum-cryptography/runtest.sh diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/plans/basic.fmf b/plans/basic.fmf new file mode 100644 index 0000000..efb100f --- /dev/null +++ b/plans/basic.fmf @@ -0,0 +1,9 @@ +summary: Basic test plan +prepare: + how: install + package: + - openwsman-server +discover: + how: fmf +execute: + how: tmt diff --git a/tests/post-quantum-cryptography/main.fmf b/tests/post-quantum-cryptography/main.fmf new file mode 100644 index 0000000..51ba4e2 --- /dev/null +++ b/tests/post-quantum-cryptography/main.fmf @@ -0,0 +1,6 @@ +summary: Post-quantum cryptography support test +author: Vitezslav Crhonek +contact: Vitezslav Crhonek +require: patch +duration: 10m +test: ./runtest.sh diff --git a/tests/post-quantum-cryptography/runtest.sh b/tests/post-quantum-cryptography/runtest.sh new file mode 100755 index 0000000..6588a8a --- /dev/null +++ b/tests/post-quantum-cryptography/runtest.sh @@ -0,0 +1,92 @@ +#!/bin/sh -eux + +function check_key_and_cert() +{ + echo -e "\n===== key info" + ssh-keygen -l -f /etc/openwsman/serverkey.pem || : + file /etc/openwsman/serverkey.pem + echo -e "\n\n\n" + + echo -e "\n===== cert info" + openssl x509 -in /etc/openwsman/servercert.pem --text --noout + echo -e "\n\n\n" +} + +function test_key_exchange() +{ + echo -e "\n===== check that it uses TLS 1.3 and the X25519MLKEM768 key exchange by default if the peer supports it" + openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert.pem Date: Tue, 24 Jun 2025 10:38:48 +0200 Subject: [PATCH 59/68] Remove STI DSP test --- tests/tests-DSP.yml | 37 ------------------------------------- 1 file changed, 37 deletions(-) delete mode 100644 tests/tests-DSP.yml diff --git a/tests/tests-DSP.yml b/tests/tests-DSP.yml deleted file mode 100644 index ec2c494..0000000 --- a/tests/tests-DSP.yml +++ /dev/null @@ -1,37 +0,0 @@ -- hosts: localhost - - roles: - - role: standard-test-beakerlib - tags: - - classic - repositories: - - repo: https://pagure.io/DSP_test.git - dest: DSP_test - version: master - - tests: - - DSP_test - environment: - # RPM package containing the policy module - TEST_RPM: openwsman-selinux - # policy module name - TEST_POLICY: openwsman - # policy sources will be extracted from corresponding .src.rpm - # policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz") - # or empty string if policy sources are not inside a tar archive - POLICY_TAR: '' - # path to policy sources (in of the tar archive) -- //.(te|if|fc) - # or path in the src.rpm if there is no tar archive -- //.(te|if|fc) - # can contain wildcards (e.g. for versions etc.) - POLICY_PATH: . - - required_packages: - - policycoreutils - - selinux-policy - - selinux-policy-targeted - - setools-console - - libselinux-utils - - rpm - - tar - - git - - openwsman-server From f8a5615d0ad53945db9edbf18c29ab56e1247880 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 7 Jul 2025 16:23:01 +0200 Subject: [PATCH 60/68] Perl 5.42 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 7ce8a06..77b2ec0 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Mon Jul 07 2025 Jitka Plesnikova - 2.8.1-7 +- Perl 5.42 rebuild + * Tue Jun 17 2025 Vitezslav Crhonek - 2.8.1-6 - Update to better support post-quantum cryptography From 3b4a6e4ac53232d1ef88c8e95110dc5cf364fae4 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 24 Jul 2025 23:42:46 +0000 Subject: [PATCH 61/68] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 77b2ec0..4f09c46 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 2.8.1-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Mon Jul 07 2025 Jitka Plesnikova - 2.8.1-7 - Perl 5.42 rebuild From c6d83b0c57be70794cbfcb98b10ded1610c65c01 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 