From 841e095c2d926aa1fbc017ba186564c3f254e920 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 22 Mar 2016 15:12:55 +0100 Subject: [PATCH 001/120] Remove SSL_LIB acquired by readlink from CFLAGS --- openwsman.spec | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 4b5d0b3..0128a36 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -16,7 +16,7 @@ BuildRequires: perl-devel pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 3%{?dist} +Release: 4%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -184,7 +184,6 @@ rm -rf build mkdir build export RPM_OPT_FLAGS="$RPM_OPT_FLAGS -DFEDORA -DNO_SSL_CALLBACK" -export SSL_LIB=`readlink %{_libdir}/libssl.so` export CFLAGS="-D_GNU_SOURCE -fPIE -DPIE" export LDFLAGS="$LDFLAGS -Wl,-z,now -pie" cd build @@ -199,7 +198,7 @@ cmake \ -DLIB=%{_lib} \ .. -make CFLAGS="-DSSL_LIB='\"$SSL_LIB\"'" +make # Make the freshly build openwsman libraries available to build the gem's # binary extension. @@ -336,6 +335,9 @@ rm -f /var/log/wsmand.log %changelog +* Tue Mar 22 2016 Vitezslav Crhonek - 2.6.2-4 +- Remove SSL_LIB acquired by readlink from CFLAGS + * Thu Feb 04 2016 Fedora Release Engineering - 2.6.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild From ad0cb2779879a8718eeabb5750ea023935a5fc15 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Sun, 15 May 2016 06:19:55 +0200 Subject: [PATCH 002/120] Perl 5.24 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 0128a36..8cade79 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -16,7 +16,7 @@ BuildRequires: perl-devel pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 4%{?dist} +Release: 5%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -335,6 +335,9 @@ rm -f /var/log/wsmand.log %changelog +* Sun May 15 2016 Jitka Plesnikova - 2.6.2-5 +- Perl 5.24 rebuild + * Tue Mar 22 2016 Vitezslav Crhonek - 2.6.2-4 - Remove SSL_LIB acquired by readlink from CFLAGS From 2a4d1cc88958767e23b260d4c3530df94ddda60a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Fri, 24 Jun 2016 10:13:54 +0200 Subject: [PATCH 003/120] Mandatory Perl build-requires added --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8cade79..31c8507 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python python-devel ruby ruby-devel rubygems-devel perl BuildRequires: python python-devel perl -BuildRequires: perl-devel pkgconfig openssl-devel +BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 From 30156671fc3cbbd763192b2bdc76a7a183774dd2 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 19 Jul 2016 08:10:01 +0000 Subject: [PATCH 004/120] - https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 31c8507..a76c7c2 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -16,7 +16,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 5%{?dist} +Release: 6%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -335,6 +335,9 @@ rm -f /var/log/wsmand.log %changelog +* Tue Jul 19 2016 Fedora Release Engineering - 2.6.2-6 +- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages + * Sun May 15 2016 Jitka Plesnikova - 2.6.2-5 - Perl 5.24 rebuild From f6475234567005ef83b8a8e0dffc40cbf818db13 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 11 Aug 2016 12:29:52 +0200 Subject: [PATCH 005/120] Add openwsman-python3 subpackage --- openwsman-2.6.2-python3.patch | 179 ++++++++++++++++++++++++++++++++++ openwsman.spec | 56 ++++++++--- 2 files changed, 220 insertions(+), 15 deletions(-) create mode 100644 openwsman-2.6.2-python3.patch diff --git a/openwsman-2.6.2-python3.patch b/openwsman-2.6.2-python3.patch new file mode 100644 index 0000000..39f9c97 --- /dev/null +++ b/openwsman-2.6.2-python3.patch @@ -0,0 +1,179 @@ +diff -up openwsman-2.6.2/bindings/CMakeLists.txt.orig openwsman-2.6.2/bindings/CMakeLists.txt +--- openwsman-2.6.2/bindings/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/bindings/CMakeLists.txt 2016-08-10 11:55:36.588710280 +0200 +@@ -10,6 +10,7 @@ include_directories(${CMAKE_BINARY_DIR}) + + IF( BUILD_PYTHON ) + add_subdirectory(python) ++add_subdirectory(python3) + ENDIF( BUILD_PYTHON ) + + IF( BUILD_RUBY ) +diff -up openwsman-2.6.2/bindings/python3/CMakeLists.txt.orig openwsman-2.6.2/bindings/python3/CMakeLists.txt +--- openwsman-2.6.2/bindings/python3/CMakeLists.txt.orig 2016-08-10 11:55:36.577710278 +0200 ++++ openwsman-2.6.2/bindings/python3/CMakeLists.txt 2016-08-10 15:15:46.005991322 +0200 +@@ -12,11 +12,28 @@ enable_testing() + + add_subdirectory(tests) + +-EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON_LIB_DIR) +-STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") ++MESSAGE(STATUS "Python3 build:") ++unset(Python_ADDITIONAL_VERSIONS) ++set(Python_ADDITIONAL_VERSIONS 3.5) ++FIND_PACKAGE(PythonLibs) ++IF (PYTHON_LIBRARY) ++ FIND_PACKAGE(PythonInterp REQUIRED) ++ #MESSAGE(STATUS "Found PythonLibs...") ++ FIND_PACKAGE(PythonLinkLibs) ++ #IF (PYTHON_LINK_LIBS) ++ # MESSAGE(STATUS "Building Python...") ++ #ENDIF (PYTHON_LINK_LIBS) ++ENDIF (PYTHON_LIBRARY) ++ ++set(PYTHON3_EXECUTABLE "${PYTHON_EXECUTABLE}") ++set(PYTHON3_INCLUDE_DIRS "${PYTHON_INCLUDE_DIRS}") ++set({PYTHON3_INCLUDE_PATH "${PYTHON_INCLUDE_PATH}") + +-MESSAGE(STATUS "Python executable: ${PYTHON_EXECUTABLE}") +-MESSAGE(STATUS "Python lib dir: ${PYTHON_LIB_DIR}") ++EXECUTE_PROCESS(COMMAND ${PYTHON3_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON3_LIB_DIR) ++STRING(REPLACE "\n" "" PYTHON3_LIB_DIR "${PYTHON3_LIB_DIR}") ++ ++MESSAGE(STATUS "Python executable: ${PYTHON3_EXECUTABLE}") ++MESSAGE(STATUS "Python lib dir: ${PYTHON3_LIB_DIR}") + + SET( SWIG_OUTPUT "${CMAKE_CURRENT_BINARY_DIR}/openwsman_wrap.c" ) + +@@ -36,14 +53,14 @@ SET(pywsman_SRCS ${SWIG_OUTPUT} ${CMAKE_ + ADD_LIBRARY( pywsman SHARED ${pywsman_SRCS} ) + SET_TARGET_PROPERTIES( pywsman PROPERTIES PREFIX "_" ) + +-INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_DIRS} ) ++INCLUDE_DIRECTORIES( ${PYTHON3_INCLUDE_DIRS} ) + # RHEL5 needs this: +-INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_PATH} ) ++INCLUDE_DIRECTORIES( ${PYTHON3_INCLUDE_PATH} ) + INCLUDE_DIRECTORIES( ${CMAKE_CURRENT_BINARY_DIR} ) + INCLUDE_DIRECTORIES( ${CMAKE_SOURCE_DIR} ${CMAKE_SOURCE_DIR}/bindings ${CMAKE_SOURCE_DIR}/include ) + + TARGET_LINK_LIBRARIES( pywsman wsman ) + TARGET_LINK_LIBRARIES( pywsman wsman_client ) + +-INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON_LIB_DIR}) +-INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) ++INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON3_LIB_DIR}) ++INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON3_LIB_DIR} ) +diff -up openwsman-2.6.2/bindings/python/CMakeLists.txt.orig openwsman-2.6.2/bindings/python/CMakeLists.txt +--- openwsman-2.6.2/bindings/python/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/bindings/python/CMakeLists.txt 2016-08-10 15:00:21.126141161 +0200 +@@ -12,11 +12,52 @@ enable_testing() + + add_subdirectory(tests) + +-EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON_LIB_DIR) +-STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") ++MESSAGE(STATUS "Python2 build:") ++set(Python_ADDITIONAL_VERSIONS 2.7) ++FIND_PACKAGE(PythonLibs) ++IF (PYTHON_LIBRARY) ++ FIND_PACKAGE(PythonInterp REQUIRED) ++ #MESSAGE(STATUS "Found PythonLibs...") ++ FIND_PACKAGE(PythonLinkLibs) ++ #IF (PYTHON_LINK_LIBS) ++ # MESSAGE(STATUS "Building Python...") ++ #ENDIF (PYTHON_LINK_LIBS) ++ENDIF (PYTHON_LIBRARY) ++ ++set(PYTHON2_EXECUTABLE "${PYTHON_EXECUTABLE}") ++set(PYTHON2_INCLUDE_DIRS "${PYTHON_INCLUDE_DIRS}") ++set(PYTHON2_INCLUDE_PATH "${PYTHON_INCLUDE_PATH}") ++ ++# clear FIND_PACKAGE(PythonLibs) side effects ++unset(PYTHONLIBS_FOUND) ++unset(PYTHON_LIBRARIES) ++unset(PYTHON_INCLUDE_PATH) ++unset(PYTHON_INCLUDE_DIRS) ++unset(PYTHON_DEBUG_LIBRARIES) ++unset(PYTHONLIBS_VERSION_STRING) ++unset(PYTHON_DEBUG_LIBRARY CACHE) ++unset(PYTHON_LIBRARY) ++unset(PYTHON_LIBRARY_DEBUG) ++unset(PYTHON_LIBRARY_RELEASE) ++unset(PYTHON_LIBRARY CACHE) ++unset(PYTHON_LIBRARY_DEBUG CACHE) ++unset(PYTHON_LIBRARY_RELEASE CACHE) ++unset(PYTHON_INCLUDE_DIR CACHE) ++unset(PYTHON_INCLUDE_DIR2 CACHE) ++ ++# clear FIND_PACKAGE(PythonInterp) side effects ++unset(PYTHONINTERP_FOUND) ++unset(PYTHON_EXECUTABLE CACHE) ++unset(PYTHON_VERSION_STRING) ++unset(PYTHON_VERSION_MAJOR) ++unset(PYTHON_VERSION_MINOR) ++unset(PYTHON_VERSION_PATCH) + +-MESSAGE(STATUS "Python executable: ${PYTHON_EXECUTABLE}") +-MESSAGE(STATUS "Python lib dir: ${PYTHON_LIB_DIR}") ++EXECUTE_PROCESS(COMMAND ${PYTHON2_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON2_LIB_DIR) ++STRING(REPLACE "\n" "" PYTHON2_LIB_DIR "${PYTHON2_LIB_DIR}") ++ ++MESSAGE(STATUS "Python executable: ${PYTHON2_EXECUTABLE}") ++MESSAGE(STATUS "Python lib dir: ${PYTHON2_LIB_DIR}") + + SET( SWIG_OUTPUT "${CMAKE_CURRENT_BINARY_DIR}/openwsman_wrap.c" ) + +@@ -36,14 +77,14 @@ SET(pywsman_SRCS ${SWIG_OUTPUT} ${CMAKE_ + ADD_LIBRARY( pywsman SHARED ${pywsman_SRCS} ) + SET_TARGET_PROPERTIES( pywsman PROPERTIES PREFIX "_" ) + +-INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_DIRS} ) ++INCLUDE_DIRECTORIES( ${PYTHON2_INCLUDE_DIRS} ) + # RHEL5 needs this: +-INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_PATH} ) ++INCLUDE_DIRECTORIES( ${PYTHON2_INCLUDE_PATH} ) + INCLUDE_DIRECTORIES( ${CMAKE_CURRENT_BINARY_DIR} ) + INCLUDE_DIRECTORIES( ${CMAKE_SOURCE_DIR} ${CMAKE_SOURCE_DIR}/bindings ${CMAKE_SOURCE_DIR}/include ) + + TARGET_LINK_LIBRARIES( pywsman wsman ) + TARGET_LINK_LIBRARIES( pywsman wsman_client ) + +-INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON_LIB_DIR}) +-INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) ++INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON2_LIB_DIR}) ++INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON2_LIB_DIR} ) +diff -up openwsman-2.6.2/CMakeLists.txt.orig openwsman-2.6.2/CMakeLists.txt +--- openwsman-2.6.2/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/CMakeLists.txt 2016-08-10 11:55:36.588710280 +0200 +@@ -168,30 +168,6 @@ MESSAGE(STATUS "Building Ruby bindings" + ENDIF(NOT RUBY_INCLUDE_PATH ) + ENDIF( BUILD_RUBY ) + +-IF( BUILD_PYTHON ) +- MESSAGE(STATUS "Building Python bindings" ) +- FIND_PACKAGE(PythonLibs) +- IF (PYTHON_LIBRARY) +- FIND_PACKAGE(PythonInterp REQUIRED) +- MESSAGE(STATUS "Found PythonLibs...") +- FIND_PACKAGE(PythonLinkLibs) +- IF (PYTHON_LINK_LIBS) +- MESSAGE(STATUS "Building Python...") +- ENDIF (PYTHON_LINK_LIBS) +- ENDIF (PYTHON_LIBRARY) +- IF(NOT PYTHON_INCLUDE_DIRS ) +- # fallback for older versions of cmake +- SET(PYTHON_INCLUDE_DIRS PYTHON_INCLUDE_PATH) +- ENDIF(NOT PYTHON_INCLUDE_DIRS ) +- IF(NOT PYTHON_INCLUDE_DIRS ) +- IF(BUILD_PYTHON_EXPLICIT) +- NO_HEADERS_WARNING_EXPL(BUILD_PYTHON Python) +- ELSE(BUILD_PYTHON_EXPLICIT) +- NO_HEADERS_WARNING(BUILD_PYTHON Python) +- ENDIF(BUILD_PYTHON_EXPLICIT) +- ENDIF(NOT PYTHON_INCLUDE_DIRS ) +-ENDIF( BUILD_PYTHON ) +- + IF( BUILD_PERL ) + INCLUDE(FindPerl) + IF(PERL_EXECUTABLE) diff --git a/openwsman.spec b/openwsman.spec index a76c7c2..ace0dc6 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,22 +1,15 @@ - -%if ! (0%{?fedora} > 12 || 0%{?rhel} > 5) -%{!?python_sitelib: %global python_sitelib %(%{__python} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib())")} -%{!?python_sitearch: %global python_sitearch %(%{__python} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))")} -%endif - # RubyGems's macros expect gem_name to exist. %global gem_name %{name} Name: openwsman BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python python-devel ruby ruby-devel rubygems-devel perl -BuildRequires: python python-devel perl +BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 6%{?dist} +Release: 7%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -33,6 +26,7 @@ Source3: owsmantestcert.sh Patch1: openwsman-2.2.7-libssl.patch Patch2: openwsman-2.4.0-pamsetup.patch Patch3: openwsman-2.4.12-ruby-binding-build.patch +Patch4: openwsman-2.6.2-python3.patch %description Openwsman is a project intended to provide an open-source @@ -107,11 +101,25 @@ Openwsman Server and service libraries License: BSD Group: Development/Libraries Summary: Python bindings for openwsman client API -Requires: python +Requires: python2 Requires: libwsman1 = %{version}-%{release} %description python -This package provides Python bindings to access the openwsman client +This package provides Python2 bindings to access the openwsman client +API. + + + + +%package python3 +License: BSD +Group: Development/Libraries +Summary: Python bindings for openwsman client API +Requires: python3 +Requires: libwsman1 = %{version}-%{release} + +%description python3 +This package provides Python3 bindings to access the openwsman client API. @@ -165,9 +173,16 @@ can use it to send shell commands to a remote Windows hosts. %prep %setup -q + +# support python3 +pushd bindings +cp -r python python3 +popd + %patch1 -p1 -b .libssl %patch2 -p1 -b .pamsetup %patch3 -p1 -b .ruby-binding-build +%patch4 -p1 -b .python3 # support ruby 2.2 pushd bindings/ruby @@ -176,6 +191,7 @@ chmod 0755 rdoc2.2 ln -sf %{_bindir}/rdoc rdoc2_2.rb popd + %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -281,10 +297,16 @@ rm -f /var/log/wsmand.log %doc AUTHORS COPYING ChangeLog README.md %files python -%{python_sitearch}/*.so -%{python_sitearch}/*.py -%{python_sitearch}/*.pyc -%{python_sitearch}/*.pyo +%{python2_sitearch}/*.so +%{python2_sitearch}/*.py +%{python2_sitearch}/*.pyc +%{python2_sitearch}/*.pyo +%doc AUTHORS COPYING ChangeLog README.md + +%files python3 +%{python3_sitearch}/*.so +%{python3_sitearch}/*.py +%{python3_sitearch}/__pycache__/* %doc AUTHORS COPYING ChangeLog README.md %files -n rubygem-%{gem_name} @@ -335,6 +357,10 @@ rm -f /var/log/wsmand.log %changelog +* Thu Aug 11 2016 Vitezslav Crhonek - 2.6.2-7 +- Add openwsman-python3 subpackage + Resolves: #1354481 + * Tue Jul 19 2016 Fedora Release Engineering - 2.6.2-6 - https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages From 0314364eccf31c5673ff108a7b08d0d5b086b77c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 19 Dec 2016 18:20:36 +0100 Subject: [PATCH 006/120] Rebuild for Python 3.6 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index ace0dc6..fc310a3 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -9,7 +9,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 7%{?dist} +Release: 8%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -357,6 +357,9 @@ rm -f /var/log/wsmand.log %changelog +* Mon Dec 19 2016 Miro Hrončok - 2.6.2-8 +- Rebuild for Python 3.6 + * Thu Aug 11 2016 Vitezslav Crhonek - 2.6.2-7 - Add openwsman-python3 subpackage Resolves: #1354481 From c4e0090cf8986d4d3fcc041b18917f42a870c933 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 3 Jan 2017 14:34:24 +0100 Subject: [PATCH 007/120] Port to openssl 1.1.0 --- openwsman-2.6.2-openssl-1.1-fix.patch | 217 ++++++++++++++++++++++++++ openwsman.spec | 8 +- 2 files changed, 224 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.6.2-openssl-1.1-fix.patch diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch new file mode 100644 index 0000000..59c1dc2 --- /dev/null +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -0,0 +1,217 @@ +diff -up openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.2/src/lib/wsman-curl-client-transport.c +--- openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/src/lib/wsman-curl-client-transport.c 2017-01-02 15:18:43.444990500 +0100 +@@ -239,12 +239,16 @@ write_handler( void *ptr, size_t size, s + static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) + { + unsigned char *thumbprint = (unsigned char *)arg; +- X509 *cert = ctx->cert; + EVP_MD *tempDigest; + + unsigned char tempFingerprint[EVP_MAX_MD_SIZE]; + unsigned int tempFingerprintLen; + tempDigest = (EVP_MD*)EVP_sha1( ); ++ ++ X509 *cert = X509_STORE_CTX_get_current_cert(ctx); ++ if(!cert) ++ return 0; ++ + if ( X509_digest(cert, tempDigest, tempFingerprint, &tempFingerprintLen ) <= 0) + return 0; + if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) +diff -up openwsman-2.6.2/src/server/shttpd/config.c.orig openwsman-2.6.2/src/server/shttpd/config.c +--- openwsman-2.6.2/src/server/shttpd/config.c.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/src/server/shttpd/config.c 2017-01-03 14:21:57.925415734 +0100 +@@ -85,32 +85,24 @@ static void + set_ssl(struct shttpd_ctx *ctx, void *arg, const char *pem) + { + SSL_CTX *CTX; ++ SSL_CONF_CTX *CCTX; + void *lib; + struct ssl_func *fp; + char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); ++ int ret; + + arg = NULL; /* Unused */ + +- /* Load SSL library dynamically */ +- if ((lib = dlopen(SSL_LIB, RTLD_LAZY)) == NULL) { +- elog(E_FATAL, NULL, "set_ssl: cannot load %s", SSL_LIB); +- ctx->ssl_ctx = NULL; +- return; +- } +- +- for (fp = ssl_sw; fp->name != NULL; fp++) { +- if ((fp->ptr.v_void = dlsym(lib, fp->name)) == NULL) { +- elog(E_FATAL, NULL,"set_ssl: cannot find %s", fp->name); +- ctx->ssl_ctx = NULL; +- return; +- } +- } +- + /* Initialize SSL crap */ + static int ssl_library_initialized = 0; + if(!ssl_library_initialized) { + debug("Initialize SSL"); ++ SSL_load_error_strings(); ++ #if OPENSSL_VERSION_NUMBER < 0x10100000L + SSL_library_init(); ++ #else ++ OPENSSL_init_ssl(0, NULL); ++ #endif + ssl_library_initialized = 1; + } + if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) { +@@ -126,17 +118,26 @@ set_ssl(struct shttpd_ctx *ctx, void *ar + SSL_CTX_free(CTX); + CTX = NULL; + } ++ if ((CCTX = SSL_CONF_CTX_new()) == NULL) { ++ elog(E_FATAL, NULL, "SSL_CONF_CTX_new error"); ++ debug("SSL_CONF_CTX_new error"); ++ } ++ else { ++ SSL_CONF_CTX_set_ssl_ctx(CCTX, CTX); ++ } ++ ++/* + while (ssl_disabled_protocols) { + struct ctx_opts_t { + char *name; +- long opt; ++ char *opt; + } protocols[] = { +- { "SSLv2", SSL_OP_NO_SSLv2 }, +- { "SSLv3", SSL_OP_NO_SSLv3 }, +- { "TLSv1", SSL_OP_NO_TLSv1 }, ++ { "SSLv2", "SSLv2" }, ++ { "SSLv3", "SSLv3" }, ++ { "TLSv1", "TLSv1" }, + # if OPENSSL_VERSION_NUMBER >= 0x10001000L +- { "TLSv1_1", SSL_OP_NO_TLSv1_1 }, +- { "TLSv1_2", SSL_OP_NO_TLSv1_2 }, ++ { "TLSv1_1", "TLSv1.1" }, ++ { "TLSv1_2", "TLSv1.2" }, + # endif + { NULL, 0 } + }; +@@ -150,7 +151,17 @@ set_ssl(struct shttpd_ctx *ctx, void *ar + for (idx = 0; protocols[idx].name ; ++idx) { + if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { + debug("SSL: disable %s protocol", protocols[idx].name); +- SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); ++ debug("SSL: set '%s' as minimum protocol version - opt value", protocols[idx].opt); ++ ret = SSL_CONF_cmd(CTX, "MinProtocol", protocols[idx].opt); ++ if (ret > 2) { ++ debug("SSL: SSL_CONF_cmd OK"); ++ } ++ if (ret == -2) { ++ debug("SSL: SSL_CONF_cmd ret == -2"); ++ } ++ if (ret != -2) { ++ debug("Error processing SSL_CONF_cmd()"); ++ } + break; + } + } +@@ -158,6 +169,10 @@ set_ssl(struct shttpd_ctx *ctx, void *ar + break; + ssl_disabled_protocols = blank_ptr + 1; + } ++*/ ++ if (!SSL_CONF_CTX_finish(CCTX)) { ++ elog(E_FATAL, NULL, "SSL_CONF_CTX_finish error"); ++ } + + ctx->ssl_ctx = CTX; + } +diff -up openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig openwsman-2.6.2/src/server/shttpd/io_ssl.c +--- openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/src/server/shttpd/io_ssl.c 2017-01-03 13:43:13.926524433 +0100 +@@ -11,26 +11,6 @@ + #include "shttpd_defs.h" + + #if !defined(NO_SSL) +-struct ssl_func ssl_sw[] = { +- {"SSL_free", {0}}, +- {"SSL_accept", {0}}, +- {"SSL_connect", {0}}, +- {"SSL_read", {0}}, +- {"SSL_write", {0}}, +- {"SSL_get_error", {0}}, +- {"SSL_set_fd", {0}}, +- {"SSL_new", {0}}, +- {"SSL_CTX_new", {0}}, +- {"SSLv23_server_method", {0}}, +- {"SSL_library_init", {0}}, +- {"SSL_CTX_use_PrivateKey_file", {0}}, +- {"SSL_CTX_use_certificate_file",{0}}, +- {"SSL_CTX_free", {0}}, +- {"SSL_pending", {0}}, +- {"SSL_CTX_use_certificate_chain_file",{0}}, +- {"SSL_CTX_ctrl", {0}}, +- {NULL, {0}} +-}; + + void + ssl_handshake(struct stream *stream) +diff -up openwsman-2.6.2/src/server/shttpd/ssl.h.orig openwsman-2.6.2/src/server/shttpd/ssl.h +--- openwsman-2.6.2/src/server/shttpd/ssl.h.