15 Aug 2025 13:04:34 +0200 Subject: [PATCH 62/68] Rebuilt for Python 3.14.0rc2 bytecode --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 4f09c46..149923b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Fri Aug 15 2025 Python Maint - 2.8.1-9 +- Rebuilt for Python 3.14.0rc2 bytecode + * Thu Jul 24 2025 Fedora Release Engineering - 2.8.1-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 655676c16c7012056ab76cecd4beedffb4f0cdb8 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 12:35:09 +0200 Subject: [PATCH 63/68] Rebuilt for Python 3.14.0rc3 bytecode --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 149923b..299a0bc 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Fri Sep 19 2025 Python Maint - 2.8.1-10 +- Rebuilt for Python 3.14.0rc3 bytecode + * Fri Aug 15 2025 Python Maint - 2.8.1-9 - Rebuilt for Python 3.14.0rc2 bytecode From d198b44b1b7f3d1d0472568ab78b41937bfac83c Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 12 Nov 2025 07:56:03 +0100 Subject: [PATCH 64/68] Update OpenSSL certificates set up, fix and enable ruby binding again --- openwsman-2.4.12-ruby-binding-build.patch | 71 +++++++++++++- openwsman-2.7.2-ssl-certs-gen-changes.patch | 102 ++++++++++++++++++++ openwsman-2.8.1-fix-ruby-io.patch | 33 +++++++ openwsman-2.8.1-rdoc-ruby34.patch | 29 ++++++ openwsman.spec | 11 ++- 5 files changed, 239 insertions(+), 7 deletions(-) create mode 100644 openwsman-2.7.2-ssl-certs-gen-changes.patch create mode 100644 openwsman-2.8.1-fix-ruby-io.patch create mode 100644 openwsman-2.8.1-rdoc-ruby34.patch diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 20f3b47..2c2e25b 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -1,12 +1,73 @@ -diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ruby/extconf.rb ---- openwsman-2.7.2/bindings/ruby/extconf.rb.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/bindings/ruby/extconf.rb 2023-08-09 12:50:21.361216733 +0200 -@@ -32,7 +32,7 @@ swig = find_executable("swig") +--- openwsman-2.8.1/bindings/ruby/extconf.rb.orig 2025-11-11 11:49:59.880195434 +0100 ++++ openwsman-2.8.1/bindings/ruby/extconf.rb 2025-11-11 11:50:46.870685458 +0100 +@@ -5,20 +5,41 @@ + require 'mkmf' + # $CFLAGS = "#{$CFLAGS} -Werror" + ++# libwsman requires 'int facility' to be defined by the application ++# Add syslog.h for LOG_DAEMON constant ++$CFLAGS = "#{$CFLAGS} -include syslog.h" ++ + # requires wsman, wsman_client, and libxml2 ++# Use CPATH and LIBRARY_PATH environment variables set by the build system ++if ENV['CPATH'] ++ ENV['CPATH'].split(':').each do |path| ++ $CPPFLAGS = "#{$CPPFLAGS} -I#{path}" ++ end ++end ++if ENV['LIBRARY_PATH'] ++ ENV['LIBRARY_PATH'].split(':').each do |path| ++ $LDFLAGS = "#{$LDFLAGS} -L#{path}" ++ end ++end + +-unless have_library('wsman', 'wsman_create_doc') ++# Custom test for libwsman that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsman_create_doc(\"test\");\n return 0;\n}", '-lwsman') + STDERR.puts "Cannot find wsman_create_doc() in libwsman" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 + end ++# Explicitly add libwsman to linker flags since we used try_link instead of have_library ++$libs = append_library($libs, "wsman") + find_header 'wsman-xml-api.h', '/usr/include/openwsman' + +-unless have_library('wsman_client', 'wsmc_create') ++# Custom test for libwsman_client that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsmc_create(\"localhost\", 80, \"/wsman\", \"http\", \"user\", \"pass\");\n return 0;\n}", '-lwsman_client -lwsman') + STDERR.puts "Cannot find wsmc_create() in libwsman_client" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 + end ++# Explicitly add libwsman_client to linker flags since we used try_link instead of have_library ++$libs = append_library($libs, "wsman_client") + find_header 'wsman-client-api.h', '/usr/include/openwsman' + + unless have_library('xml2', 'xmlNewDoc') +@@ -28,12 +49,25 @@ + end + find_header 'libxml/parser.h', '/usr/include/libxml2' + ++# Check for Ruby 3.3+ IO types ++have_type('rb_io_t', 'ruby/io.h') ++have_header 'ruby/thread.h' ++ + swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.8.1-build/openwsman-2.8.1/include -o openwsman_wrap.c openwsman.i") ++ ++# Build SWIG include paths from CPATH environment variable ++swig_includes = "-I. -I/usr/include/openwsman" ++if ENV['CPATH'] ++ ENV['CPATH'].split(':').each do |path| ++ swig_includes += " -I#{path}" ++ end ++end ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} #{swig_includes} -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." + create_makefile('_openwsman') ++ diff --git a/openwsman-2.7.2-ssl-certs-gen-changes.patch b/openwsman-2.7.2-ssl-certs-gen-changes.patch new file mode 100644 index 0000000..11de1d5 --- /dev/null +++ b/openwsman-2.7.2-ssl-certs-gen-changes.patch @@ -0,0 +1,102 @@ +diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/owsmangencert.sh.cmake +--- openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/etc/owsmangencert.sh.cmake 2025-10-17 10:16:34.482996406 +0200 +@@ -1,10 +1,74 @@ +-#!/bin/sh +- + #!/bin/sh -e + + CERTFILE=@WSMANCONF_DIR@/servercert.pem + KEYFILE=@WSMANCONF_DIR@/serverkey.pem + CNFFILE=@WSMANCONF_DIR@/ssleay.cnf ++CAFILE=@WSMANCONF_DIR@/ca.crt ++DAYS=365 ++ ++function create_ssl_cnf ++{ ++ # Get minimum RSA key length at current security level ++ # This workarounds openssl not enforcing min. key length enforced by current security level ++ KEYSIZE=`grep min_rsa_size /etc/crypto-policies/state/CURRENT.pol | cut -d ' ' -f 3` ++ ++ # Create OpenSSL configuration files for generating certificates ++ echo "[ req ]" > $CNFFILE ++ echo "default_bits = $KEYSIZE" >> $CNFFILE ++ echo "default_keyfile = privkey.pem" >> $CNFFILE ++ echo "distinguished_name = req_distinguished_name" >> $CNFFILE ++ ++ echo "[ req_distinguished_name ]" >> $CNFFILE ++ echo "countryName = Country Name (2 letter code)" >> $CNFFILE ++ echo "countryName_default = GB" >> $CNFFILE ++ echo "countryName_min = 2" >> $CNFFILE ++ echo "countryName_max = 2" >> $CNFFILE ++ ++ echo "stateOrProvinceName = State or Province Name (full name)" >> $CNFFILE ++ echo "stateOrProvinceName_default = Some-State" >> $CNFFILE ++ ++ echo "localityName = Locality Name (eg, city)" >> $CNFFILE ++ ++ echo "organizationName = Organization Name (eg, company; recommended)" >> $CNFFILE ++ echo "organizationName_max = 64" >> $CNFFILE ++ ++ echo "organizationalUnitName = Organizational Unit Name (eg, section)" >> $CNFFILE ++ echo "organizationalUnitName_max = 64" >> $CNFFILE ++ ++ echo "commonName = server name (eg. ssl.domain.tld; required!!!)" >> $CNFFILE ++ echo "commonName_max = 80" >> $CNFFILE ++ ++ echo "emailAddress = Email Address" >> $CNFFILE ++ echo "emailAddress_max = 85" >> $CNFFILE ++} ++ ++function selfsign_sscg() ++{ ++ sscg --quiet \ ++ --lifetime "${DAYS}" \ ++ --cert-key-file "${KEYFILE}" \ ++ --cert-file "${CERTFILE}" \ ++ --ca-file "${CAFILE}" ++} ++ ++function selfsign_openssl() ++{ ++ ++ echo ++ echo creating selfsigned certificate ++ echo "replace it with one signed by a certification authority (CA)" ++ echo ++ echo enter your ServerName at the Common Name prompt ++ echo ++ ++ # use special .cnf, because with normal one no valid selfsigned ++ # certificate is created ++ ++ openssl req -days $DAYS $@ -config $CNFFILE \ ++ -new -x509 -nodes -out $CERTFILE \ ++ -keyout $KEYFILE ++ chmod 600 $KEYFILE ++} + + if [ "$1" != "--force" -a -f $KEYFILE ]; then + echo "$KEYFILE exists! Use \"$0 --force.