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/src/server/shttpd/ssl.h 2017-01-02 15:18:43.445990500 +0100 +@@ -12,56 +12,4 @@ + + # include + +-#else +- +-/* +- * Snatched from OpenSSL includes. I put the prototypes here to be independent +- * from the OpenSSL source installation. Having this, shttpd + SSL can be +- * built on any system with binary SSL libraries installed. +- */ +- +-typedef struct ssl_st SSL; +-typedef struct ssl_method_st SSL_METHOD; +-typedef struct ssl_ctx_st SSL_CTX; +- +-#define SSL_ERROR_WANT_READ 2 +-#define SSL_ERROR_WANT_WRITE 3 +-#define SSL_ERROR_SYSCALL 5 +-#define SSL_FILETYPE_PEM 1 +- + #endif +- +-/* +- * Dynamically loaded SSL functionality +- */ +-struct ssl_func { +- const char *name; /* SSL function name */ +- union variant ptr; /* Function pointer */ +-}; +- +-extern struct ssl_func ssl_sw[]; +- +-#define FUNC(x) ssl_sw[x].ptr.v_func +- +-#define SSL_free(x) (* (void (*)(SSL *)) FUNC(0))(x) +-#define SSL_accept(x) (* (int (*)(SSL *)) FUNC(1))(x) +-#define SSL_connect(x) (* (int (*)(SSL *)) FUNC(2))(x) +-#define SSL_read(x,y,z) (* (int (*)(SSL *, void *, int)) FUNC(3))((x),(y),(z)) +-#define SSL_write(x,y,z) \ +- (* (int (*)(SSL *, const void *,int)) FUNC(4))((x), (y), (z)) +-#define SSL_get_error(x,y)(* (int (*)(SSL *, int)) FUNC(5))((x), (y)) +-#define SSL_set_fd(x,y) (* (int (*)(SSL *, int)) FUNC(6))((x), (y)) +-#define SSL_new(x) (* (SSL * (*)(SSL_CTX *)) FUNC(7))(x) +-#define SSL_CTX_new(x) (* (SSL_CTX * (*)(SSL_METHOD *)) FUNC(8))(x) +-#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() +-#define SSL_library_init() (* (int (*)(void)) FUNC(10))() +-#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ +- const char *, int)) FUNC(11))((x), (y), (z)) +-#define SSL_CTX_use_certificate_file(x,y,z) (* (int (*)(SSL_CTX *, \ +- const char *, int)) FUNC(12))((x), (y), (z)) +-#define SSL_CTX_use_certificate_chain_file(x,y) (* (int (*)(SSL_CTX *, \ +- const char *)) FUNC(15))((x), (y)) +-#define SSL_CTX_free(x) (*(void (*)(SSL_CTX *)) FUNC(13))(x) +-#define SSL_pending(x) (*(int (*)(SSL *)) FUNC(14))(x) +-#define SSL_CTX_ctrl(w,x,y,z) (*(long (*)(SSL_CTX *,int,long,void *)) FUNC(16))((w),(x),(y),(z)) +- diff --git a/openwsman.spec b/openwsman.spec index fc310a3..8a1ac98 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -9,7 +9,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 8%{?dist} +Release: 9%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -27,6 +27,7 @@ Patch1: openwsman-2.2.7-libssl.patch Patch2: openwsman-2.4.0-pamsetup.patch Patch3: openwsman-2.4.12-ruby-binding-build.patch Patch4: openwsman-2.6.2-python3.patch +Patch5: openwsman-2.6.2-openssl-1.1-fix.patch %description Openwsman is a project intended to provide an open-source @@ -183,6 +184,7 @@ popd %patch2 -p1 -b .pamsetup %patch3 -p1 -b .ruby-binding-build %patch4 -p1 -b .python3 +%patch5 -p1 -b .openssl-1.1-fix # support ruby 2.2 pushd bindings/ruby @@ -357,6 +359,10 @@ rm -f /var/log/wsmand.log %changelog +* Tue Jan 03 2017 Vitezslav Crhonek - 2.6.2-9 +- Port to openssl 1.1.0 + Resolves: #1383992 + * Mon Dec 19 2016 Miro Hrončok - 2.6.2-8 - Rebuild for Python 3.6 From 5efde7440c26f2f3232c2614716f84b98d8df07b Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 9 Jan 2017 16:31:54 +0100 Subject: [PATCH 008/120] Disable SSL protocols listed in config file --- openwsman-2.6.2-openssl-1.1-fix.patch | 76 +++------------------------ openwsman.spec | 5 +- 2 files changed, 11 insertions(+), 70 deletions(-) diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 59c1dc2..f0fa3c1 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ diff -up openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.2/src/lib/wsman-curl-client-transport.c --- openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/lib/wsman-curl-client-transport.c 2017-01-02 15:18:43.444990500 +0100 ++++ openwsman-2.6.2/src/lib/wsman-curl-client-transport.c 2017-01-09 15:12:40.823514921 +0100 @@ -239,12 +239,16 @@ write_handler( void *ptr, size_t size, s static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) { @@ -21,16 +21,8 @@ diff -up openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig openwsman-2. if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) diff -up openwsman-2.6.2/src/server/shttpd/config.c.orig openwsman-2.6.2/src/server/shttpd/config.c --- openwsman-2.6.2/src/server/shttpd/config.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/config.c 2017-01-03 14:21:57.925415734 +0100 -@@ -85,32 +85,24 @@ static void - set_ssl(struct shttpd_ctx *ctx, void *arg, const char *pem) - { - SSL_CTX *CTX; -+ SSL_CONF_CTX *CCTX; - void *lib; - struct ssl_func *fp; - char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); -+ int ret; ++++ openwsman-2.6.2/src/server/shttpd/config.c 2017-01-09 15:13:03.561467272 +0100 +@@ -91,26 +91,16 @@ set_ssl(struct shttpd_ctx *ctx, void *ar arg = NULL; /* Unused */ @@ -62,72 +54,18 @@ diff -up openwsman-2.6.2/src/server/shttpd/config.c.orig openwsman-2.6.2/src/ser ssl_library_initialized = 1; } if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) { -@@ -126,17 +118,26 @@ set_ssl(struct shttpd_ctx *ctx, void *ar - SSL_CTX_free(CTX); - CTX = NULL; - } -+ if ((CCTX = SSL_CONF_CTX_new()) == NULL) { -+ elog(E_FATAL, NULL, "SSL_CONF_CTX_new error"); -+ debug("SSL_CONF_CTX_new error"); -+ } -+ else { -+ SSL_CONF_CTX_set_ssl_ctx(CCTX, CTX); -+ } -+ -+/* - while (ssl_disabled_protocols) { - struct ctx_opts_t { - char *name; -- long opt; -+ char *opt; - } protocols[] = { -- { "SSLv2", SSL_OP_NO_SSLv2 }, -- { "SSLv3", SSL_OP_NO_SSLv3 }, -- { "TLSv1", SSL_OP_NO_TLSv1 }, -+ { "SSLv2", "SSLv2" }, -+ { "SSLv3", "SSLv3" }, -+ { "TLSv1", "TLSv1" }, - # if OPENSSL_VERSION_NUMBER >= 0x10001000L -- { "TLSv1_1", SSL_OP_NO_TLSv1_1 }, -- { "TLSv1_2", SSL_OP_NO_TLSv1_2 }, -+ { "TLSv1_1", "TLSv1.1" }, -+ { "TLSv1_2", "TLSv1.2" }, - # endif - { NULL, 0 } - }; -@@ -150,7 +151,17 @@ set_ssl(struct shttpd_ctx *ctx, void *ar +@@ -150,7 +140,7 @@ set_ssl(struct shttpd_ctx *ctx, void *ar for (idx = 0; protocols[idx].name ; ++idx) { if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { debug("SSL: disable %s protocol", protocols[idx].name); - SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); -+ debug("SSL: set '%s' as minimum protocol version - opt value", protocols[idx].opt); -+ ret = SSL_CONF_cmd(CTX, "MinProtocol", protocols[idx].opt); -+ if (ret > 2) { -+ debug("SSL: SSL_CONF_cmd OK"); -+ } -+ if (ret == -2) { -+ debug("SSL: SSL_CONF_cmd ret == -2"); -+ } -+ if (ret != -2) { -+ debug("Error processing SSL_CONF_cmd()"); -+ } ++ SSL_CTX_set_options(CTX, protocols[idx].opt); break; } } -@@ -158,6 +169,10 @@ set_ssl(struct shttpd_ctx *ctx, void *ar - break; - ssl_disabled_protocols = blank_ptr + 1; - } -+*/ -+ if (!SSL_CONF_CTX_finish(CCTX)) { -+ elog(E_FATAL, NULL, "SSL_CONF_CTX_finish error"); -+ } - - ctx->ssl_ctx = CTX; - } diff -up openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig openwsman-2.6.2/src/server/shttpd/io_ssl.c --- openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/io_ssl.c 2017-01-03 13:43:13.926524433 +0100 ++++ openwsman-2.6.2/src/server/shttpd/io_ssl.c 2017-01-09 15:12:40.824514919 +0100 @@ -11,26 +11,6 @@ #include "shttpd_defs.h" @@ -157,7 +95,7 @@ diff -up openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig openwsman-2.6.2/src/ser ssl_handshake(struct stream *stream) diff -up openwsman-2.6.2/src/server/shttpd/ssl.h.orig openwsman-2.6.2/src/server/shttpd/ssl.h --- openwsman-2.6.2/src/server/shttpd/ssl.h.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/ssl.h 2017-01-02 15:18:43.445990500 +0100 ++++ openwsman-2.6.2/src/server/shttpd/ssl.h 2017-01-09 15:12:40.824514919 +0100 @@ -12,56 +12,4 @@ # include diff --git a/openwsman.spec b/openwsman.spec index 8a1ac98..f490d72 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -9,7 +9,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 9%{?dist} +Release: 10%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -359,6 +359,9 @@ rm -f /var/log/wsmand.log %changelog +* Mon Jan 09 2017 Vitezslav Crhonek - 2.6.2-10 +- Disable SSL protocols listed in config file + * Tue Jan 03 2017 Vitezslav Crhonek - 2.6.2-9 - Port to openssl 1.1.0 Resolves: #1383992 From 6caad7afa8825febf976b9f2b545b678fd1b001f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?V=C3=ADt=20Ondruch?= Date: Thu, 12 Jan 2017 16:13:44 +0100 Subject: [PATCH 009/120] Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.4 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index f490d72..78a2d3a 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -9,7 +9,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 10%{?dist} +Release: 11%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -359,6 +359,9 @@ rm -f /var/log/wsmand.log %changelog +* Thu Jan 12 2017 Vít Ondruch - 2.6.2-11 +- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.4 + * Mon Jan 09 2017 Vitezslav Crhonek - 2.6.2-10 - Disable SSL protocols listed in config file From 39db6f660e303120d2c60f6b1c5c97e847f73182 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 17 Jan 2017 09:54:36 +0100 Subject: [PATCH 010/120] Update to openwsman-2.6.3 from upstream VCS --- .gitignore | 18 +-- openwsman-2.2.7-libssl.patch | 12 -- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 172 +++++++++++++--------- openwsman-2.6.2-python3.patch | 34 ++--- openwsman.spec | 49 +++--- sources | 4 +- 7 files changed, 149 insertions(+), 142 deletions(-) delete mode 100644 openwsman-2.2.7-libssl.patch diff --git a/.gitignore b/.gitignore index de1dfbc..ddcadc6 100644 --- a/.gitignore +++ b/.gitignore @@ -1,18 +1,2 @@ -openwsman-2.2.3.tar.bz2 -/openwsman-2.2.4.tar.bz2 -/openwsman-2.2.5.tar.bz2 -/openwsman-2.2.7.tar.bz2 -/openwsman-2.3.0.tar.bz2 -/openwsman-2.3.5.tar.bz2 -/openwsman-2.3.6.tar.bz2 /openwsmand.8.gz -/openwsman-2.4.0.tar.gz -/v2.4.3.tar.gz -/v2.4.4.tar.gz -/v2.4.6.tar.gz -/openwsman-2.4.12.tar.gz -/openwsman-2.4.14.tar.gz -/openwsman-2.4.15.tar.gz -/openwsman-2.6.0.tar.gz -/openwsman-2.6.1.tar.gz -/openwsman-2.6.2.tar.gz +/openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz diff --git a/openwsman-2.2.7-libssl.patch b/openwsman-2.2.7-libssl.patch deleted file mode 100644 index 717e88e..0000000 --- a/openwsman-2.2.7-libssl.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.2.7/src/server/shttpd/compat_unix.h.orig openwsman-2.2.7/src/server/shttpd/compat_unix.h ---- openwsman-2.2.7/src/server/shttpd/compat_unix.h.orig 2012-02-09 13:04:47.528527681 +0100 -+++ openwsman-2.2.7/src/server/shttpd/compat_unix.h 2012-02-09 13:05:31.582568867 +0100 -@@ -21,7 +21,7 @@ - #include - #include - #ifndef SSL_LIB --#define SSL_LIB "libssl.so" -+#define SSL_LIB "libssl.so.10" - #endif - #define DIRSEP '/' - #define IS_DIRSEP_CHAR(c) ((c) == '/') diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 133cca3..e9e478d 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.2/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index f0fa3c1..bfa6c94 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,7 +1,7 @@ -diff -up openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.2/src/lib/wsman-curl-client-transport.c ---- openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/lib/wsman-curl-client-transport.c 2017-01-09 15:12:40.823514921 +0100 -@@ -239,12 +239,16 @@ write_handler( void *ptr, size_t size, s +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c 2017-01-16 14:40:03.094728843 +0100 +@@ -241,12 +241,16 @@ write_handler( void *ptr, size_t size, s static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) { unsigned char *thumbprint = (unsigned char *)arg; @@ -19,55 +19,55 @@ diff -up openwsman-2.6.2/src/lib/wsman-curl-client-transport.c.orig openwsman-2. if ( X509_digest(cert, tempDigest, tempFingerprint, &tempFingerprintLen ) <= 0) return 0; if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) -diff -up openwsman-2.6.2/src/server/shttpd/config.c.orig openwsman-2.6.2/src/server/shttpd/config.c ---- openwsman-2.6.2/src/server/shttpd/config.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/config.c 2017-01-09 15:13:03.561467272 +0100 -@@ -91,26 +91,16 @@ set_ssl(struct shttpd_ctx *ctx, void *ar +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h 2017-01-16 14:40:03.094728843 +0100 +@@ -27,7 +27,6 @@ + pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) + #endif /* !NO_THREADS */ - arg = NULL; /* Unused */ - -- /* Load SSL library dynamically */ -- if ((lib = dlopen(SSL_LIB, RTLD_LAZY)) == NULL) { -- elog(E_FATAL, NULL, "set_ssl: cannot load %s", SSL_LIB); -- ctx->ssl_ctx = NULL; -- return; -- } -- -- for (fp = ssl_sw; fp->name != NULL; fp++) { -- if ((fp->ptr.v_void = dlsym(lib, fp->name)) == NULL) { -- elog(E_FATAL, NULL,"set_ssl: cannot find %s", fp->name); -- ctx->ssl_ctx = NULL; -- return; -- } -- } -- - /* Initialize SSL crap */ - static int ssl_library_initialized = 0; - if(!ssl_library_initialized) { - debug("Initialize SSL"); -+ SSL_load_error_strings(); -+ #if OPENSSL_VERSION_NUMBER < 0x10100000L - SSL_library_init(); -+ #else -+ OPENSSL_init_ssl(0, NULL); -+ #endif - ssl_library_initialized = 1; - } - if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) { -@@ -150,7 +140,7 @@ set_ssl(struct shttpd_ctx *ctx, void *ar - for (idx = 0; protocols[idx].name ; ++idx) { - if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { - debug("SSL: disable %s protocol", protocols[idx].name); -- SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); -+ SSL_CTX_set_options(CTX, protocols[idx].opt); - break; - } - } -diff -up openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig openwsman-2.6.2/src/server/shttpd/io_ssl.c ---- openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/io_ssl.c 2017-01-09 15:12:40.824514919 +0100 -@@ -11,26 +11,6 @@ - #include "shttpd_defs.h" +-#define SSL_LIB "libssl.so" + #define DIRSEP '/' + #define IS_DIRSEP_CHAR(c) ((c) == '/') + #define O_BINARY 0 +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig 2017-01-16 14:40:57.223705664 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h 2017-01-16 14:38:15.000000000 +0100 +@@ -0,0 +1,29 @@ ++/* ++ * Copyright (c) 2004-2005 Sergey Lyubka ++ * All rights reserved ++ * ++ * "THE BEER-WARE LICENSE" (Revision 42): ++ * Sergey Lyubka wrote this file. As long as you retain this notice you ++ * can do whatever you want with this stuff. If we meet some day, and you think ++ * this stuff is worth it, you can buy me a beer in return. ++ */ ++ ++#ifndef CONFIG_HEADER_DEFINED ++#define CONFIG_HEADER_DEFINED ++ ++#define SHTTPD_VERSION "1.42" /* Version */ ++#define CONFIG_FILE "shttpd.conf" /* Configuration file */ ++#define HTPASSWD ".htpasswd" /* Passwords file name */ ++#define URI_MAX 16384 /* Default max request size */ ++#define LISTENING_PORTS "80" /* Default listening ports */ ++#define INDEX_FILES "index.html,index.htm,index.php,index.cgi" ++#define CGI_EXT "cgi,pl,php" /* Default CGI extensions */ ++#define SSI_EXT "shtml,shtm" /* Default SSI extensions */ ++#define REALM "mydomain.com" /* Default authentication realm */ ++#define DELIM_CHARS "," /* Separators for lists */ ++#define EXPIRE_TIME 3600 /* Expiration time, seconds */ ++#define ENV_MAX 4096 /* Size of environment block */ ++#define CGI_ENV_VARS 64 /* Maximum vars passed to CGI */ ++#define SERVICE_NAME "SHTTPD " VERSION /* NT service name */ ++ ++#endif /* CONFIG_HEADER_DEFINED */ +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c 2017-01-16 14:40:03.094728843 +0100 +@@ -11,23 +11,6 @@ + #include "defs.h" #if !defined(NO_SSL) -struct ssl_func ssl_sw[] = { @@ -84,21 +84,57 @@ diff -up openwsman-2.6.2/src/server/shttpd/io_ssl.c.orig openwsman-2.6.2/src/ser - {"SSL_library_init", {0}}, - {"SSL_CTX_use_PrivateKey_file", {0}}, - {"SSL_CTX_use_certificate_file",{0}}, -- {"SSL_CTX_free", {0}}, -- {"SSL_pending", {0}}, -- {"SSL_CTX_use_certificate_chain_file",{0}}, -- {"SSL_CTX_ctrl", {0}}, - {NULL, {0}} -}; - +- void - ssl_handshake(struct stream *stream) -diff -up openwsman-2.6.2/src/server/shttpd/ssl.h.orig openwsman-2.6.2/src/server/shttpd/ssl.h ---- openwsman-2.6.2/src/server/shttpd/ssl.h.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/src/server/shttpd/ssl.h 2017-01-09 15:12:40.824514919 +0100 -@@ -12,56 +12,4 @@ + _shttpd_ssl_handshake(struct stream *stream) + { +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c 2017-01-16 14:40:03.095728843 +0100 +@@ -1474,20 +1474,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch + char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); + int retval = FALSE; - # include +- /* Load SSL library dynamically */ +- if ((lib = dlopen(SSL_LIB, RTLD_LAZY)) == NULL) { +- _shttpd_elog(E_LOG, NULL, "set_ssl: cannot load %s", SSL_LIB); +- return (FALSE); +- } +- +- for (fp = ssl_sw; fp->name != NULL; fp++) +- if ((fp->ptr.v_void = dlsym(lib, fp->name)) == NULL) { +- _shttpd_elog(E_LOG, NULL,"set_ssl: cannot find %s", fp->name); +- return (FALSE); +- } +- + /* Initialize SSL crap */ ++ debug("Initialize SSL"); ++ SSL_load_error_strings(); ++ #if OPENSSL_VERSION_NUMBER < 0x10100000L + SSL_library_init(); ++ #else ++ OPENSSL_init_ssl(0, NULL); ++ #endif + + if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) + _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); +@@ -1523,7 +1517,7 @@ set_ssl(struct shttpd_ctx *ctx, const ch + if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { + //_shttpd_elog(E_LOG, NULL, "SSL: disable %s protocol", protocols[idx].name); + debug("SSL: disable %s protocol", protocols[idx].name); +- SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); ++ SSL_CTX_set_options(CTX, protocols[idx].opt); + break; + } + } +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h 2017-01-16 14:40:03.095728843 +0100 +@@ -12,50 +12,4 @@ + + #include -#else - @@ -114,8 +150,8 @@ diff -up openwsman-2.6.2/src/server/shttpd/ssl.h.orig openwsman-2.6.2/src/server - -#define SSL_ERROR_WANT_READ 2 -#define SSL_ERROR_WANT_WRITE 3 --#define SSL_ERROR_SYSCALL 5 --#define SSL_FILETYPE_PEM 1 +-#define SSL_ERROR_SYSCALL 5 +-#define SSL_FILETYPE_PEM 1 - #endif - @@ -147,9 +183,3 @@ diff -up openwsman-2.6.2/src/server/shttpd/ssl.h.orig openwsman-2.6.2/src/server - const char *, int)) FUNC(11))((x), (y), (z)) -#define SSL_CTX_use_certificate_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(12))((x), (y), (z)) --#define SSL_CTX_use_certificate_chain_file(x,y) (* (int (*)(SSL_CTX *, \ -- const char *)) FUNC(15))((x), (y)) --#define SSL_CTX_free(x) (*(void (*)(SSL_CTX *)) FUNC(13))(x) --#define SSL_pending(x) (*(int (*)(SSL *)) FUNC(14))(x) --#define SSL_CTX_ctrl(w,x,y,z) (*(long (*)(SSL_CTX *,int,long,void *)) FUNC(16))((w),(x),(y),(z)) -- diff --git a/openwsman-2.6.2-python3.patch b/openwsman-2.6.2-python3.patch index 39f9c97..3dcf3a0 100644 --- a/openwsman-2.6.2-python3.patch +++ b/openwsman-2.6.2-python3.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.6.2/bindings/CMakeLists.txt.orig openwsman-2.6.2/bindings/CMakeLists.txt ---- openwsman-2.6.2/bindings/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/bindings/CMakeLists.txt 2016-08-10 11:55:36.588710280 +0200 +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt 2017-01-16 14:08:53.201529586 +0100 @@ -10,6 +10,7 @@ include_directories(${CMAKE_BINARY_DIR}) IF( BUILD_PYTHON ) @@ -9,14 +9,14 @@ diff -up openwsman-2.6.2/bindings/CMakeLists.txt.orig openwsman-2.6.2/bindings/C ENDIF( BUILD_PYTHON ) IF( BUILD_RUBY ) -diff -up openwsman-2.6.2/bindings/python3/CMakeLists.txt.orig openwsman-2.6.2/bindings/python3/CMakeLists.txt ---- openwsman-2.6.2/bindings/python3/CMakeLists.txt.orig 2016-08-10 11:55:36.577710278 +0200 -+++ openwsman-2.6.2/bindings/python3/CMakeLists.txt 2016-08-10 15:15:46.005991322 +0200 +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt.orig 2017-01-16 14:08:09.000000000 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt 2017-01-16 14:10:48.945480021 +0100 @@ -12,11 +12,28 @@ enable_testing() add_subdirectory(tests) --EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON_LIB_DIR) +-EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON_LIB_DIR) -STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") +MESSAGE(STATUS "Python3 build:") +unset(Python_ADDITIONAL_VERSIONS) @@ -64,14 +64,14 @@ diff -up openwsman-2.6.2/bindings/python3/CMakeLists.txt.orig openwsman-2.6.2/bi -INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) +INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON3_LIB_DIR}) +INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON3_LIB_DIR} ) -diff -up openwsman-2.6.2/bindings/python/CMakeLists.txt.orig openwsman-2.6.2/bindings/python/CMakeLists.txt ---- openwsman-2.6.2/bindings/python/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/bindings/python/CMakeLists.txt 2016-08-10 15:00:21.126141161 +0200 +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt 2017-01-16 14:12:51.954427345 +0100 @@ -12,11 +12,52 @@ enable_testing() add_subdirectory(tests) --EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON_LIB_DIR) +-EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON_LIB_DIR) -STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") +MESSAGE(STATUS "Python2 build:") +set(Python_ADDITIONAL_VERSIONS 2.7) @@ -143,18 +143,18 @@ diff -up openwsman-2.6.2/bindings/python/CMakeLists.txt.orig openwsman-2.6.2/bin -INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) +INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON2_LIB_DIR}) +INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON2_LIB_DIR} ) -diff -up openwsman-2.6.2/CMakeLists.txt.orig openwsman-2.6.2/CMakeLists.txt ---- openwsman-2.6.2/CMakeLists.txt.orig 2015-10-19 15:27:46.000000000 +0200 -+++ openwsman-2.6.2/CMakeLists.txt 2016-08-10 11:55:36.588710280 +0200 -@@ -168,30 +168,6 @@ MESSAGE(STATUS "Building Ruby bindings" +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt 2017-01-16 14:13:37.300407926 +0100 +@@ -175,30 +175,6 @@ MESSAGE(STATUS "Building Ruby bindings" ENDIF(NOT RUBY_INCLUDE_PATH ) ENDIF( BUILD_RUBY ) -IF( BUILD_PYTHON ) - MESSAGE(STATUS "Building Python bindings" ) -- FIND_PACKAGE(PythonLibs) +- FIND_PACKAGE(PythonLibs 2.6 REQUIRED) - IF (PYTHON_LIBRARY) -- FIND_PACKAGE(PythonInterp REQUIRED) +- FIND_PACKAGE(PythonInterp 2.6 REQUIRED) - MESSAGE(STATUS "Found PythonLibs...") - FIND_PACKAGE(PythonLinkLibs) - IF (PYTHON_LINK_LIBS) diff --git a/openwsman.spec b/openwsman.spec index 78a2d3a..5270c4c 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,6 +1,9 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} +%global commit 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b +%global shortcommit %(c=%{commit}; echo ${c:0:7}) + Name: openwsman BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -8,26 +11,28 @@ BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel ruby BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units -Version: 2.6.2 -Release: 11%{?dist} +Version: 2.6.3 +Release: 1.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System Summary: Open source Implementation of WS-Management -# You can get this tarball here: -# https://github.com/Openwsman/openwsman/archive/v%{version}.tar.gz -Source: %{name}-%{version}.tar.gz +# The source for this package was pulled from upstream's vcs. Use the +# following commands to generate the tarball: +# git clone https://github.com/Openwsman/openwsman.git; cd openwsman +# git archive --format tar --prefix openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/ \ +# 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b | gzip > openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz +Source: %{name}-%{commit}.tar.gz # help2man generated manpage for openwsmand binary Source1: openwsmand.8.gz # service file for systemd Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre Source3: owsmantestcert.sh -Patch1: openwsman-2.2.7-libssl.patch -Patch2: openwsman-2.4.0-pamsetup.patch -Patch3: openwsman-2.4.12-ruby-binding-build.patch -Patch4: openwsman-2.6.2-python3.patch -Patch5: openwsman-2.6.2-openssl-1.1-fix.patch +Patch1: openwsman-2.4.0-pamsetup.patch +Patch2: openwsman-2.4.12-ruby-binding-build.patch +Patch3: openwsman-2.6.2-python3.patch +Patch4: openwsman-2.6.2-openssl-1.1-fix.patch %description Openwsman is a project intended to provide an open-source @@ -173,18 +178,17 @@ can use it to send shell commands to a remote Windows hosts. %prep -%setup -q +%setup -q -n %{name}-%{commit} # support python3 pushd bindings cp -r python python3 popd -%patch1 -p1 -b .libssl -%patch2 -p1 -b .pamsetup -%patch3 -p1 -b .ruby-binding-build -%patch4 -p1 -b .python3 -%patch5 -p1 -b .openssl-1.1-fix +%patch1 -p1 -b .pamsetup +%patch2 -p1 -b .ruby-binding-build +%patch3 -p1 -b .python3 +%patch4 -p1 -b .openssl-1.1-fix # support ruby 2.2 pushd bindings/ruby @@ -220,9 +224,9 @@ make # Make the freshly build openwsman libraries available to build the gem's # binary extension. -export LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{version}/build/src/lib -export CPATH=/builddir/build/BUILD/%{name}-%{version}/include/ -export LD_LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{version}/build/src/lib/ +export LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{commit}/build/src/lib +export CPATH=/builddir/build/BUILD/%{name}-%{commit}/include/ +export LD_LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{commit}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem @@ -263,9 +267,6 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ -# rename winrs.rb -> winrs -mv %{buildroot}/%{_bindir}/winrs.rb %{buildroot}%{_bindir}/winrs - %post -n libwsman1 -p /sbin/ldconfig %postun -n libwsman1 -p /sbin/ldconfig @@ -359,6 +360,10 @@ rm -f /var/log/wsmand.log %changelog +* Tue Jan 17 2017 Vitezslav Crhonek - 2.6.3-1.git4391e5c +- Update to openwsman-2.6.3 from upstream VCS + (because it contains shttpd 1.42) + * Thu Jan 12 2017 Vít Ondruch - 2.6.2-11 - Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.4 diff --git a/sources b/sources index d7b0ede..7e874d1 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -4f2d9b1d7da6d87fcd38a9aa23559723 openwsmand.8.gz -221163800046cca5ddb38868d3f82d7e openwsman-2.6.2.tar.gz +SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c +SHA512 (openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz) = 9126053fb65457662e7a6275afe16b6fa6aaf978c2909aff97bca3d7dd3c8c1e7378e86ced97de42f86dd1060f2c7246ac3b1ecc4bf3d853606cc9d2d60d8eed From 549757547170896bd3398e4617d22f9f59750b1b Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 11 Feb 2017 01:00:43 +0000 Subject: [PATCH 011/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 5270c4c..9e49790 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 1.git%{shortcommit}%{?dist} +Release: 2.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -360,6 +360,9 @@ rm -f /var/log/wsmand.log %changelog +* Sat Feb 11 2017 Fedora Release Engineering - 2.6.3-2.git4391e5c +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + * Tue Jan 17 2017 Vitezslav Crhonek - 2.6.3-1.git4391e5c - Update to openwsman-2.6.3 from upstream VCS (because it contains shttpd 1.42) From 8ac725e7c46c96966e0256be6dd1cedb0eca9729 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 13 Mar 2017 11:12:42 +0100 Subject: [PATCH 012/120] Add shebang to winrs ruby script, make it executable --- openwsman-2.6.2-winrs-shebang.patch | 9 +++++++++ openwsman.spec | 11 +++++++++-- 2 files changed, 18 insertions(+), 2 deletions(-) create mode 100644 openwsman-2.6.2-winrs-shebang.patch diff --git a/openwsman-2.6.2-winrs-shebang.patch b/openwsman-2.6.2-winrs-shebang.patch new file mode 100644 index 0000000..87cdc61 --- /dev/null +++ b/openwsman-2.6.2-winrs-shebang.patch @@ -0,0 +1,9 @@ +diff -up openwsman-2.6.2/examples/winrs.rb.orig openwsman-2.6.2/examples/winrs.rb +--- openwsman-2.6.2/examples/winrs.rb.orig 2015-10-19 15:27:46.000000000 +0200 ++++ openwsman-2.6.2/examples/winrs.rb 2017-03-13 10:30:22.812169561 +0100 +@@ -1,3 +1,5 @@ ++#!/usr/bin/env ruby ++# + # winrs.rb + # + # Windows Remote Shell diff --git a/openwsman.spec b/openwsman.spec index 4b5d0b3..5d5866e 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -16,7 +16,7 @@ BuildRequires: perl-devel pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.2 -Release: 3%{?dist} +Release: 4%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -33,6 +33,8 @@ Source3: owsmantestcert.sh Patch1: openwsman-2.2.7-libssl.patch Patch2: openwsman-2.4.0-pamsetup.patch Patch3: openwsman-2.4.12-ruby-binding-build.patch +# Patch4: adds shebang to winrs ruby script, already upstream +Patch4: openwsman-2.6.2-winrs-shebang.patch %description Openwsman is a project intended to provide an open-source @@ -168,6 +170,7 @@ can use it to send shell commands to a remote Windows hosts. %patch1 -p1 -b .libssl %patch2 -p1 -b .pamsetup %patch3 -p1 -b .ruby-binding-build +%patch4 -p1 -b .winrs-shebang # support ruby 2.2 pushd bindings/ruby @@ -332,10 +335,14 @@ rm -f /var/log/wsmand.log %doc AUTHORS COPYING ChangeLog README.md %files winrs -%{_bindir}/winrs +%attr(0755,root,root) %{_bindir}/winrs %changelog +* Mon Mar 13 2017 Vitezslav Crhonek - 2.6.2-4 +- Add shebang to winrs ruby script, make it executable + Resolves: #1387087 + * Thu Feb 04 2016 Fedora Release Engineering - 2.6.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild From 21b16061a101efff34b81b580e7a50007214dadd Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Sun, 4 Jun 2017 15:43:11 +0200 Subject: [PATCH 013/120] Perl 5.26 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 9e49790..6aa6753 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 2.git%{shortcommit}%{?dist} +Release: 3.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -360,6 +360,9 @@ rm -f /var/log/wsmand.log %changelog +* Sun Jun 04 2017 Jitka Plesnikova - 2.6.3-3.git4391e5c +- Perl 5.26 rebuild + * Sat Feb 11 2017 Fedora Release Engineering - 2.6.3-2.git4391e5c - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild From 27534e0c13f851c74204e69af1fc20909bc37102 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Wed, 12 Jul 2017 15:17:15 +0200 Subject: [PATCH 014/120] perl dependency renamed to perl-interpreter --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 6aa6753..5f8df56 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -7,7 +7,7 @@ Name: openwsman BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl +BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl-interpreter BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units From 4bb1f28e2547f448a11fcd34b9ff67c709bd48af Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 27 Jul 2017 01:55:42 +0000 Subject: [PATCH 015/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 5f8df56..bfa3ecb 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 3.git%{shortcommit}%{?dist} +Release: 4.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -360,6 +360,9 @@ rm -f /var/log/wsmand.log %changelog +* Thu Jul 27 2017 Fedora Release Engineering - 2.6.3-4.git4391e5c +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + * Sun Jun 04 2017 Jitka Plesnikova - 2.6.3-3.git4391e5c - Perl 5.26 rebuild From 4e09bf833c4f406bebe86f44b40f04388271623d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 3 Aug 2017 04:38:49 +0000 Subject: [PATCH 016/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index bfa3ecb..aeb6fa8 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 4.git%{shortcommit}%{?dist} +Release: 5.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -360,6 +360,9 @@ rm -f /var/log/wsmand.log %changelog +* Thu Aug 03 2017 Fedora Release Engineering - 2.6.3-5.git4391e5c +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + * Thu Jul 27 2017 Fedora Release Engineering - 2.6.3-4.git4391e5c - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild From bb317dc7aea458b7f4b118b77371c827d8391f1b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Sat, 19 Aug 2017 09:39:05 -0400 Subject: [PATCH 017/120] Python 2 binary package renamed to python2-openwsman --- openwsman.spec | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index aeb6fa8..8dc3a46 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 5.git%{shortcommit}%{?dist} +Release: 6.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -103,14 +103,18 @@ Openwsman Server and service libraries -%package python +%package -n python2-openwsman +%{?python_provide:%python_provide python2-openwsman} +# Remove before F30 +Provides: %{name}-python%{?_isa} = %{version}-%{release} +Obsoletes: %{name}-python < %{version}-%{release} License: BSD Group: Development/Libraries Summary: Python bindings for openwsman client API Requires: python2 Requires: libwsman1 = %{version}-%{release} -%description python +%description -n python2-openwsman This package provides Python2 bindings to access the openwsman client API. @@ -299,7 +303,7 @@ rm -f /var/log/wsmand.log %{_libdir}/*.so %doc AUTHORS COPYING ChangeLog README.md -%files python +%files -n python2-openwsman %{python2_sitearch}/*.so %{python2_sitearch}/*.py %{python2_sitearch}/*.pyc @@ -360,6 +364,10 @@ rm -f /var/log/wsmand.log %changelog +* Sat Aug 19 2017 Zbigniew Jędrzejewski-Szmek - 2.6.3-6.git4391e5c +- Python 2 binary package renamed to python2-openwsman + See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3 + * Thu Aug 03 2017 Fedora Release Engineering - 2.6.3-5.git4391e5c - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild From 307beb63ab92f089bd02cf3c909c36d147dc563d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Sun, 20 Aug 2017 10:39:47 -0400 Subject: [PATCH 018/120] Add Provides for the old name without %_isa --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8dc3a46..00587db 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -12,7 +12,7 @@ BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units Version: 2.6.3 -Release: 6.git%{shortcommit}%{?dist} +Release: 7.git%{shortcommit}%{?dist} Url: http://www.openwsman.org/ License: BSD Group: Applications/System @@ -106,6 +106,7 @@ Openwsman Server and service libraries %package -n python2-openwsman %{?python_provide:%python_provide python2-openwsman} # Remove before F30 +Provides: %{name}-python = %{version}-%{release} Provides: %{name}-python%{?_isa} = %{version}-%{release} Obsoletes: %{name}-python < %{version}-%{release} License: BSD @@ -364,6 +365,9 @@ rm -f /var/log/wsmand.log %changelog +* Sun Aug 20 2017 Zbigniew Jędrzejewski-Szmek - 2.6.3-7.git4391e5c +- Add Provides for the old name without %%_isa + * Sat Aug 19 2017 Zbigniew Jędrzejewski-Szmek - 2.6.3-6.git4391e5c - Python 2 binary package renamed to python2-openwsman See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3 From 2b477257dd89e15209070a1237cb114e1bb340ac Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 12 Sep 2017 14:21:50 +0200 Subject: [PATCH 019/120] Spec file clean up, Updated openssl-1.1 patch --- openwsman-2.6.2-openssl-1.1-fix.patch | 35 ++-- openwsman.spec | 232 +++++++++++--------------- 2 files changed, 117 insertions(+), 150 deletions(-) diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index bfa6c94..82c333c 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,7 +1,7 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c --- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c 2017-01-16 14:40:03.094728843 +0100 -@@ -241,12 +241,16 @@ write_handler( void *ptr, size_t size, s ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c 2017-09-12 12:56:51.720463095 +0200 +@@ -241,12 +241,20 @@ write_handler( void *ptr, size_t size, s static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) { unsigned char *thumbprint = (unsigned char *)arg; @@ -12,7 +12,11 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-c unsigned int tempFingerprintLen; tempDigest = (EVP_MD*)EVP_sha1( ); + ++#if OPENSSL_VERSION_NUMBER >= 0x10100000L + X509 *cert = X509_STORE_CTX_get_current_cert(ctx); ++#else ++ X509 *cert = ctx->cert; ++#endif + if(!cert) + return 0; + @@ -21,7 +25,7 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-c if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h --- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h 2017-01-16 14:40:03.094728843 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h 2017-09-12 12:56:51.720463095 +0200 @@ -27,7 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -31,8 +35,8 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/co #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig 2017-01-16 14:40:57.223705664 +0100 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h 2017-01-16 14:38:15.000000000 +0100 +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig 2017-09-12 12:56:51.720463095 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h 2017-09-12 12:56:51.720463095 +0200 @@ -0,0 +1,29 @@ +/* + * Copyright (c) 2004-2005 Sergey Lyubka @@ -65,7 +69,7 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/co +#endif /* CONFIG_HEADER_DEFINED */ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c --- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c 2017-01-16 14:40:03.094728843 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c 2017-09-12 12:56:51.720463095 +0200 @@ -11,23 +11,6 @@ #include "defs.h" @@ -92,7 +96,7 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io { diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c --- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c 2017-01-16 14:40:03.095728843 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c 2017-09-12 12:58:20.132254340 +0200 @@ -1474,20 +1474,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); int retval = FALSE; @@ -112,26 +116,29 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/sh /* Initialize SSL crap */ + debug("Initialize SSL"); + SSL_load_error_strings(); -+ #if OPENSSL_VERSION_NUMBER < 0x10100000L - SSL_library_init(); -+ #else ++#if OPENSSL_VERSION_NUMBER >= 0x10100000L + OPENSSL_init_ssl(0, NULL); -+ #endif ++#else + SSL_library_init(); ++#endif if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -@@ -1523,7 +1517,7 @@ set_ssl(struct shttpd_ctx *ctx, const ch +@@ -1523,7 +1517,11 @@ set_ssl(struct shttpd_ctx *ctx, const ch if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { //_shttpd_elog(E_LOG, NULL, "SSL: disable %s protocol", protocols[idx].name); debug("SSL: disable %s protocol", protocols[idx].name); -- SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); ++#if OPENSSL_VERSION_NUMBER >= 0x10100000L + SSL_CTX_set_options(CTX, protocols[idx].opt); ++#else + SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); ++#endif break; } } diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h --- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h 2017-01-16 14:40:03.095728843 +0100 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h 2017-09-12 12:56:51.721463093 +0200 @@ -12,50 +12,4 @@ #include diff --git a/openwsman.spec b/openwsman.spec index 00587db..2e6f0c7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,186 +1,143 @@ # RubyGems's macros expect gem_name to exist. -%global gem_name %{name} +%global gem_name %{name} -%global commit 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b -%global shortcommit %(c=%{commit}; echo ${c:0:7}) +%global commit 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b +%global shortcommit %(c=%{commit}; echo ${c:0:7}) -Name: openwsman -BuildRequires: swig -BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl-interpreter -BuildRequires: perl-devel perl-generators pkgconfig openssl-devel -BuildRequires: cmake -BuildRequires: systemd-units -Version: 2.6.3 -Release: 7.git%{shortcommit}%{?dist} -Url: http://www.openwsman.org/ -License: BSD -Group: Applications/System -Summary: Open source Implementation of WS-Management +Name: openwsman +Version: 2.6.3 +Release: 8.git%{shortcommit}%{?dist} +Summary: Open source Implementation of WS-Management + +License: BSD +URL: http://www.openwsman.org/ # The source for this package was pulled from upstream's vcs. Use the # following commands to generate the tarball: # git clone https://github.com/Openwsman/openwsman.git; cd openwsman # git archive --format tar --prefix openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/ \ # 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b | gzip > openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz -Source: %{name}-%{commit}.tar.gz +Source0: %{name}-%{commit}.tar.gz # help2man generated manpage for openwsmand binary -Source1: openwsmand.8.gz +Source1: openwsmand.8.gz # service file for systemd -Source2: openwsmand.service +Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre -Source3: owsmantestcert.sh -Patch1: openwsman-2.4.0-pamsetup.patch -Patch2: openwsman-2.4.12-ruby-binding-build.patch -Patch3: openwsman-2.6.2-python3.patch -Patch4: openwsman-2.6.2-openssl-1.1-fix.patch +Source3: owsmantestcert.sh +Patch1: openwsman-2.4.0-pamsetup.patch +Patch2: openwsman-2.4.12-ruby-binding-build.patch +Patch3: openwsman-2.6.2-python3.patch +Patch4: openwsman-2.6.2-openssl-1.1-fix.patch +BuildRequires: swig +BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel +BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl-interpreter +BuildRequires: perl-devel perl-generators pkgconfig openssl-devel +BuildRequires: cmake +BuildRequires: systemd-units %description Openwsman is a project intended to provide an open-source -implementation of the Web Services Management specipication +implementation of the Web Services Management specification (WS-Management) and to expose system management information on the Linux operating system using the WS-Management protocol. WS-Management is based on a suite of web services specifications and usage requirements that exposes a set of operations focused on and covers all system management aspects. - - - %package -n libwsman1 -License: BSD -Group: System Environment/Libraries -Summary: Open source Implementation of WS-Management -Provides: %{name} = %{version}-%{release} -Obsoletes: %{name} < %{version}-%{release} +License: BSD +Summary: Open source Implementation of WS-Management +Provides: %{name} = %{version}-%{release} +Obsoletes: %{name} < %{version}-%{release} %description -n libwsman1 -Openwsman library for packages dependent on openwsman - - - +Openwsman library for packages dependent on openwsman. %package -n libwsman-devel -License: BSD -Group: Development/Libraries -Summary: Open source Implementation of WS-Management -Provides: %{name}-devel = %{version}-%{release} -Obsoletes: %{name}-devel < %{version}-%{release} -Requires: libwsman1 = %{version}-%{release} -Requires: %{name}-server = %{version}-%{release} -Requires: %{name}-client = %{version}-%{release} -Requires: sblim-sfcc-devel libxml2-devel pam-devel -Requires: libcurl-devel +License: BSD +Summary: Open source Implementation of WS-Management +Provides: %{name}-devel = %{version}-%{release} +Obsoletes: %{name}-devel < %{version}-%{release} +Requires: libwsman1 = %{version}-%{release} +Requires: %{name}-server = %{version}-%{release} +Requires: %{name}-client = %{version}-%{release} +Requires: sblim-sfcc-devel libxml2-devel pam-devel +Requires: libcurl-devel %description -n libwsman-devel -Development files for openwsman - - +Development files for openwsman. %package client -License: BSD -Group: System Environment/Libraries -Summary: Openwsman Client libraries +License: BSD +Summary: Openwsman Client libraries %description client -Openwsman Client libraries - - - +Openwsman Client libraries. %package server -License: BSD -Group: System Environment/Daemons -Requires: net-tools -Requires(post): chkconfig -Requires(preun): chkconfig -Requires(postun): initscripts -Summary: Openwsman Server and service libraries -Requires: libwsman1 = %{version}-%{release} +License: BSD +Requires: net-tools +Summary: Openwsman Server and service libraries +Requires: libwsman1 = %{version}-%{release} %description server -Openwsman Server and service libraries - - - +Openwsman Server and service libraries. %package -n python2-openwsman %{?python_provide:%python_provide python2-openwsman} # Remove before F30 -Provides: %{name}-python = %{version}-%{release} -Provides: %{name}-python%{?