\"" +@@ -15,18 +79,7 @@ if [ "$1" = "--force" ]; then + shift + fi + +-echo +-echo creating selfsigned certificate +-echo "replace it with one signed by a certification authority (CA)" +-echo +-echo enter your ServerName at the Common Name prompt +-echo +- +-# use special .cnf, because with normal one no valid selfsigned +-# certificate is created +- +-openssl req -days 365 $@ -config $CNFFILE \ +- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ +- -keyout $KEYFILE +-chmod 600 $KEYFILE ++create_ssl_cnf + ++# If sscg fails, try openssl ++selfsign_sscg || selfsign_openssl diff --git a/openwsman-2.8.1-fix-ruby-io.patch b/openwsman-2.8.1-fix-ruby-io.patch new file mode 100644 index 0000000..605bf91 --- /dev/null +++ b/openwsman-2.8.1-fix-ruby-io.patch @@ -0,0 +1,33 @@ +diff -up openwsman-2.8.1/bindings/openwsman.i.orig openwsman-2.8.1/bindings/openwsman.i +--- openwsman-2.8.1/bindings/openwsman.i.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/bindings/openwsman.i 2025-10-21 16:56:01.025576984 +0200 +@@ -105,15 +105,8 @@ SWIGINTERNINLINE SV *SWIG_From_double S + #if HAVE_RUBY_THREAD_H /* New threading model */ + #include + #endif +-#if RUBY_VERSION > 18 +- #if HAVE_RB_IO_T +- #define rb_fptr_t rb_io_t +- #else +- #define rb_fptr_t struct rb_io +- #endif +-#else +- #define rb_fptr_t struct OpenFile +-#endif ++/* Use rb_io_t for Ruby 1.9+ */ ++#define rb_fptr_t rb_io_t + %} + + %typemap(in) FILE* { +@@ -122,11 +115,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S + Check_Type($input, T_FILE); + GetOpenFile($input, fptr); + /*rb_io_check_writable(fptr);*/ +-#if RUBY_VERSION > 18 + $1 = rb_io_stdio_file(fptr); +-#else +- $1 = GetReadFile(fptr); +-#endif + } + + #endif /* SWIGRUBY */ diff --git a/openwsman-2.8.1-rdoc-ruby34.patch b/openwsman-2.8.1-rdoc-ruby34.patch new file mode 100644 index 0000000..de30428 --- /dev/null +++ b/openwsman-2.8.1-rdoc-ruby34.patch @@ -0,0 +1,29 @@ +--- openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-11-10 15:00:00.000000000 +0100 +@@ -108,10 +108,24 @@ class RDoc::Parser::SWIG < RDoc::Parser + ## + # Prepare to parse a SWIG file + +- def initialize(top_level, file_name, content, options, stats) +- super ++ def initialize(top_level, file_name, content, options, stats = nil) ++ # RDoc 6.6+ (Ruby 3.3+) removed the stats parameter from Parser.initialize ++ # Check the arity of the parent class initialize method to determine which API we're using ++ parent_arity = RDoc::Parser.instance_method(:initialize).arity ++ ++ if parent_arity == 4 || parent_arity == -5 ++ # RDoc 6.6+: only pass 4 arguments to super ++ super(top_level, file_name, content, options) ++ # Create a dummy stats object for compatibility ++ @stats = Object.new ++ def @stats.method_missing(m, *args); end ++ else ++ # Older RDoc: pass all 5 arguments including stats ++ super(top_level, file_name, content, options, stats) ++ @stats = stats ++ end + + @known_classes = RDoc::KNOWN_CLASSES.dup + @content = handle_tab_width handle_ifdefs_in(@content) + @renames = {} # maps old_name => [ new_name, args ] + @aliases = {} # maps name => [ alias_name, args ] diff --git a/openwsman.spec b/openwsman.spec index 299a0bc..9fb5371 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -18,14 +18,14 @@ %global with_perl 0 %global with_python 0 %else -%global with_ruby 0 +%global with_ruby 1 %global with_perl 1 %global with_python 1 %endif Name: openwsman Version: 2.8.1 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -51,6 +51,9 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-gcc15-fix.patch Patch7: openwsman-2.8.1-post-quantum.patch +Patch8: openwsman-2.7.2-ssl-certs-gen-changes.patch +Patch9: openwsman-2.8.1-rdoc-ruby34.patch +Patch10: openwsman-2.8.1-fix-ruby-io.