_isa} = %{version}-%{release} -Obsoletes: %{name}-python < %{version}-%{release} -License: BSD -Group: Development/Libraries -Summary: Python bindings for openwsman client API -Requires: python2 -Requires: libwsman1 = %{version}-%{release} +Provides: %{name}-python = %{version}-%{release} +Provides: %{name}-python%{?_isa} = %{version}-%{release} +Obsoletes: %{name}-python < %{version}-%{release} +License: BSD +Summary: Python bindings for openwsman client API +Requires: python2 +Requires: libwsman1 = %{version}-%{release} %description -n python2-openwsman -This package provides Python2 bindings to access the openwsman client -API. - - - +This package provides Python2 bindings to access the openwsman client API. %package python3 -License: BSD -Group: Development/Libraries -Summary: Python bindings for openwsman client API -Requires: python3 -Requires: libwsman1 = %{version}-%{release} +License: BSD +Summary: Python bindings for openwsman client API +Requires: python3 +Requires: libwsman1 = %{version}-%{release} %description python3 -This package provides Python3 bindings to access the openwsman client -API. - - - +This package provides Python3 bindings to access the openwsman client API. %package -n rubygem-%{gem_name} -License: BSD -Group: Development/Libraries -Summary: Ruby client bindings for Openwsman -Obsoletes: %{name}-ruby < %{version}-%{release} +License: BSD +Summary: Ruby client bindings for Openwsman +Obsoletes: %{name}-ruby < %{version}-%{release} %description -n rubygem-%{gem_name} The openwsman gem provides a Ruby API to manage systems using the WS-Management protocol. %package -n rubygem-%{gem_name}-doc -Summary: Documentation for %{name} -Group: Documentation -Requires: rubygem-%{gem_name} = %{version}-%{release} -BuildArch: noarch +Summary: Documentation for %{name} +Requires: rubygem-%{gem_name} = %{version}-%{release} +BuildArch: noarch %description -n rubygem-%{gem_name}-doc Documentation for rubygem-%{gem_name} - - - %package perl -License: BSD -Group: Development/Libraries -Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) -Summary: Perl bindings for openwsman client API -Requires: libwsman1 = %{version}-%{release} +License: BSD +Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) +Summary: Perl bindings for openwsman client API +Requires: libwsman1 = %{version}-%{release} %description perl This package provides Perl bindings to access the openwsman client API. - - - %package winrs -Summary: Windows Remote Shell -Requires: rubygem-%{gem_name} = %{version}-%{release} +Summary: Windows Remote Shell +Requires: rubygem-%{gem_name} = %{version}-%{release} %description winrs -This is a command line tool for the Windows Remote Shell protocol. You -can use it to send shell commands to a remote Windows hosts. - - - +This is a command line tool for the Windows Remote Shell protocol. +You can use it to send shell commands to a remote Windows hosts. %prep %setup -q -n %{name}-%{commit} @@ -202,7 +159,6 @@ chmod 0755 rdoc2.2 ln -sf %{_bindir}/rdoc rdoc2_2.rb popd - %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -215,15 +171,15 @@ export CFLAGS="-D_GNU_SOURCE -fPIE -DPIE" export LDFLAGS="$LDFLAGS -Wl,-z,now -pie" cd build cmake \ - -DCMAKE_INSTALL_PREFIX=/usr \ - -DCMAKE_VERBOSE_MAKEFILE=TRUE \ - -DCMAKE_BUILD_TYPE=Release \ - -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ - -DCMAKE_CXX_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS" \ - -DCMAKE_SKIP_RPATH=1 \ - -DPACKAGE_ARCHITECTURE=`uname -m` \ - -DLIB=%{_lib} \ - .. + -DCMAKE_INSTALL_PREFIX=/usr \ + -DCMAKE_VERBOSE_MAKEFILE=TRUE \ + -DCMAKE_BUILD_TYPE=Release \ + -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ + -DCMAKE_CXX_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS" \ + -DCMAKE_SKIP_RPATH=1 \ + -DPACKAGE_ARCHITECTURE=`uname -m` \ + -DLIB=%{_lib} \ + .. make @@ -265,7 +221,7 @@ install -m 644 include/wsman-dispatcher.h %{buildroot}/%{_includedir}/openwsman mkdir -p %{buildroot}%{gem_dir} cp -pa ./build%{gem_dir}/* \ - %{buildroot}%{gem_dir}/ + %{buildroot}%{gem_dir}/ rm -rf %{buildroot}%{gem_instdir}/ext @@ -299,23 +255,23 @@ rm -f /var/log/wsmand.log %{_libdir}/libwsman_curl_client_transport.so.* %files -n libwsman-devel +%doc AUTHORS COPYING ChangeLog README.md %{_includedir}/* %{_libdir}/pkgconfig/* %{_libdir}/*.so -%doc AUTHORS COPYING ChangeLog README.md %files -n python2-openwsman +%doc AUTHORS COPYING ChangeLog README.md %{python2_sitearch}/*.so %{python2_sitearch}/*.py %{python2_sitearch}/*.pyc %{python2_sitearch}/*.pyo -%doc AUTHORS COPYING ChangeLog README.md %files python3 +%doc AUTHORS COPYING ChangeLog README.md %{python3_sitearch}/*.so %{python3_sitearch}/*.py %{python3_sitearch}/__pycache__/* -%doc AUTHORS COPYING ChangeLog README.md %files -n rubygem-%{gem_name} %doc AUTHORS COPYING ChangeLog README.md @@ -329,11 +285,12 @@ rm -f /var/log/wsmand.log %doc %{gem_docdir} %files perl +%doc AUTHORS COPYING ChangeLog README.md %{perl_vendorarch}/openwsman.so %{perl_vendorlib}/openwsman.pm -%doc AUTHORS COPYING ChangeLog README.md %files server +%doc AUTHORS COPYING ChangeLog README.md # Don't remove *.so files from the server package. # the server fails to start without these files. %dir %{_sysconfdir}/openwsman @@ -353,18 +310,21 @@ rm -f /var/log/wsmand.log %{_sbindir}/openwsmand %{_libdir}/libwsman_server.so.* %{_mandir}/man8/* -%doc AUTHORS COPYING ChangeLog README.md %files client +%doc AUTHORS COPYING ChangeLog README.md %{_libdir}/libwsman_clientpp.so.* %config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf -%doc AUTHORS COPYING ChangeLog README.md %files winrs %{_bindir}/winrs - %changelog +* Tue Sep 12 2017 Vitezslav Crhonek - 2.6.3-8.git4391e5c +- Spec file clean up (removed RPM Groups tags, removed obsolete chkconfig/initscripts + dependencies, improved readability, fixed indentation) +- Updated openssl-1.1 patch to support builds with older openssl versions + * Sun Aug 20 2017 Zbigniew Jędrzejewski-Szmek - 2.6.3-7.git4391e5c - Add Provides for the old name without %%_isa From 7e1a79131588b1b66494177883ebc7b2577c8ce1 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 4 Oct 2017 14:13:33 +0200 Subject: [PATCH 020/120] Remove unnecessary net-tools requirement --- openwsman.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 2e6f0c7..77c2b1f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -6,7 +6,7 @@ Name: openwsman Version: 2.6.3 -Release: 8.git%{shortcommit}%{?dist} +Release: 9.git%{shortcommit}%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -75,7 +75,6 @@ Openwsman Client libraries. %package server License: BSD -Requires: net-tools Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} @@ -320,6 +319,10 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Oct 04 2017 Vitezslav Crhonek - 2.6.3-9.git +- Remove unnecessary net-tools requirement + Resolves: #1496142 + * Tue Sep 12 2017 Vitezslav Crhonek - 2.6.3-8.git4391e5c - Spec file clean up (removed RPM Groups tags, removed obsolete chkconfig/initscripts dependencies, improved readability, fixed indentation) From fa331df4dd818e1a7bd185804c428bb01fae1d75 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Sat, 6 Jan 2018 15:31:08 +0900 Subject: [PATCH 021/120] Backport git patches to support 2.5 --- openwsman-2.6.2-0006-Find-Ruby-2.5.patch | 34 +++++++++++ ...-Make-ruby_parser_swig-Ruby2.5-aware.patch | 58 +++++++++++++++++++ openwsman.spec | 23 ++++---- 3 files changed, 104 insertions(+), 11 deletions(-) create mode 100644 openwsman-2.6.2-0006-Find-Ruby-2.5.patch create mode 100644 openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch diff --git a/openwsman-2.6.2-0006-Find-Ruby-2.5.patch b/openwsman-2.6.2-0006-Find-Ruby-2.5.patch new file mode 100644 index 0000000..3cb7279 --- /dev/null +++ b/openwsman-2.6.2-0006-Find-Ruby-2.5.patch @@ -0,0 +1,34 @@ +From 86f06c1e30b2fddeac6be8f8508ac225ebd0d4e1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= +Date: Fri, 24 Nov 2017 16:39:22 +0100 +Subject: [PATCH 06/20] Find Ruby 2.5 + +--- + cmake/modules/FindRuby.cmake | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/cmake/modules/FindRuby.cmake b/cmake/modules/FindRuby.cmake +index 1671f029..bc6d48d4 100644 +--- a/cmake/modules/FindRuby.cmake ++++ b/cmake/modules/FindRuby.cmake +@@ -21,7 +21,7 @@ endif (RUBY_LIBRARY AND RUBY_INCLUDE_PATH) + # RUBY_LIBDIR=`$RUBY -r rbconfig -e 'printf("%s",RbConfig::CONFIG@<:@"libdir"@:>@)'` + # RUBY_LIBRUBYARG=`$RUBY -r rbconfig -e 'printf("%s",RbConfig::CONFIG@<:@"LIBRUBYARG_SHARED"@:>@)'` + +-FIND_PROGRAM(RUBY_EXECUTABLE NAMES ruby ruby22 ruby21 ruby20 ruby19 ruby1.8 ruby18 ) ++FIND_PROGRAM(RUBY_EXECUTABLE NAMES ruby.ruby2.5 ruby.ruby2.4 ruby.ruby2.3 ruby.ruby2.2 ruby ruby22 ruby21 ruby20 ruby19 ruby1.8 ruby18 ) + + EXECUTE_PROCESS(COMMAND ${RUBY_EXECUTABLE} -r rbconfig -e "print RbConfig::CONFIG['MAJOR']" + OUTPUT_VARIABLE RUBY_VERSION_MAJOR) +@@ -91,7 +91,7 @@ FIND_PATH(RUBY_INCLUDE_PATH + /usr/lib/ruby/1.8/i586-linux-gnu/ ) + + FIND_LIBRARY(RUBY_LIBRARY +- NAMES ruby ruby1.9 ruby1.8 ++ NAMES ruby2.5 ruby2.4 ruby2.3 ruby2.2 ruby2.1 ruby ruby1.9 ruby1.8 + PATHS + ${RUBY_POSSIBLE_LIB_PATH} + ${RUBY_RUBY_LIB_PATH} +-- +2.15.1 + diff --git a/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch b/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch new file mode 100644 index 0000000..ed89add --- /dev/null +++ b/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch @@ -0,0 +1,58 @@ +From 0082a57f47aafb4ba3def4754602bdc0750ead6d Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= +Date: Fri, 24 Nov 2017 16:40:07 +0100 +Subject: [PATCH 08/20] Make ruby_parser_swig Ruby2.5-aware + +--- + bindings/ruby/rdoc_parser_swig.rb | 24 ++++++++++++++++++------ + 1 file changed, 18 insertions(+), 6 deletions(-) + +diff --git a/bindings/ruby/rdoc_parser_swig.rb b/bindings/ruby/rdoc_parser_swig.rb +index 6f72f791..0c5bd415 100644 +--- a/bindings/ruby/rdoc_parser_swig.rb ++++ b/bindings/ruby/rdoc_parser_swig.rb +@@ -364,11 +364,17 @@ class RDoc::Parser::SWIG < RDoc::Parser + + #meth_obj.params = params + meth_obj.start_collecting_tokens +- tk = RDoc::RubyToken::Token.new nil, 1, 1 +- tk.set_text body ++ begin ++ RDoc::const_get "RubyToken" ++ tk = RDoc::RubyToken::Token.new nil, 1, 1 ++ tk.set_text body ++ meth_obj.offset = offset ++ rescue NameError ++ # rdoc 2.5 ++ tk = { :line_no => 1, :char_no => 1, :text => body } ++ end + meth_obj.add_token tk + meth_obj.comment = strip_stars comment +- meth_obj.offset = offset + meth_obj.line = file_content[0, offset].count("\n") + 1 + + body +@@ -381,11 +387,17 @@ class RDoc::Parser::SWIG < RDoc::Parser + find_modifiers comment, meth_obj + + meth_obj.start_collecting_tokens +- tk = RDoc::RubyToken::Token.new nil, 1, 1 +- tk.set_text body ++ begin ++ RDoc::const_get "RubyToken" ++ tk = RDoc::RubyToken::Token.new nil, 1, 1 ++ tk.set_text body ++ meth_obj.offset = offset ++ rescue NameError ++ # rdoc 2.5 ++ tk = { :line_no => 1, :char_no => 1, :text => body } ++ end + meth_obj.add_token tk + meth_obj.comment = strip_stars(comment) + meth_obj.comment.to_s +- meth_obj.offset = offset + meth_obj.line = file_content[0, offset].count("\n") + 1 + + body +-- +2.15.1 + diff --git a/openwsman.spec b/openwsman.spec index 77c2b1f..3fd21ff 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -6,7 +6,7 @@ Name: openwsman Version: 2.6.3 -Release: 9.git%{shortcommit}%{?dist} +Release: 10.git%{shortcommit}%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -27,6 +27,9 @@ Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-python3.patch Patch4: openwsman-2.6.2-openssl-1.1-fix.patch +# Patch5, 6 are github backport fixes for ruby 2.5 +Patch5: openwsman-2.6.2-0006-Find-Ruby-2.5.patch +Patch6: openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -150,13 +153,8 @@ popd %patch2 -p1 -b .ruby-binding-build %patch3 -p1 -b .python3 %patch4 -p1 -b .openssl-1.1-fix - -# support ruby 2.2 -pushd bindings/ruby -cat rdoc2.1 | sed -e 's|rdoc2_1|rdoc2_2|' > rdoc2.2 -chmod 0755 rdoc2.2 -ln -sf %{_bindir}/rdoc rdoc2_2.rb -popd +%patch5 -p1 -b .ruby25_1 +%patch6 -p1 -b .ruby25_2 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -184,9 +182,9 @@ make # Make the freshly build openwsman libraries available to build the gem's # binary extension. -export LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{commit}/build/src/lib -export CPATH=/builddir/build/BUILD/%{name}-%{commit}/include/ -export LD_LIBRARY_PATH=/builddir/build/BUILD/%{name}-%{commit}/build/src/lib/ +export LIBRARY_PATH=%{_builddir}/%{name}-%{commit}/build/src/lib +export CPATH=%{_builddir}/%{name}-%{commit}/include/ +export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{commit}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem @@ -319,6 +317,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Sat Jan 6 2018 Mamoru TASAKA - 2.6.3-10.git4391e5c +- Backport git patches to support 2.5 + * Wed Oct 04 2017 Vitezslav Crhonek - 2.6.3-9.git - Remove unnecessary net-tools requirement Resolves: #1496142 From a9aed0bd879e5f981fd3535cd913a7fe80721107 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Sat, 6 Jan 2018 15:36:57 +0900 Subject: [PATCH 022/120] fix changelog --- openwsman.spec | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 3fd21ff..2002390 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -318,7 +318,8 @@ rm -f /var/log/wsmand.log %changelog * Sat Jan 6 2018 Mamoru TASAKA - 2.6.3-10.git4391e5c -- Backport git patches to support 2.5 +- F-28: rebuild for ruby 2.5 +- Backport git patches to support ruby 2.5 * Wed Oct 04 2017 Vitezslav Crhonek - 2.6.3-9.git - Remove unnecessary net-tools requirement From e348d774bc2bd6f0f0730fa0aa1b46566636e8fb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 20 Jan 2018 23:07:26 +0100 Subject: [PATCH 023/120] Rebuilt for switch to libxcrypt --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 2002390..e8daac1 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -6,7 +6,7 @@ Name: openwsman Version: 2.6.3 -Release: 10.git%{shortcommit}%{?dist} +Release: 11.git%{shortcommit}%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -317,6 +317,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Sat Jan 20 2018 Björn Esser - 2.6.3-11.git4391e5c +- Rebuilt for switch to libxcrypt + * Sat Jan 6 2018 Mamoru TASAKA - 2.6.3-10.git4391e5c - F-28: rebuild for ruby 2.5 - Backport git patches to support ruby 2.5 From 84d17f67f3866361d8b9a21e02aad33829ead5c2 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 23 Jan 2018 13:47:32 +0100 Subject: [PATCH 024/120] Update to openwsman-2.6.5 --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-0006-Find-Ruby-2.5.patch | 34 ---- ...-Make-ruby_parser_swig-Ruby2.5-aware.patch | 58 ------ openwsman-2.6.2-openssl-1.1-fix.patch | 74 +++----- openwsman-2.6.2-python3.patch | 179 ------------------ openwsman-2.6.5-http-status-line.patch | 39 ++++ openwsman.spec | 69 ++----- sources | 2 +- 9 files changed, 82 insertions(+), 377 deletions(-) delete mode 100644 openwsman-2.6.2-0006-Find-Ruby-2.5.patch delete mode 100644 openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch delete mode 100644 openwsman-2.6.2-python3.patch create mode 100644 openwsman-2.6.5-http-status-line.patch diff --git a/.gitignore b/.gitignore index ddcadc6..77b5874 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz +/v2.6.5.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index e9e478d..7f46996 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.5/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-0006-Find-Ruby-2.5.patch b/openwsman-2.6.2-0006-Find-Ruby-2.5.patch deleted file mode 100644 index 3cb7279..0000000 --- a/openwsman-2.6.2-0006-Find-Ruby-2.5.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 86f06c1e30b2fddeac6be8f8508ac225ebd0d4e1 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= -Date: Fri, 24 Nov 2017 16:39:22 +0100 -Subject: [PATCH 06/20] Find Ruby 2.5 - ---- - cmake/modules/FindRuby.cmake | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/cmake/modules/FindRuby.cmake b/cmake/modules/FindRuby.cmake -index 1671f029..bc6d48d4 100644 ---- a/cmake/modules/FindRuby.cmake -+++ b/cmake/modules/FindRuby.cmake -@@ -21,7 +21,7 @@ endif (RUBY_LIBRARY AND RUBY_INCLUDE_PATH) - # RUBY_LIBDIR=`$RUBY -r rbconfig -e 'printf("%s",RbConfig::CONFIG@<:@"libdir"@:>@)'` - # RUBY_LIBRUBYARG=`$RUBY -r rbconfig -e 'printf("%s",RbConfig::CONFIG@<:@"LIBRUBYARG_SHARED"@:>@)'` - --FIND_PROGRAM(RUBY_EXECUTABLE NAMES ruby ruby22 ruby21 ruby20 ruby19 ruby1.8 ruby18 ) -+FIND_PROGRAM(RUBY_EXECUTABLE NAMES ruby.ruby2.5 ruby.ruby2.4 ruby.ruby2.3 ruby.ruby2.2 ruby ruby22 ruby21 ruby20 ruby19 ruby1.8 ruby18 ) - - EXECUTE_PROCESS(COMMAND ${RUBY_EXECUTABLE} -r rbconfig -e "print RbConfig::CONFIG['MAJOR']" - OUTPUT_VARIABLE RUBY_VERSION_MAJOR) -@@ -91,7 +91,7 @@ FIND_PATH(RUBY_INCLUDE_PATH - /usr/lib/ruby/1.8/i586-linux-gnu/ ) - - FIND_LIBRARY(RUBY_LIBRARY -- NAMES ruby ruby1.9 ruby1.8 -+ NAMES ruby2.5 ruby2.4 ruby2.3 ruby2.2 ruby2.1 ruby ruby1.9 ruby1.8 - PATHS - ${RUBY_POSSIBLE_LIB_PATH} - ${RUBY_RUBY_LIB_PATH} --- -2.15.1 - diff --git a/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch b/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch deleted file mode 100644 index ed89add..0000000 --- a/openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch +++ /dev/null @@ -1,58 +0,0 @@ -From 0082a57f47aafb4ba3def4754602bdc0750ead6d Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Klaus=20K=C3=A4mpf?= -Date: Fri, 24 Nov 2017 16:40:07 +0100 -Subject: [PATCH 08/20] Make ruby_parser_swig Ruby2.5-aware - ---- - bindings/ruby/rdoc_parser_swig.rb | 24 ++++++++++++++++++------ - 1 file changed, 18 insertions(+), 6 deletions(-) - -diff --git a/bindings/ruby/rdoc_parser_swig.rb b/bindings/ruby/rdoc_parser_swig.rb -index 6f72f791..0c5bd415 100644 ---- a/bindings/ruby/rdoc_parser_swig.rb -+++ b/bindings/ruby/rdoc_parser_swig.rb -@@ -364,11 +364,17 @@ class RDoc::Parser::SWIG < RDoc::Parser - - #meth_obj.params = params - meth_obj.start_collecting_tokens -- tk = RDoc::RubyToken::Token.new nil, 1, 1 -- tk.set_text body -+ begin -+ RDoc::const_get "RubyToken" -+ tk = RDoc::RubyToken::Token.new nil, 1, 1 -+ tk.set_text body -+ meth_obj.offset = offset -+ rescue NameError -+ # rdoc 2.5 -+ tk = { :line_no => 1, :char_no => 1, :text => body } -+ end - meth_obj.add_token tk - meth_obj.comment = strip_stars comment -- meth_obj.offset = offset - meth_obj.line = file_content[0, offset].count("\n") + 1 - - body -@@ -381,11 +387,17 @@ class RDoc::Parser::SWIG < RDoc::Parser - find_modifiers comment, meth_obj - - meth_obj.start_collecting_tokens -- tk = RDoc::RubyToken::Token.new nil, 1, 1 -- tk.set_text body -+ begin -+ RDoc::const_get "RubyToken" -+ tk = RDoc::RubyToken::Token.new nil, 1, 1 -+ tk.set_text body -+ meth_obj.offset = offset -+ rescue NameError -+ # rdoc 2.5 -+ tk = { :line_no => 1, :char_no => 1, :text => body } -+ end - meth_obj.add_token tk - meth_obj.comment = strip_stars(comment) + meth_obj.comment.to_s -- meth_obj.offset = offset - meth_obj.line = file_content[0, offset].count("\n") + 1 - - body --- -2.15.1 - diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 82c333c..1be385d 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-client-transport.c 2017-09-12 12:56:51.720463095 +0200 +diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c +--- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2017-11-28 09:32:15.000000000 +0100 ++++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-01-23 13:14:59.357153453 +0100 @@ -241,12 +241,20 @@ write_handler( void *ptr, size_t size, s static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) { @@ -23,53 +23,23 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/lib/wsman-curl-c if ( X509_digest(cert, tempDigest, tempFingerprint, &tempFingerprintLen ) <= 0) return 0; if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/compat_unix.h 2017-09-12 12:56:51.720463095 +0200 -@@ -27,7 +27,6 @@ +diff -up openwsman-2.6.5/src/server/shttpd/compat_unix.h.orig openwsman-2.6.5/src/server/shttpd/compat_unix.h +--- openwsman-2.6.5/src/server/shttpd/compat_unix.h.orig 2017-11-28 09:32:15.000000000 +0100 ++++ openwsman-2.6.5/src/server/shttpd/compat_unix.h 2018-01-23 13:14:59.357153453 +0100 +@@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ +-#ifndef SSL_LIB -#define SSL_LIB "libssl.so" +-#endif +- #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h.orig 2017-09-12 12:56:51.720463095 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/config.h 2017-09-12 12:56:51.720463095 +0200 -@@ -0,0 +1,29 @@ -+/* -+ * Copyright (c) 2004-2005 Sergey Lyubka -+ * All rights reserved -+ * -+ * "THE BEER-WARE LICENSE" (Revision 42): -+ * Sergey Lyubka wrote this file. As long as you retain this notice you -+ * can do whatever you want with this stuff. If we meet some day, and you think -+ * this stuff is worth it, you can buy me a beer in return. -+ */ -+ -+#ifndef CONFIG_HEADER_DEFINED -+#define CONFIG_HEADER_DEFINED -+ -+#define SHTTPD_VERSION "1.42" /* Version */ -+#define CONFIG_FILE "shttpd.conf" /* Configuration file */ -+#define HTPASSWD ".htpasswd" /* Passwords file name */ -+#define URI_MAX 16384 /* Default max request size */ -+#define LISTENING_PORTS "80" /* Default listening ports */ -+#define INDEX_FILES "index.html,index.htm,index.php,index.cgi" -+#define CGI_EXT "cgi,pl,php" /* Default CGI extensions */ -+#define SSI_EXT "shtml,shtm" /* Default SSI extensions */ -+#define REALM "mydomain.com" /* Default authentication realm */ -+#define DELIM_CHARS "," /* Separators for lists */ -+#define EXPIRE_TIME 3600 /* Expiration time, seconds */ -+#define ENV_MAX 4096 /* Size of environment block */ -+#define CGI_ENV_VARS 64 /* Maximum vars passed to CGI */ -+#define SERVICE_NAME "SHTTPD " VERSION /* NT service name */ -+ -+#endif /* CONFIG_HEADER_DEFINED */ -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io_ssl.c 2017-09-12 12:56:51.720463095 +0200 +diff -up openwsman-2.6.5/src/server/shttpd/io_ssl.c.orig openwsman-2.6.5/src/server/shttpd/io_ssl.c +--- openwsman-2.6.5/src/server/shttpd/io_ssl.c.orig 2017-11-28 09:32:15.000000000 +0100 ++++ openwsman-2.6.5/src/server/shttpd/io_ssl.c 2018-01-23 13:14:59.357153453 +0100 @@ -11,23 +11,6 @@ #include "defs.h" @@ -94,12 +64,12 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/io void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/shttpd.c 2017-09-12 12:58:20.132254340 +0200 -@@ -1474,20 +1474,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch - char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); +diff -up openwsman-2.6.5/src/server/shttpd/shttpd.c.orig openwsman-2.6.5/src/server/shttpd/shttpd.c +--- openwsman-2.6.5/src/server/shttpd/shttpd.c.orig 2017-11-28 09:32:15.000000000 +0100 ++++ openwsman-2.6.5/src/server/shttpd/shttpd.c 2018-01-23 13:16:13.738228773 +0100 +@@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; + EC_KEY* key; - /* Load SSL library dynamically */ - if ((lib = dlopen(SSL_LIB, RTLD_LAZY)) == NULL) { @@ -124,7 +94,7 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/sh if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -@@ -1523,7 +1517,11 @@ set_ssl(struct shttpd_ctx *ctx, const ch +@@ -1532,7 +1526,11 @@ set_ssl(struct shttpd_ctx *ctx, const ch if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { //_shttpd_elog(E_LOG, NULL, "SSL: disable %s protocol", protocols[idx].name); debug("SSL: disable %s protocol", protocols[idx].name); @@ -136,9 +106,9 @@ diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/sh break; } } -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/shttpd/ssl.h 2017-09-12 12:56:51.721463093 +0200 +diff -up openwsman-2.6.5/src/server/shttpd/ssl.h.orig openwsman-2.6.5/src/server/shttpd/ssl.h +--- openwsman-2.6.5/src/server/shttpd/ssl.h.orig 2017-11-28 09:32:15.000000000 +0100 ++++ openwsman-2.6.5/src/server/shttpd/ssl.h 2018-01-23 13:14:59.358153454 +0100 @@ -12,50 +12,4 @@ #include diff --git a/openwsman-2.6.2-python3.patch b/openwsman-2.6.2-python3.patch deleted file mode 100644 index 3dcf3a0..0000000 --- a/openwsman-2.6.2-python3.patch +++ /dev/null @@ -1,179 +0,0 @@ -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/CMakeLists.txt 2017-01-16 14:08:53.201529586 +0100 -@@ -10,6 +10,7 @@ include_directories(${CMAKE_BINARY_DIR}) - - IF( BUILD_PYTHON ) - add_subdirectory(python) -+add_subdirectory(python3) - ENDIF( BUILD_PYTHON ) - - IF( BUILD_RUBY ) -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt.orig 2017-01-16 14:08:09.000000000 +0100 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python3/CMakeLists.txt 2017-01-16 14:10:48.945480021 +0100 -@@ -12,11 +12,28 @@ enable_testing() - - add_subdirectory(tests) - --EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON_LIB_DIR) --STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") -+MESSAGE(STATUS "Python3 build:") -+unset(Python_ADDITIONAL_VERSIONS) -+set(Python_ADDITIONAL_VERSIONS 3.5) -+FIND_PACKAGE(PythonLibs) -+IF (PYTHON_LIBRARY) -+ FIND_PACKAGE(PythonInterp REQUIRED) -+ #MESSAGE(STATUS "Found PythonLibs...") -+ FIND_PACKAGE(PythonLinkLibs) -+ #IF (PYTHON_LINK_LIBS) -+ # MESSAGE(STATUS "Building Python...") -+ #ENDIF (PYTHON_LINK_LIBS) -+ENDIF (PYTHON_LIBRARY) -+ -+set(PYTHON3_EXECUTABLE "${PYTHON_EXECUTABLE}") -+set(PYTHON3_INCLUDE_DIRS "${PYTHON_INCLUDE_DIRS}") -+set({PYTHON3_INCLUDE_PATH "${PYTHON_INCLUDE_PATH}") - --MESSAGE(STATUS "Python executable: ${PYTHON_EXECUTABLE}") --MESSAGE(STATUS "Python lib dir: ${PYTHON_LIB_DIR}") -+EXECUTE_PROCESS(COMMAND ${PYTHON3_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON3_LIB_DIR) -+STRING(REPLACE "\n" "" PYTHON3_LIB_DIR "${PYTHON3_LIB_DIR}") -+ -+MESSAGE(STATUS "Python executable: ${PYTHON3_EXECUTABLE}") -+MESSAGE(STATUS "Python lib dir: ${PYTHON3_LIB_DIR}") - - SET( SWIG_OUTPUT "${CMAKE_CURRENT_BINARY_DIR}/openwsman_wrap.c" ) - -@@ -36,14 +53,14 @@ SET(pywsman_SRCS ${SWIG_OUTPUT} ${CMAKE_ - ADD_LIBRARY( pywsman SHARED ${pywsman_SRCS} ) - SET_TARGET_PROPERTIES( pywsman PROPERTIES PREFIX "_" ) - --INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_DIRS} ) -+INCLUDE_DIRECTORIES( ${PYTHON3_INCLUDE_DIRS} ) - # RHEL5 needs this: --INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_PATH} ) -+INCLUDE_DIRECTORIES( ${PYTHON3_INCLUDE_PATH} ) - INCLUDE_DIRECTORIES( ${CMAKE_CURRENT_BINARY_DIR} ) - INCLUDE_DIRECTORIES( ${CMAKE_SOURCE_DIR} ${CMAKE_SOURCE_DIR}/bindings ${CMAKE_SOURCE_DIR}/include ) - - TARGET_LINK_LIBRARIES( pywsman wsman ) - TARGET_LINK_LIBRARIES( pywsman wsman_client ) - --INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON_LIB_DIR}) --INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) -+INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON3_LIB_DIR}) -+INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON3_LIB_DIR} ) -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/bindings/python/CMakeLists.txt 2017-01-16 14:12:51.954427345 +0100 -@@ -12,11 +12,52 @@ enable_testing() - - add_subdirectory(tests) - --EXECUTE_PROCESS(COMMAND ${PYTHON_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))" OUTPUT_VARIABLE PYTHON_LIB_DIR) --STRING(REPLACE "\n" "" PYTHON_LIB_DIR "${PYTHON_LIB_DIR}") -+MESSAGE(STATUS "Python2 build:") -+set(Python_ADDITIONAL_VERSIONS 2.7) -+FIND_PACKAGE(PythonLibs) -+IF (PYTHON_LIBRARY) -+ FIND_PACKAGE(PythonInterp REQUIRED) -+ #MESSAGE(STATUS "Found PythonLibs...") -+ FIND_PACKAGE(PythonLinkLibs) -+ #IF (PYTHON_LINK_LIBS) -+ # MESSAGE(STATUS "Building Python...") -+ #ENDIF (PYTHON_LINK_LIBS) -+ENDIF (PYTHON_LIBRARY) -+ -+set(PYTHON2_EXECUTABLE "${PYTHON_EXECUTABLE}") -+set(PYTHON2_INCLUDE_DIRS "${PYTHON_INCLUDE_DIRS}") -+set(PYTHON2_INCLUDE_PATH "${PYTHON_INCLUDE_PATH}") -+ -+# clear FIND_PACKAGE(PythonLibs) side effects -+unset(PYTHONLIBS_FOUND) -+unset(PYTHON_LIBRARIES) -+unset(PYTHON_INCLUDE_PATH) -+unset(PYTHON_INCLUDE_DIRS) -+unset(PYTHON_DEBUG_LIBRARIES) -+unset(PYTHONLIBS_VERSION_STRING) -+unset(PYTHON_DEBUG_LIBRARY CACHE) -+unset(PYTHON_LIBRARY) -+unset(PYTHON_LIBRARY_DEBUG) -+unset(PYTHON_LIBRARY_RELEASE) -+unset(PYTHON_LIBRARY CACHE) -+unset(PYTHON_LIBRARY_DEBUG CACHE) -+unset(PYTHON_LIBRARY_RELEASE CACHE) -+unset(PYTHON_INCLUDE_DIR CACHE) -+unset(PYTHON_INCLUDE_DIR2 CACHE) -+ -+# clear FIND_PACKAGE(PythonInterp) side effects -+unset(PYTHONINTERP_FOUND) -+unset(PYTHON_EXECUTABLE CACHE) -+unset(PYTHON_VERSION_STRING) -+unset(PYTHON_VERSION_MAJOR) -+unset(PYTHON_VERSION_MINOR) -+unset(PYTHON_VERSION_PATCH) - --MESSAGE(STATUS "Python executable: ${PYTHON_EXECUTABLE}") --MESSAGE(STATUS "Python lib dir: ${PYTHON_LIB_DIR}") -+EXECUTE_PROCESS(COMMAND ${PYTHON2_EXECUTABLE} -c "from distutils.sysconfig import get_python_lib; print get_python_lib(1)" OUTPUT_VARIABLE PYTHON2_LIB_DIR) -+STRING(REPLACE "\n" "" PYTHON2_LIB_DIR "${PYTHON2_LIB_DIR}") -+ -+MESSAGE(STATUS "Python executable: ${PYTHON2_EXECUTABLE}") -+MESSAGE(STATUS "Python lib dir: ${PYTHON2_LIB_DIR}") - - SET( SWIG_OUTPUT "${CMAKE_CURRENT_BINARY_DIR}/openwsman_wrap.c" ) - -@@ -36,14 +77,14 @@ SET(pywsman_SRCS ${SWIG_OUTPUT} ${CMAKE_ - ADD_LIBRARY( pywsman SHARED ${pywsman_SRCS} ) - SET_TARGET_PROPERTIES( pywsman PROPERTIES PREFIX "_" ) - --INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_DIRS} ) -+INCLUDE_DIRECTORIES( ${PYTHON2_INCLUDE_DIRS} ) - # RHEL5 needs this: --INCLUDE_DIRECTORIES( ${PYTHON_INCLUDE_PATH} ) -+INCLUDE_DIRECTORIES( ${PYTHON2_INCLUDE_PATH} ) - INCLUDE_DIRECTORIES( ${CMAKE_CURRENT_BINARY_DIR} ) - INCLUDE_DIRECTORIES( ${CMAKE_SOURCE_DIR} ${CMAKE_SOURCE_DIR}/bindings ${CMAKE_SOURCE_DIR}/include ) - - TARGET_LINK_LIBRARIES( pywsman wsman ) - TARGET_LINK_LIBRARIES( pywsman wsman_client ) - --INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON_LIB_DIR}) --INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON_LIB_DIR} ) -+INSTALL(TARGETS pywsman LIBRARY DESTINATION ${PYTHON2_LIB_DIR}) -+INSTALL(FILES ${CMAKE_CURRENT_BINARY_DIR}/pywsman.py DESTINATION ${PYTHON2_LIB_DIR} ) -diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt ---- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt.orig 2016-07-27 16:03:55.000000000 +0200 -+++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/CMakeLists.txt 2017-01-16 14:13:37.300407926 +0100 -@@ -175,30 +175,6 @@ MESSAGE(STATUS "Building Ruby bindings" - ENDIF(NOT RUBY_INCLUDE_PATH ) - ENDIF( BUILD_RUBY ) - --IF( BUILD_PYTHON ) -- MESSAGE(STATUS "Building Python bindings" ) -- FIND_PACKAGE(PythonLibs 2.6 REQUIRED) -- IF (PYTHON_LIBRARY) -- FIND_PACKAGE(PythonInterp 2.6 REQUIRED) -- MESSAGE(STATUS "Found PythonLibs...") -- FIND_PACKAGE(PythonLinkLibs) -- IF (PYTHON_LINK_LIBS) -- MESSAGE(STATUS "Building Python...") -- ENDIF (PYTHON_LINK_LIBS) -- ENDIF (PYTHON_LIBRARY) -- IF(NOT PYTHON_INCLUDE_DIRS ) -- # fallback for older versions of cmake -- SET(PYTHON_INCLUDE_DIRS PYTHON_INCLUDE_PATH) -- ENDIF(NOT PYTHON_INCLUDE_DIRS ) -- IF(NOT PYTHON_INCLUDE_DIRS ) -- IF(BUILD_PYTHON_EXPLICIT) -- NO_HEADERS_WARNING_EXPL(BUILD_PYTHON Python) -- ELSE(BUILD_PYTHON_EXPLICIT) -- NO_HEADERS_WARNING(BUILD_PYTHON Python) -- ENDIF(BUILD_PYTHON_EXPLICIT) -- ENDIF(NOT PYTHON_INCLUDE_DIRS ) --ENDIF( BUILD_PYTHON ) -- - IF( BUILD_PERL ) - INCLUDE(FindPerl) - IF(PERL_EXECUTABLE) diff --git a/openwsman-2.6.5-http-status-line.patch b/openwsman-2.6.5-http-status-line.patch new file mode 100644 index 0000000..f571508 --- /dev/null +++ b/openwsman-2.6.5-http-status-line.patch @@ -0,0 +1,39 @@ +diff -up openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c.orig openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c +--- openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c.orig 2016-07-27 16:03:55.000000000 +0200 ++++ openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/src/server/wsmand-listener.c 2018-01-22 13:05:04.478923300 +0100 +@@ -344,6 +344,35 @@ DONE: + if (fault_reason == NULL) { + // this is a way to segfault, investigate + //fault_reason = shttpd_reason_phrase(status); ++ // ugly workaround follows... ++ switch (status) { ++ case 200: ++ fault_reason = "OK"; ++ break; ++ case 400: ++ fault_reason = "Bad request"; ++ break; ++ case 401: ++ fault_reason = "Unauthorized"; ++ break; ++ case 403: ++ fault_reason = "Forbidden"; ++ break; ++ case 404: ++ fault_reason = "Not found"; ++ break; ++ case 500: ++ fault_reason = "Internal Error"; ++ break; ++ case 501: ++ fault_reason = "Not implemented"; ++ break; ++ case 415: ++ fault_reason = "Unsupported Media Type"; ++ break; ++ default: ++ fault_reason = ""; ++ } + } + debug("Response status=%d (%s)", status, fault_reason); + diff --git a/openwsman.spec b/openwsman.spec index e8daac1..9fde24b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,22 +1,14 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} -%global commit 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b -%global shortcommit %(c=%{commit}; echo ${c:0:7}) - Name: openwsman -Version: 2.6.3 -Release: 11.git%{shortcommit}%{?dist} +Version: 2.6.5 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD URL: http://www.openwsman.org/ -# The source for this package was pulled from upstream's vcs. Use the -# following commands to generate the tarball: -# git clone https://github.com/Openwsman/openwsman.git; cd openwsman -# git archive --format tar --prefix openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b/ \ -# 4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b | gzip > openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz -Source0: %{name}-%{commit}.tar.gz +Source0: https://github.com/Openwsman/openwsman/archive/v%{version}.tar.gz # help2man generated manpage for openwsmand binary Source1: openwsmand.8.gz # service file for systemd @@ -25,14 +17,11 @@ Source2: openwsmand.service Source3: owsmantestcert.sh Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch -Patch3: openwsman-2.6.2-python3.patch -Patch4: openwsman-2.6.2-openssl-1.1-fix.patch -# Patch5, 6 are github backport fixes for ruby 2.5 -Patch5: openwsman-2.6.2-0006-Find-Ruby-2.5.patch -Patch6: openwsman-2.6.2-0008-Make-ruby_parser_swig-Ruby2.5-aware.patch +Patch3: openwsman-2.6.2-openssl-1.1-fix.patch +Patch4: openwsman-2.6.5-http-status-line.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python3 python3-devel python2 python2-devel ruby ruby-devel rubygems-devel perl-interpreter +BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units @@ -84,25 +73,12 @@ Requires: libwsman1 = %{version}-%{release} %description server Openwsman Server and service libraries. -%package -n python2-openwsman -%{?python_provide:%python_provide python2-openwsman} -# Remove before F30 -Provides: %{name}-python = %{version}-%{release} -Provides: %{name}-python%{?_isa} = %{version}-%{release} -Obsoletes: %{name}-python < %{version}-%{release} -License: BSD -Summary: Python bindings for openwsman client API -Requires: python2 -Requires: libwsman1 = %{version}-%{release} - -%description -n python2-openwsman -This package provides Python2 bindings to access the openwsman client API. - %package python3 License: BSD Summary: Python bindings for openwsman client API Requires: python3 Requires: libwsman1 = %{version}-%{release} +%{?python_provide:%python_provide python3-openwsman} %description python3 This package provides Python3 bindings to access the openwsman client API. @@ -142,19 +118,12 @@ This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. %prep -%setup -q -n %{name}-%{commit} - -# support python3 -pushd bindings -cp -r python python3 -popd +%setup -q %patch1 -p1 -b .pamsetup %patch2 -p1 -b .ruby-binding-build -%patch3 -p1 -b .python3 -%patch4 -p1 -b .openssl-1.1-fix -%patch5 -p1 -b .ruby25_1 -%patch6 -p1 -b .ruby25_2 +%patch3 -p1 -b .openssl-1.1-fix +%patch4 -p1 -b .http-status-line %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -182,9 +151,9 @@ make # Make the freshly build openwsman libraries available to build the gem's # binary extension. -export LIBRARY_PATH=%{_builddir}/%{name}-%{commit}/build/src/lib -export CPATH=%{_builddir}/%{name}-%{commit}/include/ -export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{commit}/build/src/lib/ +export LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib +export CPATH=%{_builddir}/%{name}-%{version}/include/ +export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem @@ -257,13 +226,6 @@ rm -f /var/log/wsmand.log %{_libdir}/pkgconfig/* %{_libdir}/*.so -%files -n python2-openwsman -%doc AUTHORS COPYING ChangeLog README.md -%{python2_sitearch}/*.so -%{python2_sitearch}/*.py -%{python2_sitearch}/*.pyc -%{python2_sitearch}/*.pyo - %files python3 %doc AUTHORS COPYING ChangeLog README.md %{python3_sitearch}/*.so @@ -317,6 +279,11 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jan 23 2018 Vitezslav Crhonek - 2.6.5-1 +- Update to openwsman-2.6.5 +- Simplify python binding build and drop python2 subpackage +- Fix malformed HTTP 200 status line + * Sat Jan 20 2018 Björn Esser - 2.6.3-11.git4391e5c - Rebuilt for switch to libxcrypt diff --git a/sources b/sources index 7e874d1..b9ddf41 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (openwsman-4391e5c68d99c6239e1672d1c8a5a16d7d8c4c2b.tar.gz) = 9126053fb65457662e7a6275afe16b6fa6aaf978c2909aff97bca3d7dd3c8c1e7378e86ced97de42f86dd1060f2c7246ac3b1ecc4bf3d853606cc9d2d60d8eed +SHA512 (v2.6.5.tar.gz) = dff103d50ddf974aa90db5be74761dd83944e64e1bab65161ee2941949c46af57c5d53d011ccbf1ef21002c825f4a2be8d6431c83610dd930b5ac4352fd0762b From 0408a863ebd0af05af9e454a93933d74002976f8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 8 Feb 2018 17:53:47 +0000 Subject: [PATCH 025/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 9fde24b..b46e1b3 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -279,6 +279,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu Feb 08 2018 Fedora Release Engineering - 2.6.5-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + * Tue Jan 23 2018 Vitezslav Crhonek - 2.6.5-1 - Update to openwsman-2.6.5 - Simplify python binding build and drop python2 subpackage From bdce3e3008c4b77f1073d469761911a1e9d5f689 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 21 Feb 2018 11:04:42 +0100 Subject: [PATCH 026/120] Fix wrong SSL_CTX_set_cipher_list() retval check --- ...sman-2.6.5-fix-set-cipher-list-retval-check.patch | 12 ++++++++++++ openwsman.spec | 6 +++++- 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.6.5-fix-set-cipher-list-retval-check.patch diff --git a/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch b/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch new file mode 100644 index 0000000..dc3e52c --- /dev/null +++ b/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.6.5/src/server/shttpd/shttpd.c.orig openwsman-2.6.5/src/server/shttpd/shttpd.c +--- openwsman-2.6.5/src/server/shttpd/shttpd.c.orig 2018-02-21 10:53:24.964163710 +0100 ++++ openwsman-2.6.5/src/server/shttpd/shttpd.c 2018-02-21 10:53:31.854162875 +0100 +@@ -1541,7 +1541,7 @@ set_ssl(struct shttpd_ctx *ctx, const ch + + if (ssl_cipher_list) { + int rc = SSL_CTX_set_cipher_list(CTX, ssl_cipher_list); +- if (rc != 0) { ++ if (rc != 1) { + _shttpd_elog(E_LOG, NULL, "Failed to set SSL cipher list \"%s\"", ssl_cipher_list); + } + } diff --git a/openwsman.spec b/openwsman.spec index b46e1b3..d062f11 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -19,6 +19,7 @@ Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch +Patch5: openwsman-2.6.5-fix-set-cipher-list-retval-check.