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -417,6 +420,10 @@ fi %endif %changelog +* Wed Nov 12 2025 Vitezslav Crhonek - 2.8.1-11 +- Update OpenSSL certificates set up +- Fix ruby binding, enable it + * Fri Sep 19 2025 Python Maint - 2.8.1-10 - Rebuilt for Python 3.14.0rc3 bytecode From 7df5ef0bbeedb5eecf13cc015b4dc78b283f6d19 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Sat, 3 Jan 2026 09:58:06 +0900 Subject: [PATCH 65/68] Support rdoc 6.16 and above (for ruby4.0) --- openwsman-2.8.1-rdoc-6_16.patch | 18 ++++++++++++++++++ openwsman.spec | 6 +++++- 2 files changed, 23 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.8.1-rdoc-6_16.patch diff --git a/openwsman-2.8.1-rdoc-6_16.patch b/openwsman-2.8.1-rdoc-6_16.patch new file mode 100644 index 0000000..c0dc8b4 --- /dev/null +++ b/openwsman-2.8.1-rdoc-6_16.patch @@ -0,0 +1,18 @@ +diff -urp '--exclude=*~' openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb +--- openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:43:41.804273994 +0900 ++++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:56:06.991238037 +0900 +@@ -377,7 +377,13 @@ class RDoc::Parser::SWIG < RDoc::Parser + find_modifiers comment, meth_obj if comment + + #meth_obj.params = params +- meth_obj.start_collecting_tokens ++ # https://github.com/ruby/rdoc/pull/1471 changes the parameter for ++ # RDoc::TokenStream.start_collecting_tokens ++ if meth_obj.method(:start_collecting_tokens).arity == 1 ++ meth_obj.start_collecting_tokens :ruby ++ else ++ meth_obj.start_collecting_tokens ++ end + begin + RDoc::const_get "RubyToken" + tk = RDoc::RubyToken::Token.new nil, 1, 1 diff --git a/openwsman.spec b/openwsman.spec index 9fb5371..94298f8 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -54,6 +54,7 @@ Patch7: openwsman-2.8.1-post-quantum.patch Patch8: openwsman-2.7.2-ssl-certs-gen-changes.patch Patch9: openwsman-2.8.1-rdoc-ruby34.patch Patch10: openwsman-2.8.1-fix-ruby-io.patch +Patch11: openwsman-2.8.1-rdoc-6_16.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -420,6 +421,9 @@ fi %endif %changelog +* Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 +- Support rdoc 6.16 and above (for ruby4.0) + * Wed Nov 12 2025 Vitezslav Crhonek - 2.8.1-11 - Update OpenSSL certificates set up - Fix ruby binding, enable it From 724b68ff8066812f071e553bd9a50ff00d1e56ec Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 8 Jan 2026 09:55:02 +0100 Subject: [PATCH 66/68] Update post-quantum support test --- openwsman.spec | 5 ++++- tests/post-quantum-cryptography/runtest.sh | 20 ++++++++++---------- 2 files changed, 14 insertions(+), 11 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 94298f8..75d8459 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -421,6 +421,9 @@ fi %endif %changelog +* Thu Jan 08 2026 Vitezslav Crhonek - 2.8.1-13 +- Fix PQC test + * Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 - Support rdoc 6.16 and above (for ruby4.0) diff --git a/tests/post-quantum-cryptography/runtest.sh b/tests/post-quantum-cryptography/runtest.sh index 6588a8a..a09dda5 100755 --- a/tests/post-quantum-cryptography/runtest.sh +++ b/tests/post-quantum-cryptography/runtest.sh @@ -52,17 +52,17 @@ rm -rf /etc/openwsman/{servercert,serverkey}.pem # update genOpenPegasusSSLCerts to generate a new key using ML-DSA-65 # and issue a self-signed certificate for localhost using this key patch /etc/openwsman/owsmangencert.sh << 'EOF' ---- /etc/openwsman/owsmangencert.sh.orig 2025-06-25 04:03:22.295778704 -0400 -+++ /etc/openwsman/owsmangencert.sh 2025-06-25 04:05:12.181435542 -0400 -@@ -26,7 +26,7 @@ - # certificate is created +--- owsmangencert.sh.orig 2026-01-08 03:50:31.852413993 -0500 ++++ owsmangencert.sh 2026-01-08 03:52:41.883088457 -0500 +@@ -65,7 +65,7 @@ + # certificate is created - openssl req -days 365 $@ -config $CNFFILE \ -- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ -+ -newkey mldsa65 -x509 -nodes -out $CERTFILE \ - -keyout $KEYFILE - chmod 600 $KEYFILE - + openssl req -days $DAYS $@ -config $CNFFILE \ +- -new -x509 -nodes -out $CERTFILE \ ++ -newkey mldsa65 -x509 -nodes -out $CERTFILE \ + -keyout $KEYFILE + chmod 600 $KEYFILE + } EOF (echo CZ; echo "Czech Republic"; echo Brno; echo "Red Hat"; echo "Core Services"; echo localhost; echo joe@example.com; ) | /etc/openwsman/owsmangencert.sh From 901f747d526d3e5ee60ff3171cf398186ddfe3e1 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 12 Jan 2026 08:39:40 +0100 Subject: [PATCH 67/68] Fix bogus 'sscg' arguments --- openwsman-2.7.2-ssl-certs-gen-changes.patch | 8 ++++---- openwsman.spec | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/openwsman-2.7.2-ssl-certs-gen-changes.patch b/openwsman-2.7.2-ssl-certs-gen-changes.patch index 11de1d5..0f0b96a 100644 --- a/openwsman-2.7.2-ssl-certs-gen-changes.patch +++ b/openwsman-2.7.2-ssl-certs-gen-changes.patch @@ -51,10 +51,10 @@ diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/ows +function selfsign_sscg() +{ + sscg --quiet \ -+ --lifetime "${DAYS}" \ -+ --cert-key-file "${KEYFILE}" \ -+ --cert-file "${CERTFILE}" \ -+ --ca-file "${CAFILE}" ++ --lifetime "$DAYS" \ ++ --cert-key-file "$KEYFILE" \ ++ --cert-file "$CERTFILE" \ ++ --ca-file "$CAFILE" +} + +function selfsign_openssl() diff --git a/openwsman.spec b/openwsman.spec index 75d8459..1a56b52 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -422,7 +422,7 @@ fi %changelog * Thu Jan 08 2026 Vitezslav Crhonek - 2.8.1-13 -- Fix PQC test +- Fix bogus 'sscg' arguments * Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 - Support rdoc 6.16 and above (for ruby4.0) From 897a78ebf80fc3e450fcb17a0ab65e4047147985 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 9 Jan 2026 07:49:16 +0100 Subject: [PATCH 68/68] Add 'sscg' SSL files generation test --- tests/sscg-generated-certificates/main.fmf | 6 ++++++ tests/sscg-generated-certificates/runtest.sh | 17 +++++++++++++++++ 2 files changed, 23 insertions(+) create mode 100644 tests/sscg-generated-certificates/main.fmf create mode 100755 tests/sscg-generated-certificates/runtest.sh diff --git a/tests/sscg-generated-certificates/main.fmf b/tests/sscg-generated-certificates/main.fmf new file mode 100644 index 0000000..0b30fd6 --- /dev/null +++ b/tests/sscg-generated-certificates/main.fmf @@ -0,0 +1,6 @@ +summary: Service works with 'sscg' generated SSL certificates +author: Vitezslav Crhonek +contact: Vitezslav Crhonek +require: sscg +duration: 10m +test: ./runtest.sh diff --git a/tests/sscg-generated-certificates/runtest.sh b/tests/sscg-generated-certificates/runtest.sh new file mode 100755 index 0000000..459ba4b --- /dev/null +++ b/tests/sscg-generated-certificates/runtest.sh @@ -0,0 +1,17 @@ +#!/bin/sh -ux + +# remove previously generated SSL files +rm -rf /etc/openwsman/{servercert,serverkey}*.pem /etc/openwsman/ca.crt + +# remove SSL fallback to relly really just on sscg +cp /etc/openwsman/owsmangencert.sh /etc/openwsman/test-script.sh +sed -i 's/^selfsign_sscg ||.*/selfsign_sscg/' /etc/openwsman/test-script.sh + +# generate new SSL files using sscg +/etc/openwsman/test-script.sh + +# check that SSL files were generated +[ -f /etc/openwsman/servercert.pem ] && [ -f /etc/openwsman/serverkey.pem ] || { echo "Error: SSL files missing"; exit 1; } + +# try to start the service +systemctl start openwsmand