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -279,6 +280,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Feb 21 2018 Vitezslav Crhonek - 2.6.5-3 +- Fix wrong SSL_CTX_set_cipher_list() retval check + * Thu Feb 08 2018 Fedora Release Engineering - 2.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild From 0b7d9736b5c80986ccb781bf5272bb42bb6fbf1e Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 22 Feb 2018 09:59:17 +0100 Subject: [PATCH 027/120] Add BuildRequires gcc and gcc-c++ --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d062f11..0816859 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -26,6 +26,7 @@ BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpr BuildRequires: perl-devel perl-generators pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units +BuildRequires: gcc gcc-c++ %description Openwsman is a project intended to provide an open-source @@ -125,6 +126,7 @@ You can use it to send shell commands to a remote Windows hosts. %patch2 -p1 -b .ruby-binding-build %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line +%patch5 -p1 -b .fix-set-cipher-list-retval-check %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -280,8 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog -* Wed Feb 21 2018 Vitezslav Crhonek - 2.6.5-3 +* Thu Feb 22 2018 Vitezslav Crhonek - 2.6.5-3 - Fix wrong SSL_CTX_set_cipher_list() retval check +- Add BuildRequires gcc and gcc-c++ * Thu Feb 08 2018 Fedora Release Engineering - 2.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild From 07795a5453feee1dadccf6996cc34541b7ecf217 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 28 Feb 2018 10:14:30 +0100 Subject: [PATCH 028/120] Explicitly disable build of java binding --- openwsman.spec | 2 ++ 1 file changed, 2 insertions(+) diff --git a/openwsman.spec b/openwsman.spec index 0816859..01d2810 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -148,6 +148,7 @@ cmake \ -DCMAKE_SKIP_RPATH=1 \ -DPACKAGE_ARCHITECTURE=`uname -m` \ -DLIB=%{_lib} \ + -DBUILD_JAVA=no \ .. make @@ -285,6 +286,7 @@ rm -f /var/log/wsmand.log * Thu Feb 22 2018 Vitezslav Crhonek - 2.6.5-3 - Fix wrong SSL_CTX_set_cipher_list() retval check - Add BuildRequires gcc and gcc-c++ +- Explicitly disable build of java bindings (build fails if java-devel is installed) * Thu Feb 08 2018 Fedora Release Engineering - 2.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild From 3f1e511d6fffab88152e506ebe54dfb8fa9fd675 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Tue, 19 Jun 2018 10:49:07 +0200 Subject: [PATCH 029/120] Rebuilt for Python 3.7 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 01d2810..97af3aa 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jun 19 2018 Miro Hrončok - 2.6.5-4 +- Rebuilt for Python 3.7 + * Thu Feb 22 2018 Vitezslav Crhonek - 2.6.5-3 - Fix wrong SSL_CTX_set_cipher_list() retval check - Add BuildRequires gcc and gcc-c++ From 75bde100a0ac77e1547d9f88a909c8281ac4151d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Tue, 19 Jun 2018 11:44:14 +0200 Subject: [PATCH 030/120] Rebuilt for Python 3.7 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 97af3aa..e526828 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jun 19 2018 Miro Hrončok - 2.6.5-5 +- Rebuilt for Python 3.7 + * Tue Jun 19 2018 Miro Hrončok - 2.6.5-4 - Rebuilt for Python 3.7 From 6a258f7a467851bee6609957d2ab33e8717347d0 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Thu, 28 Jun 2018 03:27:23 +0200 Subject: [PATCH 031/120] Perl 5.28 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index e526828..3897adf 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu Jun 28 2018 Jitka Plesnikova - 2.6.5-6 +- Perl 5.28 rebuild + * Tue Jun 19 2018 Miro Hrončok - 2.6.5-5 - Rebuilt for Python 3.7 From f6939e4ecc747d5129a49de11ef782c70d59b7de Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Tue, 3 Jul 2018 12:36:10 +0200 Subject: [PATCH 032/120] Perl 5.28 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 3897adf..db7a740 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jul 03 2018 Petr Pisar - 2.6.5-7 +- Perl 5.28 rebuild + * Thu Jun 28 2018 Jitka Plesnikova - 2.6.5-6 - Perl 5.28 rebuild From d77320bcc670f1ae45a18fd7ff368c4202f1a3c0 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 13 Jul 2018 15:14:33 +0000 Subject: [PATCH 033/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index db7a740..42f55d7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri Jul 13 2018 Fedora Release Engineering - 2.6.5-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + * Tue Jul 03 2018 Petr Pisar - 2.6.5-7 - Perl 5.28 rebuild From 46a9d78c6d7afefd88de447a9d81693778332e97 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 1 Oct 2018 11:53:20 +0200 Subject: [PATCH 034/120] Require the Python interpreter directly instead of using the package name --- openwsman.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 42f55d7..1d75065 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -78,7 +78,7 @@ Openwsman Server and service libraries. %package python3 License: BSD Summary: Python bindings for openwsman client API -Requires: python3 +Requires: %{__python3} Requires: libwsman1 = %{version}-%{release} %{?python_provide:%python_provide python3-openwsman} @@ -283,6 +283,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Oct 01 2018 Vitezslav Crhonek - 2.6.5-9 +- Require the Python interpreter directly instead of using the package name + * Fri Jul 13 2018 Fedora Release Engineering - 2.6.5-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild From 8e7d5b2b9d2023e892bd81c59e37d168b95ff794 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 14 Nov 2018 14:35:32 +0100 Subject: [PATCH 035/120] Reflect changes in libcurl error codes --- ...man-2.6.5-libcurl-error-codes-update.patch | 27 +++++++++++++++++++ openwsman.spec | 8 +++++- 2 files changed, 34 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.6.5-libcurl-error-codes-update.patch diff --git a/openwsman-2.6.5-libcurl-error-codes-update.patch b/openwsman-2.6.5-libcurl-error-codes-update.patch new file mode 100644 index 0000000..82ee51f --- /dev/null +++ b/openwsman-2.6.5-libcurl-error-codes-update.patch @@ -0,0 +1,27 @@ +diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c +--- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2018-11-14 13:53:27.442138557 +0100 ++++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-11-14 14:11:28.508714204 +0100 +@@ -186,16 +186,23 @@ convert_to_last_error(CURLcode r) + return WS_LASTERR_SSL_CONNECT_ERROR; + case CURLE_BAD_FUNCTION_ARGUMENT: + return WS_LASTERR_CURL_BAD_FUNCTION_ARG; ++#if LIBCURL_VERSION_NUM < 0x073E00 + case CURLE_SSL_PEER_CERTIFICATE: + return WS_LASTERR_SSL_PEER_CERTIFICATE; ++#endif + case CURLE_SSL_ENGINE_NOTFOUND: + return WS_LASTERR_SSL_ENGINE_NOTFOUND; + case CURLE_SSL_ENGINE_SETFAILED: + return WS_LASTERR_SSL_ENGINE_SETFAILED; + case CURLE_SSL_CERTPROBLEM: + return WS_LASTERR_SSL_CERTPROBLEM; ++#if LIBCURL_VERSION_NUM < 0x073E00 + case CURLE_SSL_CACERT: + return WS_LASTERR_SSL_CACERT; ++#else ++ case CURLE_PEER_FAILED_VERIFICATION: ++ return WS_LASTERR_SSL_PEER_CERTIFICATE; ++#endif + #if LIBCURL_VERSION_NUM > 0x70C01 + case CURLE_SSL_ENGINE_INITFAILED: + return WS_LASTERR_SSL_ENGINE_INITFAILED; diff --git a/openwsman.spec b/openwsman.spec index 1d75065..8603375 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.5 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -20,6 +20,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.5-fix-set-cipher-list-retval-check.patch +Patch6: openwsman-2.6.5-libcurl-error-codes-update.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -127,6 +128,7 @@ You can use it to send shell commands to a remote Windows hosts. %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line %patch5 -p1 -b .fix-set-cipher-list-retval-check +%patch6 -p1 -b .libcurl-error-codes-update %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -283,6 +285,10 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Nov 14 2018 Vitezslav Crhonek - 2.6.5-10 +- Reflect changes in libcurl error codes + Resolves: #1649393 + * Mon Oct 01 2018 Vitezslav Crhonek - 2.6.5-9 - Require the Python interpreter directly instead of using the package name From 8be31c757a1139709ee2f20e12a4833cada011c3 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 22 Nov 2018 13:37:08 +0100 Subject: [PATCH 036/120] Update to openwsman-2.6.8 --- .gitignore | 2 +- openwsman-2.4.0-pamsetup.patch | 23 +++---- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 69 +++++-------------- ...6.5-fix-set-cipher-list-retval-check.patch | 12 ---- openwsman.spec | 14 ++-- sources | 1 + 7 files changed, 38 insertions(+), 85 deletions(-) delete mode 100644 openwsman-2.6.5-fix-set-cipher-list-retval-check.patch diff --git a/.gitignore b/.gitignore index 77b5874..490fdf3 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.6.5.tar.gz +/v2.6.8.tar.gz diff --git a/openwsman-2.4.0-pamsetup.patch b/openwsman-2.4.0-pamsetup.patch index 021ca88..466b5df 100644 --- a/openwsman-2.4.0-pamsetup.patch +++ b/openwsman-2.4.0-pamsetup.patch @@ -1,16 +1,13 @@ -diff -up openwsman-2.6.1/etc/pam/openwsman.pamsetup openwsman-2.6.1/etc/pam/openwsman ---- openwsman-2.6.1/etc/pam/openwsman.pamsetup 2015-08-27 15:46:46.000000000 +0200 -+++ openwsman-2.6.1/etc/pam/openwsman 2015-08-31 16:08:28.166913889 +0200 -@@ -1,7 +1,7 @@ - #%PAM-1.0 --auth required pam_unix2.so nullok -+auth required pam_unix.so nullok +diff -up openwsman-2.6.8/etc/pam/openwsman.orig openwsman-2.6.8/etc/pam/openwsman +--- openwsman-2.6.8/etc/pam/openwsman.orig 2018-11-21 13:51:52.776325243 +0100 ++++ openwsman-2.6.8/etc/pam/openwsman 2018-11-21 13:54:17.066351134 +0100 +@@ -2,6 +2,6 @@ + auth required pam_unix.so nullok auth required pam_nologin.so --account required pam_unix2.so --password required pam_pwcheck.so nullok --password required pam_unix2.so nullok use_first_pass use_authtok --session required pam_unix2.so none -+account required pam_unix.so + account required pam_unix.so +-password required pam_cracklib.so nullok +-password required pam_unix.so nullok use_first_pass use_authtok nis shadow +-session required pam_unix.so none +password required pam_pwquality.so -+password required pam_unix.so nullok use_first_pass use_authtok ++password required pam_unix.so nullok use_first_pass use_authtok +session required pam_unix.so diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 7f46996..1a4e76e 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.5/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.8/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 1be385d..98f6bc2 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,31 +1,6 @@ -diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c ---- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2017-11-28 09:32:15.000000000 +0100 -+++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-01-23 13:14:59.357153453 +0100 -@@ -241,12 +241,20 @@ write_handler( void *ptr, size_t size, s - static int ssl_certificate_thumbprint_verify_callback(X509_STORE_CTX *ctx, void *arg) - { - unsigned char *thumbprint = (unsigned char *)arg; -- X509 *cert = ctx->cert; - EVP_MD *tempDigest; - - unsigned char tempFingerprint[EVP_MAX_MD_SIZE]; - unsigned int tempFingerprintLen; - tempDigest = (EVP_MD*)EVP_sha1( ); -+ -+#if OPENSSL_VERSION_NUMBER >= 0x10100000L -+ X509 *cert = X509_STORE_CTX_get_current_cert(ctx); -+#else -+ X509 *cert = ctx->cert; -+#endif -+ if(!cert) -+ return 0; -+ - if ( X509_digest(cert, tempDigest, tempFingerprint, &tempFingerprintLen ) <= 0) - return 0; - if(!memcmp(tempFingerprint, thumbprint, tempFingerprintLen)) -diff -up openwsman-2.6.5/src/server/shttpd/compat_unix.h.orig openwsman-2.6.5/src/server/shttpd/compat_unix.h ---- openwsman-2.6.5/src/server/shttpd/compat_unix.h.orig 2017-11-28 09:32:15.000000000 +0100 -+++ openwsman-2.6.5/src/server/shttpd/compat_unix.h 2018-01-23 13:14:59.357153453 +0100 +diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/src/server/shttpd/compat_unix.h +--- openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/compat_unix.h 2018-11-22 13:30:10.756423510 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -37,9 +12,9 @@ diff -up openwsman-2.6.5/src/server/shttpd/compat_unix.h.orig openwsman-2.6.5/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.6.5/src/server/shttpd/io_ssl.c.orig openwsman-2.6.5/src/server/shttpd/io_ssl.c ---- openwsman-2.6.5/src/server/shttpd/io_ssl.c.orig 2017-11-28 09:32:15.000000000 +0100 -+++ openwsman-2.6.5/src/server/shttpd/io_ssl.c 2018-01-23 13:14:59.357153453 +0100 +diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/server/shttpd/io_ssl.c +--- openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/io_ssl.c 2018-11-22 13:30:10.757423510 +0100 @@ -11,23 +11,6 @@ #include "defs.h" @@ -64,9 +39,9 @@ diff -up openwsman-2.6.5/src/server/shttpd/io_ssl.c.orig openwsman-2.6.5/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.6.5/src/server/shttpd/shttpd.c.orig openwsman-2.6.5/src/server/shttpd/shttpd.c ---- openwsman-2.6.5/src/server/shttpd/shttpd.c.orig 2017-11-28 09:32:15.000000000 +0100 -+++ openwsman-2.6.5/src/server/shttpd/shttpd.c 2018-01-23 13:16:13.738228773 +0100 +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2018-11-22 13:30:41.314416695 +0100 @@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -94,22 +69,10 @@ diff -up openwsman-2.6.5/src/server/shttpd/shttpd.c.orig openwsman-2.6.5/src/ser if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -@@ -1532,7 +1526,11 @@ set_ssl(struct shttpd_ctx *ctx, const ch - if (strncasecmp(protocols[idx].name, ssl_disabled_protocols, blank_ptr-ssl_disabled_protocols) == 0) { - //_shttpd_elog(E_LOG, NULL, "SSL: disable %s protocol", protocols[idx].name); - debug("SSL: disable %s protocol", protocols[idx].name); -+#if OPENSSL_VERSION_NUMBER >= 0x10100000L -+ SSL_CTX_set_options(CTX, protocols[idx].opt); -+#else - SSL_CTX_ctrl(CTX, SSL_CTRL_OPTIONS, protocols[idx].opt, NULL); -+#endif - break; - } - } -diff -up openwsman-2.6.5/src/server/shttpd/ssl.h.orig openwsman-2.6.5/src/server/shttpd/ssl.h ---- openwsman-2.6.5/src/server/shttpd/ssl.h.orig 2017-11-28 09:32:15.000000000 +0100 -+++ openwsman-2.6.5/src/server/shttpd/ssl.h 2018-01-23 13:14:59.358153454 +0100 -@@ -12,50 +12,4 @@ +diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server/shttpd/ssl.h +--- openwsman-2.6.8/src/server/shttpd/ssl.h.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/shttpd/ssl.h 2018-11-22 13:30:10.757423510 +0100 +@@ -12,52 +12,4 @@ #include @@ -130,7 +93,7 @@ diff -up openwsman-2.6.5/src/server/shttpd/ssl.h.orig openwsman-2.6.5/src/server -#define SSL_ERROR_SYSCALL 5 -#define SSL_FILETYPE_PEM 1 - - #endif +-#endif - -/* - * Dynamically loaded SSL functionality @@ -153,9 +116,11 @@ diff -up openwsman-2.6.5/src/server/shttpd/ssl.h.orig openwsman-2.6.5/src/server -#define SSL_get_error(x,y)(* (int (*)(SSL *, int)) FUNC(5))((x), (y)) -#define SSL_set_fd(x,y) (* (int (*)(SSL *, int)) FUNC(6))((x), (y)) -#define SSL_new(x) (* (SSL * (*)(SSL_CTX *)) FUNC(7))(x) --#define SSL_CTX_new(x) (* (SSL_CTX * (*)(SSL_METHOD *)) FUNC(8))(x) +-#define SSL_CTX_new(x) (* (SSL_CTX * (*)(const SSL_METHOD *)) FUNC(8))(x) +-#if OPENSSL_VERSION_NUMBER < 0x10100000L -#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() -#define SSL_library_init() (* (int (*)(void)) FUNC(10))() + #endif -#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(11))((x), (y), (z)) -#define SSL_CTX_use_certificate_file(x,y,z) (* (int (*)(SSL_CTX *, \ diff --git a/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch b/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch deleted file mode 100644 index dc3e52c..0000000 --- a/openwsman-2.6.5-fix-set-cipher-list-retval-check.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.6.5/src/server/shttpd/shttpd.c.orig openwsman-2.6.5/src/server/shttpd/shttpd.c ---- openwsman-2.6.5/src/server/shttpd/shttpd.c.orig 2018-02-21 10:53:24.964163710 +0100 -+++ openwsman-2.6.5/src/server/shttpd/shttpd.c 2018-02-21 10:53:31.854162875 +0100 -@@ -1541,7 +1541,7 @@ set_ssl(struct shttpd_ctx *ctx, const ch - - if (ssl_cipher_list) { - int rc = SSL_CTX_set_cipher_list(CTX, ssl_cipher_list); -- if (rc != 0) { -+ if (rc != 1) { - _shttpd_elog(E_LOG, NULL, "Failed to set SSL cipher list \"%s\"", ssl_cipher_list); - } - } diff --git a/openwsman.spec b/openwsman.spec index 8603375..845166d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -2,8 +2,8 @@ %global gem_name %{name} Name: openwsman -Version: 2.6.5 -Release: 10%{?dist} +Version: 2.6.8 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -19,8 +19,7 @@ Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch -Patch5: openwsman-2.6.5-fix-set-cipher-list-retval-check.patch -Patch6: openwsman-2.6.5-libcurl-error-codes-update.patch +Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -127,8 +126,7 @@ You can use it to send shell commands to a remote Windows hosts. %patch2 -p1 -b .ruby-binding-build %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line -%patch5 -p1 -b .fix-set-cipher-list-retval-check -%patch6 -p1 -b .libcurl-error-codes-update +%patch5 -p1 -b .libcurl-error-codes-update %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -151,6 +149,7 @@ cmake \ -DPACKAGE_ARCHITECTURE=`uname -m` \ -DLIB=%{_lib} \ -DBUILD_JAVA=no \ + -DBUILD_PYTHON=no \ .. make @@ -285,6 +284,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu Nov 22 2018 Vitezslav Crhonek - 2.6.8-1 +- Update to openwsman-2.6.8 + * Wed Nov 14 2018 Vitezslav Crhonek - 2.6.5-10 - Reflect changes in libcurl error codes Resolves: #1649393 diff --git a/sources b/sources index b9ddf41..8128bd2 100644 --- a/sources +++ b/sources @@ -1,2 +1,3 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c SHA512 (v2.6.5.tar.gz) = dff103d50ddf974aa90db5be74761dd83944e64e1bab65161ee2941949c46af57c5d53d011ccbf1ef21002c825f4a2be8d6431c83610dd930b5ac4352fd0762b +SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 From 21ba3ec6d65a9c0b9655f2dc667a99f0a6ad7c58 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 26 Nov 2018 11:19:10 +0100 Subject: [PATCH 037/120] Update sources --- sources | 1 - 1 file changed, 1 deletion(-) diff --git a/sources b/sources index 8128bd2..80e25cc 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.6.5.tar.gz) = dff103d50ddf974aa90db5be74761dd83944e64e1bab65161ee2941949c46af57c5d53d011ccbf1ef21002c825f4a2be8d6431c83610dd930b5ac4352fd0762b SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 From 415906b5a98a462148586a4023574240fcdc687d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Mon, 14 Jan 2019 19:11:27 +0100 Subject: [PATCH 038/120] Rebuilt for libcrypt.so.2 (#1666033) --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 845166d..d22953f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -284,6 +284,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Jan 14 2019 Björn Esser - 2.6.8-2 +- Rebuilt for libcrypt.so.2 (#1666033) + * Thu Nov 22 2018 Vitezslav Crhonek - 2.6.8-1 - Update to openwsman-2.6.8 From e135327d2f38ce8f1839e6f04488c84fbaff9a2a Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Mon, 21 Jan 2019 22:35:19 +0900 Subject: [PATCH 039/120] F-30: rebuild against ruby26 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d22953f..9d3d031 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -284,6 +284,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Jan 21 2019 Mamoru TASAKA - 2.6.8-3 +- F-30: rebuild against ruby26 + * Mon Jan 14 2019 Björn Esser - 2.6.8-2 - Rebuilt for libcrypt.so.2 (#1666033) From 102fbea1ba451df9dcdbdd002e37de005068f47b Mon Sep 17 00:00:00 2001 From: Igor Gnatenko Date: Tue, 22 Jan 2019 18:40:36 +0100 Subject: [PATCH 040/120] Remove obsolete ldconfig scriptlets References: https://fedoraproject.org/wiki/Changes/RemoveObsoleteScriptlets Signed-off-by: Igor Gnatenko --- openwsman.spec | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 9d3d031..feaea5d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -199,12 +199,10 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ -%post -n libwsman1 -p /sbin/ldconfig - -%postun -n libwsman1 -p /sbin/ldconfig +%ldconfig_scriptlets -n libwsman1 %post server -/sbin/ldconfig +%{?ldconfig} %systemd_post openwsmand.service %preun server @@ -213,11 +211,9 @@ cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdi %postun server rm -f /var/log/wsmand.log %systemd_postun_with_restart openwsmand.service -/sbin/ldconfig +%{?ldconfig} -%post client -p /sbin/ldconfig - -%postun client -p /sbin/ldconfig +%ldconfig_scriptlets client %files -n libwsman1 %doc AUTHORS COPYING ChangeLog README.md TODO From 6dcd9ddbfc6ddbf9b6145b1c4cf84fb146b9b171 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 1 Feb 2019 17:36:08 +0000 Subject: [PATCH 041/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index feaea5d..084176c 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -280,6 +280,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri Feb 01 2019 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + * Mon Jan 21 2019 Mamoru TASAKA - 2.6.8-3 - F-30: rebuild against ruby26 From b28c67e01e0784fe3bcd7b15f50376c86500b3a9 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 13 Mar 2019 14:34:58 +0100 Subject: [PATCH 042/120] Fix CVE-2019-3816, CVE-2019-3833 and remove Dist Tag from changelog --- openwsman-2.6.8-CVE-2019-3816.patch | 79 ++++++++++++++++++++++++ openwsman-2.6.8-CVE-2019-3833.patch | 94 +++++++++++++++++++++++++++++ openwsman.spec | 15 ++++- 3 files changed, 186 insertions(+), 2 deletions(-) create mode 100644 openwsman-2.6.8-CVE-2019-3816.patch create mode 100644 openwsman-2.6.8-CVE-2019-3833.patch diff --git a/openwsman-2.6.8-CVE-2019-3816.patch b/openwsman-2.6.8-CVE-2019-3816.patch new file mode 100644 index 0000000..aa8835f --- /dev/null +++ b/openwsman-2.6.8-CVE-2019-3816.patch @@ -0,0 +1,79 @@ +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 08:52:06.112090942 +0100 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:01:15.496156789 +0100 +@@ -336,10 +336,12 @@ date_to_epoch(const char *s) + } + + static void +-remove_double_dots(char *s) ++remove_all_leading_dots(char *s) + { + char *p = s; + ++ while (*s != '\0' && *s == '.') s++; ++ + while (*s != '\0') { + *p++ = *s++; + if (s[-1] == '/' || s[-1] == '\\') +@@ -546,7 +548,7 @@ decide_what_to_do(struct conn *c) + *c->query++ = '\0'; + + _shttpd_url_decode(c->uri, strlen(c->uri), c->uri, strlen(c->uri) + 1); +- remove_double_dots(c->uri); ++ remove_all_leading_dots(c->uri); + + root = c->ctx->options[OPT_ROOT]; + if (strlen(c->uri) + strlen(root) >= sizeof(path)) { +@@ -556,6 +558,7 @@ decide_what_to_do(struct conn *c) + + (void) _shttpd_snprintf(path, sizeof(path), "%s%s", root, c->uri); + ++ DBG(("decide_what_to_do -> processed path: [%s]", path)); + /* User may use the aliases - check URI for mount point */ + if (is_alias(c->ctx, c->uri, &alias_uri, &alias_path) != NULL) { + (void) _shttpd_snprintf(path, sizeof(path), "%.*s%s", +@@ -572,7 +575,10 @@ decide_what_to_do(struct conn *c) + if ((ruri = _shttpd_is_registered_uri(c->ctx, c->uri)) != NULL) { + _shttpd_setup_embedded_stream(c, + ruri->callback, ruri->callback_data); +- } else ++ } else { ++ _shttpd_send_server_error(c, 403, "Forbidden"); ++ } ++#if 0 + if (strstr(path, HTPASSWD)) { + /* Do not allow to view passwords files */ + _shttpd_send_server_error(c, 403, "Forbidden"); +@@ -656,6 +662,7 @@ decide_what_to_do(struct conn *c) + } else { + _shttpd_send_server_error(c, 500, "Internal Error"); + } ++#endif + } + + static int +diff -up openwsman-2.6.8/src/server/wsmand.c.orig openwsman-2.6.8/src/server/wsmand.c +--- openwsman-2.6.8/src/server/wsmand.c.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/src/server/wsmand.c 2019-03-13 09:03:25.919181279 +0100 +@@ -198,6 +198,10 @@ static void daemonize(void) + int fd; + char *pid; + ++ /* Change our CWD to / */ ++ i = chdir("/"); ++ assert(i == 0); ++ + if (wsmand_options_get_foreground_debug() > 0) { + return; + } +@@ -214,10 +218,6 @@ static void daemonize(void) + log_pid = 0; + setsid(); + +- /* Change our CWD to / */ +- i=chdir("/"); +- assert(i == 0); +- + /* Close all file descriptors. */ + for (i = getdtablesize(); i >= 0; --i) + close(i); diff --git a/openwsman-2.6.8-CVE-2019-3833.patch b/openwsman-2.6.8-CVE-2019-3833.patch new file mode 100644 index 0000000..301724f --- /dev/null +++ b/openwsman-2.6.8-CVE-2019-3833.patch @@ -0,0 +1,94 @@ +diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c +--- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 09:32:32.417633057 +0100 ++++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:58:04.482486589 +0100 +@@ -705,11 +705,11 @@ parse_http_request(struct conn *c) + _shttpd_send_server_error(c, 500, "Cannot allocate request"); + } + ++ io_inc_tail(&c->rem.io, req_len); ++ + if (c->loc.flags & FLAG_CLOSED) + return; + +- io_inc_tail(&c->rem.io, req_len); +- + DBG(("Conn %d: parsing request: [%.*s]", c->rem.chan.sock, req_len, s)); + c->rem.flags |= FLAG_HEADERS_PARSED; + +@@ -975,7 +975,7 @@ write_stream(struct stream *from, struct + } + + +-static void ++static int + connection_desctructor(struct llhead *lp) + { + struct conn *c = LL_ENTRY(lp, struct conn, link); +@@ -999,7 +999,8 @@ connection_desctructor(struct llhead *lp + * Check the "Connection: " header before we free c->request + * If it its 'keep-alive', then do not close the connection + */ +- do_close = (c->ch.connection.v_vec.len >= vec.len && ++ do_close = c->rem.flags & FLAG_CLOSED || ++ (c->ch.connection.v_vec.len >= vec.len && + !_shttpd_strncasecmp(vec.ptr,c->ch.connection.v_vec.ptr,vec.len)) || + (c->major_version < 1 || + (c->major_version >= 1 && c->minor_version < 1)); +@@ -1021,7 +1022,7 @@ connection_desctructor(struct llhead *lp + io_clear(&c->loc.io); + c->birth_time = _shttpd_current_time; + if (io_data_len(&c->rem.io) > 0) +- process_connection(c, 0, 0); ++ return 1; + } else { + if (c->rem.io_class != NULL) + c->rem.io_class->close(&c->rem); +@@ -1032,6 +1033,8 @@ connection_desctructor(struct llhead *lp + + free(c); + } ++ ++ return 0; + } + + static void +@@ -1039,7 +1042,7 @@ worker_destructor(struct llhead *lp) + { + struct worker *worker = LL_ENTRY(lp, struct worker, link); + +- free_list(&worker->connections, connection_desctructor); ++ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); + free(worker); + } + +@@ -1072,6 +1075,8 @@ add_to_set(int fd, fd_set *set, int *max + static void + process_connection(struct conn *c, int remote_ready, int local_ready) + { ++again: ++ + /* Read from remote end if it is ready */ + if (remote_ready && io_space_len(&c->rem.io)) + read_stream(&c->rem); +@@ -1100,7 +1105,11 @@ process_connection(struct conn *c, int r + if ((_shttpd_current_time > c->expire_time) || + (c->rem.flags & FLAG_CLOSED) || + ((c->loc.flags & FLAG_CLOSED) && !io_data_len(&c->loc.io))) +- connection_desctructor(&c->link); ++ if (connection_desctructor(&c->link)) { ++ remote_ready = 0; ++ local_ready = 0; ++ goto again; ++ } + } + + static int +@@ -1642,7 +1651,7 @@ worker_function(void *param) + while (worker->exit_flag == 0) + poll_worker(worker, 1000 * 10); + +- free_list(&worker->connections, connection_desctructor); ++ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); + free(worker); + } + diff --git a/openwsman.spec b/openwsman.spec index 084176c..870f5f7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -20,6 +20,8 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch +Patch6: openwsman-2.6.8-CVE-2019-3816.patch +Patch7: openwsman-2.6.8-CVE-2019-3833.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -127,6 +129,8 @@ You can use it to send shell commands to a remote Windows hosts. %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line %patch5 -p1 -b .libcurl-error-codes-update +%patch6 -p1 -b .CVE-2019-3816 +%patch7 -p1 -b .CVE-2019-3833 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -280,6 +284,13 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Mar 13 2019 Vitezslav Crhonek - 2.6.8-5 +- Fix CVE-2019-3816 + Resolves: #1687760 +- Fix CVE-2019-3833 + Resolves: #1687762 +- Remove Dist Tag from the oldest changelog entry + * Fri Feb 01 2019 Fedora Release Engineering - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild @@ -610,5 +621,5 @@ rm -f /var/log/wsmand.log * Mon Sep 22 2008 Matt Domsch - 2.1.0-1 - update to 2.1.0, resolves security issues -* Tue Aug 19 2008 - 2.0.0-1%{?dist} +* Tue Aug 19 2008 - 2.0.0-1 - Modified the spec file to adhere to fedora packaging guidelines. From 75334969388d544a7f1760e33eb9203c9a8ef3a7 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 1 Apr 2019 13:59:14 +0200 Subject: [PATCH 043/120] Add requires libwsman1 for rubygem-openwsman --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 870f5f7..0dfd975 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -91,6 +91,7 @@ This package provides Python3 bindings to access the openwsman client API. License: BSD Summary: Ruby client bindings for Openwsman Obsoletes: %{name}-ruby < %{version}-%{release} +Requires: libwsman1 = %{version}-%{release} %description -n rubygem-%{gem_name} The openwsman gem provides a Ruby API to manage systems using @@ -284,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Apr 01 2019 Vitezslav Crhonek - 2.6.8-6 +- Add requires libwsman1 for rubygem-openwsman + * Wed Mar 13 2019 Vitezslav Crhonek - 2.6.8-5 - Fix CVE-2019-3816 Resolves: #1687760 From b0de51d2a70bbc025978a1760ab539fb3cf50db5 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Thu, 30 May 2019 13:43:00 +0200 Subject: [PATCH 044/120] Perl 5.30 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 0dfd975..541c0dd 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu May 30 2019 Jitka Plesnikova - 2.6.8-7 +- Perl 5.30 rebuild + * Mon Apr 01 2019 Vitezslav Crhonek - 2.6.8-6 - Add requires libwsman1 for rubygem-openwsman From ef167b04405c382179daf4e0b2adb3182174afa4 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 25 Jul 2019 23:39:57 +0000 Subject: [PATCH 045/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 541c0dd..6ec12a9 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu Jul 25 2019 Fedora Release Engineering - 2.6.8-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + * Thu May 30 2019 Jitka Plesnikova - 2.6.8-7 - Perl 5.30 rebuild From e422ac33790066a1046f43eaca840483bf5f4e94 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Mon, 19 Aug 2019 10:21:32 +0200 Subject: [PATCH 046/120] Rebuilt for Python 3.8 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 6ec12a9..8c0a031 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Aug 19 2019 Miro Hrončok - 2.6.8-9 +- Rebuilt for Python 3.8 + * Thu Jul 25 2019 Fedora Release Engineering - 2.6.8-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild From e8f40aab8a28d25b9e92371f5fc6fc1192811b5f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Thu, 3 Oct 2019 13:57:53 +0200 Subject: [PATCH 047/120] Rebuilt for Python 3.8.0rc1 (#1748018) --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8c0a031..c4da547 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Thu Oct 03 2019 Miro Hrončok - 2.6.8-10 +- Rebuilt for Python 3.8.0rc1 (#1748018) + * Mon Aug 19 2019 Miro Hrončok - 2.6.8-9 - Rebuilt for Python 3.8 From 4d62e7d3d3c616fdae4327f28ce7b308d303da74 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Sat, 18 Jan 2020 13:34:42 +0900 Subject: [PATCH 048/120] F-32: rebuild against ruby27 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c4da547..576d564 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Sat Jan 18 2020 Mamoru TASAKA - 2.6.8-11 +- F-32: rebuild against ruby27 + * Thu Oct 03 2019 Miro Hrončok - 2.6.8-10 - Rebuilt for Python 3.8.0rc1 (#1748018) From ffa5e2d1e3128fd85af01190a805d78e7a5bc69b Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Wed, 29 Jan 2020 20:28:59 +0000 Subject: [PATCH 049/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 576d564..7ef4fa4 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Jan 29 2020 Fedora Release Engineering - 2.6.8-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + * Sat Jan 18 2020 Mamoru TASAKA - 2.6.8-11 - F-32: rebuild against ruby27 From 203b40c9d79751a2fabe629c3035ef2fd13183db Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= Date: Tue, 26 May 2020 02:55:10 +0200 Subject: [PATCH 050/120] Rebuilt for Python 3.9 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 7ef4fa4..8574478 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue May 26 2020 Miro Hrončok - 2.6.8-13 +- Rebuilt for Python 3.9 + * Wed Jan 29 2020 Fedora Release Engineering - 2.6.8-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild From df0e5b4b98fd51dcc239bb3367a71b0d87c4880b Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 22 Jun 2020 19:29:23 +0200 Subject: [PATCH 051/120] Perl 5.32 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8574478..71f22d2 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 13%{?dist} +Release: 14%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -285,6 +285,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Mon Jun 22 2020 Jitka Plesnikova - 2.6.8-14 +- Perl 5.32 rebuild + * Tue May 26 2020 Miro Hrončok - 2.6.8-13 - Rebuilt for Python 3.9 From 2bbca28487dfac48490333a04c69597addc85b4c Mon Sep 17 00:00:00 2001 From: Jeff Law Date: Wed, 8 Jul 2020 16:04:08 -0600 Subject: [PATCH 052/120] Disable LTO --- openwsman.spec | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 71f22d2..0c23479 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 14%{?dist} +Release: 15%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -134,6 +134,11 @@ You can use it to send shell commands to a remote Windows hosts. %patch7 -p1 -b .CVE-2019-3833 %build +# We override CFLAGS/LDFLAGS below and force PIE executables, which is generally +# fine, except that it ultimately tries to mix PIC and PIE which is a no-no +# and triggers errors with LTO +# Disable LTO +%define _lto_cflags %{nil} # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -285,6 +290,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Jul 08 2020 Jeff Law - 2.6.8-15 +- Disable LTO + * Mon Jun 22 2020 Jitka Plesnikova - 2.6.8-14 - Perl 5.32 rebuild From 5f12a36e1bb6c2bdbb018befdc5d4b2828a0b5fe Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 28 Jul 2020 12:51:55 +0000 Subject: [PATCH 053/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 0c23479..7b19ae0 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 15%{?dist} +Release: 16%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -290,6 +290,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jul 28 2020 Fedora Release Engineering - 2.6.8-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + * Wed Jul 08 2020 Jeff Law - 2.6.8-15 - Disable LTO From 86820ef4bec0de1557d1dfe3f19786392b5ca640 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 22 Sep 2020 14:52:16 +0200 Subject: [PATCH 054/120] Use make macros, update flags, enable LTO, update ssleay.conf --- openwsman-2.6.8-update-ssleay-conf.patch | 15 +++++++++++++++ openwsman.spec | 21 ++++++++++++--------- 2 files changed, 27 insertions(+), 9 deletions(-) create mode 100644 openwsman-2.6.8-update-ssleay-conf.patch diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch new file mode 100644 index 0000000..15c5c74 --- /dev/null +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -0,0 +1,15 @@ +diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf +--- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 ++++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 +@@ -2,10 +2,8 @@ + # SSLeay example configuration file. + # + +-RANDFILE = /dev/random +- + [ req ] +-default_bits = 1024 ++default_bits = 2048 + default_keyfile = privkey.pem + distinguished_name = req_distinguished_name + diff --git a/openwsman.spec b/openwsman.spec index 7b19ae0..8c33e99 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 16%{?dist} +Release: 17%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -22,6 +22,7 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch Patch6: openwsman-2.6.8-CVE-2019-3816.patch Patch7: openwsman-2.6.8-CVE-2019-3833.patch +Patch8: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter @@ -132,13 +133,9 @@ You can use it to send shell commands to a remote Windows hosts. %patch5 -p1 -b .libcurl-error-codes-update %patch6 -p1 -b .CVE-2019-3816 %patch7 -p1 -b .CVE-2019-3833 +%patch8 -p1 -b .update-ssleay-conf %build -# We override CFLAGS/LDFLAGS below and force PIE executables, which is generally -# fine, except that it ultimately tries to mix PIC and PIE which is a no-no -# and triggers errors with LTO -# Disable LTO -%define _lto_cflags %{nil} # Removing executable permissions on .c and .h files to fix rpmlint warnings. chmod -x src/cpp/WsmanClient.h @@ -146,8 +143,8 @@ rm -rf build mkdir build export RPM_OPT_FLAGS="$RPM_OPT_FLAGS -DFEDORA -DNO_SSL_CALLBACK" -export CFLAGS="-D_GNU_SOURCE -fPIE -DPIE" -export LDFLAGS="$LDFLAGS -Wl,-z,now -pie" +export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" +export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ -DCMAKE_INSTALL_PREFIX=/usr \ @@ -178,7 +175,7 @@ cd build # Do not install the ruby extension, we are proviging the rubygem- instead. echo -n > bindings/ruby/cmake_install.cmake -make DESTDIR=%{buildroot} install +%make_install cd .. rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la @@ -290,6 +287,12 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Sep 22 2020 Vitezslav Crhonek - 2.6.8-17 +- Use make macros, patch by Tom Stellard + (https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro) +- Update flags, enable LTO +- Remove RANDFILE and increase default bits in ssleay.conf + * Tue Jul 28 2020 Fedora Release Engineering - 2.6.8-16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From ed78e5cc80bf4a4d1c9b9e1498fdee1215aada90 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 6 Jan 2021 22:35:31 +0900 Subject: [PATCH 055/120] F-34: rebuild against ruby 3.0 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8c33e99..24055e4 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 17%{?dist} +Release: 18%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -287,6 +287,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Wed Jan 06 2021 Mamoru TASAKA - 2.6.8-18 +- F-34: rebuild against ruby 3.0 + * Tue Sep 22 2020 Vitezslav Crhonek - 2.6.8-17 - Use make macros, patch by Tom Stellard (https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro) From c9696b4337dfc044966b30e629f3c82fdf3800c1 Mon Sep 17 00:00:00 2001 From: Tom Stellard Date: Thu, 7 Jan 2021 06:43:20 +0000 Subject: [PATCH 056/120] Add BuildRequires: make https://fedoraproject.org/wiki/Changes/Remove_make_from_BuildRoot --- openwsman.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/openwsman.spec b/openwsman.spec index 24055e4..771cdec 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -23,6 +23,7 @@ Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch Patch6: openwsman-2.6.8-CVE-2019-3816.patch Patch7: openwsman-2.6.8-CVE-2019-3833.patch Patch8: openwsman-2.6.8-update-ssleay-conf.patch +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter From 421a2a247fb8062e6e15fd4136e163950156b4f8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 26 Jan 2021 22:39:09 +0000 Subject: [PATCH 057/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 771cdec..d9b286e 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 18%{?dist} +Release: 19%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -288,6 +288,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Jan 26 2021 Fedora Release Engineering - 2.6.8-19 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Wed Jan 06 2021 Mamoru TASAKA - 2.6.8-18 - F-34: rebuild against ruby 3.0 From 2893dc05061ffddf64d572e7c209d065cfd148c5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 2 Mar 2021 16:13:08 +0100 Subject: [PATCH 058/120] Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d9b286e..178444b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.6.8 -Release: 19%{?dist} +Release: 20%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -288,6 +288,10 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2.6.8-20 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + * Tue Jan 26 2021 Fedora Release Engineering - 2.6.8-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From ed117179785e4b28f5dd4a6ff5c992994895dc4f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 9 Mar 2021 11:29:15 +0100 Subject: [PATCH 059/120] Update to openwsman-2.7.0 --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 52 +++++----- ...man-2.6.5-libcurl-error-codes-update.patch | 27 ------ openwsman-2.6.8-CVE-2019-3816.patch | 79 ---------------- openwsman-2.6.8-CVE-2019-3833.patch | 94 ------------------- openwsman.spec | 17 ++-- sources | 1 + 8 files changed, 40 insertions(+), 234 deletions(-) delete mode 100644 openwsman-2.6.5-libcurl-error-codes-update.patch delete mode 100644 openwsman-2.6.8-CVE-2019-3816.patch delete mode 100644 openwsman-2.6.8-CVE-2019-3833.patch diff --git a/.gitignore b/.gitignore index 490fdf3..40748df 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.6.8.tar.gz +/v2.7.0.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 1a4e76e..6b5ebfb 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.6.8/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.0/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 98f6bc2..5d64644 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/src/server/shttpd/compat_unix.h ---- openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/compat_unix.h 2018-11-22 13:30:10.756423510 +0100 +diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h +--- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,10 +12,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/compat_unix.h.orig openwsman-2.6.8/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/server/shttpd/io_ssl.c ---- openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/io_ssl.c 2018-11-22 13:30:10.757423510 +0100 -@@ -11,23 +11,6 @@ +diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c +--- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100 +@@ -11,28 +11,6 @@ #include "defs.h" #if !defined(NO_SSL) @@ -29,8 +29,13 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser - {"SSL_set_fd", {0}}, - {"SSL_new", {0}}, - {"SSL_CTX_new", {0}}, +-#if OPENSSL_VERSION_NUMBER < 0x10100000L - {"SSLv23_server_method", {0}}, - {"SSL_library_init", {0}}, +-#else +- {"TLS_server_method", {0}}, +- {"OPENSSL_init_ssl", {0}}, +-#endif - {"SSL_CTX_use_PrivateKey_file", {0}}, - {"SSL_CTX_use_certificate_file",{0}}, - {NULL, {0}} @@ -39,10 +44,10 @@ diff -up openwsman-2.6.8/src/server/shttpd/io_ssl.c.orig openwsman-2.6.8/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2018-11-22 13:30:41.314416695 +0100 -@@ -1476,20 +1476,14 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c +--- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100 +@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -59,20 +64,20 @@ diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/ser - } - /* Initialize SSL crap */ -+ debug("Initialize SSL"); -+ SSL_load_error_strings(); -+#if OPENSSL_VERSION_NUMBER >= 0x10100000L -+ OPENSSL_init_ssl(0, NULL); -+#else - SSL_library_init(); -+#endif + #if OPENSSL_VERSION_NUMBER < 0x10100000L + SSL_library_init(); if ((CTX = SSL_CTX_new(SSLv23_server_method())) == NULL) + #else +- OPENSSL_init_ssl(); ++ OPENSSL_init_ssl(0, NULL); + if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) + #endif _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server/shttpd/ssl.h ---- openwsman-2.6.8/src/server/shttpd/ssl.h.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/shttpd/ssl.h 2018-11-22 13:30:10.757423510 +0100 -@@ -12,52 +12,4 @@ +diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h +--- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200 ++++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100 +@@ -12,55 +12,4 @@ #include @@ -120,6 +125,9 @@ diff -up openwsman-2.6.8/src/server/shttpd/ssl.h.orig openwsman-2.6.8/src/server -#if OPENSSL_VERSION_NUMBER < 0x10100000L -#define SSLv23_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() -#define SSL_library_init() (* (int (*)(void)) FUNC(10))() +-#else +-#define TLS_server_method() (* (SSL_METHOD * (*)(void)) FUNC(9))() +-#define OPENSSL_init_ssl() (* (int (*)(void)) FUNC(10))() #endif -#define SSL_CTX_use_PrivateKey_file(x,y,z) (* (int (*)(SSL_CTX *, \ - const char *, int)) FUNC(11))((x), (y), (z)) diff --git a/openwsman-2.6.5-libcurl-error-codes-update.patch b/openwsman-2.6.5-libcurl-error-codes-update.patch deleted file mode 100644 index 82ee51f..0000000 --- a/openwsman-2.6.5-libcurl-error-codes-update.patch +++ /dev/null @@ -1,27 +0,0 @@ -diff -up openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig openwsman-2.6.5/src/lib/wsman-curl-client-transport.c ---- openwsman-2.6.5/src/lib/wsman-curl-client-transport.c.orig 2018-11-14 13:53:27.442138557 +0100 -+++ openwsman-2.6.5/src/lib/wsman-curl-client-transport.c 2018-11-14 14:11:28.508714204 +0100 -@@ -186,16 +186,23 @@ convert_to_last_error(CURLcode r) - return WS_LASTERR_SSL_CONNECT_ERROR; - case CURLE_BAD_FUNCTION_ARGUMENT: - return WS_LASTERR_CURL_BAD_FUNCTION_ARG; -+#if LIBCURL_VERSION_NUM < 0x073E00 - case CURLE_SSL_PEER_CERTIFICATE: - return WS_LASTERR_SSL_PEER_CERTIFICATE; -+#endif - case CURLE_SSL_ENGINE_NOTFOUND: - return WS_LASTERR_SSL_ENGINE_NOTFOUND; - case CURLE_SSL_ENGINE_SETFAILED: - return WS_LASTERR_SSL_ENGINE_SETFAILED; - case CURLE_SSL_CERTPROBLEM: - return WS_LASTERR_SSL_CERTPROBLEM; -+#if LIBCURL_VERSION_NUM < 0x073E00 - case CURLE_SSL_CACERT: - return WS_LASTERR_SSL_CACERT; -+#else -+ case CURLE_PEER_FAILED_VERIFICATION: -+ return WS_LASTERR_SSL_PEER_CERTIFICATE; -+#endif - #if LIBCURL_VERSION_NUM > 0x70C01 - case CURLE_SSL_ENGINE_INITFAILED: - return WS_LASTERR_SSL_ENGINE_INITFAILED; diff --git a/openwsman-2.6.8-CVE-2019-3816.patch b/openwsman-2.6.8-CVE-2019-3816.patch deleted file mode 100644 index aa8835f..0000000 --- a/openwsman-2.6.8-CVE-2019-3816.patch +++ /dev/null @@ -1,79 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 08:52:06.112090942 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:01:15.496156789 +0100 -@@ -336,10 +336,12 @@ date_to_epoch(const char *s) - } - - static void --remove_double_dots(char *s) -+remove_all_leading_dots(char *s) - { - char *p = s; - -+ while (*s != '\0' && *s == '.') s++; -+ - while (*s != '\0') { - *p++ = *s++; - if (s[-1] == '/' || s[-1] == '\\') -@@ -546,7 +548,7 @@ decide_what_to_do(struct conn *c) - *c->query++ = '\0'; - - _shttpd_url_decode(c->uri, strlen(c->uri), c->uri, strlen(c->uri) + 1); -- remove_double_dots(c->uri); -+ remove_all_leading_dots(c->uri); - - root = c->ctx->options[OPT_ROOT]; - if (strlen(c->uri) + strlen(root) >= sizeof(path)) { -@@ -556,6 +558,7 @@ decide_what_to_do(struct conn *c) - - (void) _shttpd_snprintf(path, sizeof(path), "%s%s", root, c->uri); - -+ DBG(("decide_what_to_do -> processed path: [%s]", path)); - /* User may use the aliases - check URI for mount point */ - if (is_alias(c->ctx, c->uri, &alias_uri, &alias_path) != NULL) { - (void) _shttpd_snprintf(path, sizeof(path), "%.*s%s", -@@ -572,7 +575,10 @@ decide_what_to_do(struct conn *c) - if ((ruri = _shttpd_is_registered_uri(c->ctx, c->uri)) != NULL) { - _shttpd_setup_embedded_stream(c, - ruri->callback, ruri->callback_data); -- } else -+ } else { -+ _shttpd_send_server_error(c, 403, "Forbidden"); -+ } -+#if 0 - if (strstr(path, HTPASSWD)) { - /* Do not allow to view passwords files */ - _shttpd_send_server_error(c, 403, "Forbidden"); -@@ -656,6 +662,7 @@ decide_what_to_do(struct conn *c) - } else { - _shttpd_send_server_error(c, 500, "Internal Error"); - } -+#endif - } - - static int -diff -up openwsman-2.6.8/src/server/wsmand.c.orig openwsman-2.6.8/src/server/wsmand.c ---- openwsman-2.6.8/src/server/wsmand.c.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/src/server/wsmand.c 2019-03-13 09:03:25.919181279 +0100 -@@ -198,6 +198,10 @@ static void daemonize(void) - int fd; - char *pid; - -+ /* Change our CWD to / */ -+ i = chdir("/"); -+ assert(i == 0); -+ - if (wsmand_options_get_foreground_debug() > 0) { - return; - } -@@ -214,10 +218,6 @@ static void daemonize(void) - log_pid = 0; - setsid(); - -- /* Change our CWD to / */ -- i=chdir("/"); -- assert(i == 0); -- - /* Close all file descriptors. */ - for (i = getdtablesize(); i >= 0; --i) - close(i); diff --git a/openwsman-2.6.8-CVE-2019-3833.patch b/openwsman-2.6.8-CVE-2019-3833.patch deleted file mode 100644 index 301724f..0000000 --- a/openwsman-2.6.8-CVE-2019-3833.patch +++ /dev/null @@ -1,94 +0,0 @@ -diff -up openwsman-2.6.8/src/server/shttpd/shttpd.c.orig openwsman-2.6.8/src/server/shttpd/shttpd.c ---- openwsman-2.6.8/src/server/shttpd/shttpd.c.orig 2019-03-13 09:32:32.417633057 +0100 -+++ openwsman-2.6.8/src/server/shttpd/shttpd.c 2019-03-13 09:58:04.482486589 +0100 -@@ -705,11 +705,11 @@ parse_http_request(struct conn *c) - _shttpd_send_server_error(c, 500, "Cannot allocate request"); - } - -+ io_inc_tail(&c->rem.io, req_len); -+ - if (c->loc.flags & FLAG_CLOSED) - return; - -- io_inc_tail(&c->rem.io, req_len); -- - DBG(("Conn %d: parsing request: [%.*s]", c->rem.chan.sock, req_len, s)); - c->rem.flags |= FLAG_HEADERS_PARSED; - -@@ -975,7 +975,7 @@ write_stream(struct stream *from, struct - } - - --static void -+static int - connection_desctructor(struct llhead *lp) - { - struct conn *c = LL_ENTRY(lp, struct conn, link); -@@ -999,7 +999,8 @@ connection_desctructor(struct llhead *lp - * Check the "Connection: " header before we free c->request - * If it its 'keep-alive', then do not close the connection - */ -- do_close = (c->ch.connection.v_vec.len >= vec.len && -+ do_close = c->rem.flags & FLAG_CLOSED || -+ (c->ch.connection.v_vec.len >= vec.len && - !_shttpd_strncasecmp(vec.ptr,c->ch.connection.v_vec.ptr,vec.len)) || - (c->major_version < 1 || - (c->major_version >= 1 && c->minor_version < 1)); -@@ -1021,7 +1022,7 @@ connection_desctructor(struct llhead *lp - io_clear(&c->loc.io); - c->birth_time = _shttpd_current_time; - if (io_data_len(&c->rem.io) > 0) -- process_connection(c, 0, 0); -+ return 1; - } else { - if (c->rem.io_class != NULL) - c->rem.io_class->close(&c->rem); -@@ -1032,6 +1033,8 @@ connection_desctructor(struct llhead *lp - - free(c); - } -+ -+ return 0; - } - - static void -@@ -1039,7 +1042,7 @@ worker_destructor(struct llhead *lp) - { - struct worker *worker = LL_ENTRY(lp, struct worker, link); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - -@@ -1072,6 +1075,8 @@ add_to_set(int fd, fd_set *set, int *max - static void - process_connection(struct conn *c, int remote_ready, int local_ready) - { -+again: -+ - /* Read from remote end if it is ready */ - if (remote_ready && io_space_len(&c->rem.io)) - read_stream(&c->rem); -@@ -1100,7 +1105,11 @@ process_connection(struct conn *c, int r - if ((_shttpd_current_time > c->expire_time) || - (c->rem.flags & FLAG_CLOSED) || - ((c->loc.flags & FLAG_CLOSED) && !io_data_len(&c->loc.io))) -- connection_desctructor(&c->link); -+ if (connection_desctructor(&c->link)) { -+ remote_ready = 0; -+ local_ready = 0; -+ goto again; -+ } - } - - static int -@@ -1642,7 +1651,7 @@ worker_function(void *param) - while (worker->exit_flag == 0) - poll_worker(worker, 1000 * 10); - -- free_list(&worker->connections, connection_desctructor); -+ free_list(&worker->connections, (void (*)(struct llhead *))connection_desctructor); - free(worker); - } - diff --git a/openwsman.spec b/openwsman.spec index 178444b..7483631 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -2,8 +2,8 @@ %global gem_name %{name} Name: openwsman -Version: 2.6.8 -Release: 20%{?dist} +Version: 2.7.0 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -19,10 +19,7 @@ Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch -Patch5: openwsman-2.6.5-libcurl-error-codes-update.patch -Patch6: openwsman-2.6.8-CVE-2019-3816.patch -Patch7: openwsman-2.6.8-CVE-2019-3833.patch -Patch8: openwsman-2.6.8-update-ssleay-conf.patch +Patch5: openwsman-2.6.8-update-ssleay-conf.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -131,10 +128,7 @@ You can use it to send shell commands to a remote Windows hosts. %patch2 -p1 -b .ruby-binding-build %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line -%patch5 -p1 -b .libcurl-error-codes-update -%patch6 -p1 -b .CVE-2019-3816 -%patch7 -p1 -b .CVE-2019-3833 -%patch8 -p1 -b .update-ssleay-conf +%patch5 -p1 -b .update-ssleay-conf %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -288,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Tue Mar 09 2021 Vitezslav Crhonek - 2.7.0-1 +- Update to openwsman-2.7.0 (thanks for a patch to Bastian Germann) + * Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 2.6.8-20 - Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. diff --git a/sources b/sources index 80e25cc..d5e209f 100644 --- a/sources +++ b/sources @@ -1,2 +1,3 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 +SHA512 (v2.7.0.tar.gz) = e61792eafd09e3608c736091d2742049086adaf5fffcda9391e4712ed1dedf3a533546a6af61ea6ce49d4cf4fb3649cb168f20260c4e975797395d6e565c6c37 From 994e5efb43a0c75e86fa44fe499a374fe9843890 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Fri, 21 May 2021 12:45:21 +0200 Subject: [PATCH 060/120] Perl 5.34 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 7483631..6bb5c54 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.7.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -282,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri May 21 2021 Jitka Plesnikova - 2.7.0-2 +- Perl 5.34 rebuild + * Tue Mar 09 2021 Vitezslav Crhonek - 2.7.0-1 - Update to openwsman-2.7.0 (thanks for a patch to Bastian Germann) From 83bb22a627eb9e9a4d8da9315718fdcca935b340 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 4 Jun 2021 20:14:09 +0200 Subject: [PATCH 061/120] Rebuilt for Python 3.10 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 6bb5c54..5a8c795 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -3,7 +3,7 @@ Name: openwsman Version: 2.7.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -282,6 +282,9 @@ rm -f /var/log/wsmand.log %{_bindir}/winrs %changelog +* Fri Jun 04 2021 Python Maint - 2.7.0-3 +- Rebuilt for Python 3.10 + * Fri May 21 2021 Jitka Plesnikova - 2.7.0-2 - Perl 5.34 rebuild From 959c5926888713e417d6fd7bdf111f56743d91a9 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 13:13:35 +0200 Subject: [PATCH 062/120] Add SELinux subpackage Signed-off-by: Vitezslav Crhonek --- openwsman.fc | 7 ++++ openwsman.if | 79 +++++++++++++++++++++++++++++++++++++++++++ openwsman.spec | 81 ++++++++++++++++++++++++++++++++++++++++++++- openwsman.te | 74 +++++++++++++++++++++++++++++++++++++++++ tests/tests-DSP.yml | 37 +++++++++++++++++++++ 5 files changed, 277 insertions(+), 1 deletion(-) create mode 100644 openwsman.fc create mode 100644 openwsman.if create mode 100644 openwsman.te create mode 100644 tests/tests-DSP.yml diff --git a/openwsman.fc b/openwsman.fc new file mode 100644 index 0000000..00d0643 --- /dev/null +++ b/openwsman.fc @@ -0,0 +1,7 @@ +/usr/lib/systemd/system/openwsmand.* -- gen_context(system_u:object_r:openwsman_unit_file_t,s0) + +/usr/sbin/openwsmand -- gen_context(system_u:object_r:openwsman_exec_t,s0) + +/var/log/wsmand.* -- gen_context(system_u:object_r:openwsman_log_t,s0) + +/var/run/wsmand.* -- gen_context(system_u:object_r:openwsman_run_t,s0) diff --git a/openwsman.if b/openwsman.if new file mode 100644 index 0000000..747853a --- /dev/null +++ b/openwsman.if @@ -0,0 +1,79 @@ +## WS-Management Server + +######################################## +## +## Execute openwsman in the openwsman domin. +## +## +## +## Domain allowed to transition. +## +## +# +interface(`openwsman_domtrans',` + gen_require(` + type openwsman_t, openwsman_exec_t; + ') + + corecmd_search_bin($1) + domtrans_pattern($1, openwsman_exec_t, openwsman_t) +') +######################################## +## +## Execute openwsman server in the openwsman domain. +## +## +## +## Domain allowed to transition. +## +## +# +interface(`openwsman_systemctl',` + gen_require(` + type openwsman_t; + type openwsman_unit_file_t; + ') + + systemd_exec_systemctl($1) + init_reload_services($1) + systemd_read_fifo_file_passwd_run($1) + allow $1 openwsman_unit_file_t:file read_file_perms; + allow $1 openwsman_unit_file_t:service manage_service_perms; + + ps_process_pattern($1, openwsman_t) +') + + +######################################## +## +## All of the rules required to administrate +## an openwsman environment +## +## +## +## Domain allowed access. +## +## +## +# +interface(`openwsman_admin',` + gen_require(` + type openwsman_t; + type openwsman_unit_file_t; + ') + + allow $1 openwsman_t:process { signal_perms }; + ps_process_pattern($1, openwsman_t) + + tunable_policy(`deny_ptrace',`',` + allow $1 openwsman_t:process ptrace; + ') + + openwsman_systemctl($1) + admin_pattern($1, openwsman_unit_file_t) + allow $1 openwsman_unit_file_t:service all_service_perms; + optional_policy(` + systemd_passwd_agent_exec($1) + systemd_read_fifo_file_passwd_run($1) + ') +') diff --git a/openwsman.spec b/openwsman.spec index 5a8c795..4518aad 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -1,9 +1,15 @@ # RubyGems's macros expect gem_name to exist. %global gem_name %{name} +# defining macros needed by SELinux +%global with_selinux 1 +%global selinuxtype targeted +%global moduletype contrib +%global modulename openwsman + Name: openwsman Version: 2.7.0 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -15,6 +21,11 @@ Source1: openwsmand.8.gz Source2: openwsmand.service # script for testing presence of the certificates in ExecStartPre Source3: owsmantestcert.sh +# Source100-102: selinux policy for openwsman, extracted +# from https://github.com/fedora-selinux/selinux-policy +Source100: %{modulename}.te +Source101: %{modulename}.if +Source102: %{modulename}.fc Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch @@ -72,6 +83,11 @@ Openwsman Client libraries. License: BSD Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} +%if 0%{?with_selinux} +# This ensures that the *-selinux package and all it’s dependencies are not pulled +# into containers and other systems that do not use SELinux +Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) +%endif %description server Openwsman Server and service libraries. @@ -121,6 +137,20 @@ Requires: rubygem-%{gem_name} = %{version}-%{release} This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. +%if 0%{?with_selinux} +# SELinux subpackage +%package selinux +Summary: openwsman SELinux policy +BuildArch: noarch +Requires: selinux-policy-%{selinuxtype} +Requires(post): selinux-policy-%{selinuxtype} +BuildRequires: selinux-policy-devel +%{?selinux_requires} + +%description selinux +Custom SELinux policy module +%endif + %prep %setup -q @@ -164,6 +194,15 @@ export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem +%if 0%{?with_selinux} +# SELinux policy (originally from selinux-policy-contrib) +# this policy module will override the production module +mkdir selinux +cp -p %{SOURCE100} %{SOURCE101} %{SOURCE102} selinux/ +make -f %{_datadir}/selinux/devel/Makefile %{modulename}.pp +bzip2 -9 %{modulename}.pp +%endif + %install cd build @@ -201,6 +240,11 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%if 0%{?with_selinux} +install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 +install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}/%{name}.if +%endif + %ldconfig_scriptlets -n libwsman1 %post server @@ -217,6 +261,30 @@ rm -f /var/log/wsmand.log %ldconfig_scriptlets client +%if 0%{?with_selinux} +# SELinux contexts are saved so that only affected files can be +# relabeled after the policy module installation +%pre selinux +%selinux_relabel_pre -s %{selinuxtype} + +%post selinux +%selinux_modules_install -s %{selinuxtype} %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 +%selinux_relabel_post -s %{selinuxtype} + +if [ "$1" -le "1" ]; then # First install + # the service needs to be restarted for the custom label to be applied + %systemd_postun_with_restart openwsmand.service +fi + +%postun selinux +if [ $1 -eq 0 ]; then + %selinux_modules_uninstall -s %{selinuxtype} %{modulename} + %selinux_relabel_post -s %{selinuxtype} + # the service needs to be restarted for the custom label to be removed + %systemd_postun_with_restart openwsmand.service +fi +%endif + %files -n libwsman1 %doc AUTHORS COPYING ChangeLog README.md TODO %{_libdir}/libwsman.so.* @@ -281,7 +349,18 @@ rm -f /var/log/wsmand.log %files winrs %{_bindir}/winrs +%if 0%{?with_selinux} +%files selinux +%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* +%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if +%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} +%endif + %changelog +* Tue Jun 08 2021 Vitezslav Crhonek - 2.7.0-4 +- Incorporate -selinux subpackage + See https://fedoraproject.org/wiki/SELinux/IndependentPolicy + * Fri Jun 04 2021 Python Maint - 2.7.0-3 - Rebuilt for Python 3.10 diff --git a/openwsman.te b/openwsman.te new file mode 100644 index 0000000..3bcd32c --- /dev/null +++ b/openwsman.te @@ -0,0 +1,74 @@ +policy_module(openwsman, 1.0.0) + +######################################## +# +# Declarations +# + +type openwsman_t; +type openwsman_exec_t; +init_daemon_domain(openwsman_t, openwsman_exec_t) + +type openwsman_tmp_t; +files_tmp_file(openwsman_tmp_t) + +type openwsman_tmpfs_t; +files_tmpfs_file(openwsman_tmpfs_t) + +type openwsman_log_t; +logging_log_file(openwsman_log_t) + +type openwsman_run_t; +files_pid_file(openwsman_run_t) + +type openwsman_unit_file_t; +systemd_unit_file(openwsman_unit_file_t) + +######################################## +# +# openwsman local policy +# + +allow openwsman_t self:capability setuid; + +allow openwsman_t self:process { fork }; +allow openwsman_t self:fifo_file rw_fifo_file_perms; +allow openwsman_t self:unix_stream_socket create_stream_socket_perms; +allow openwsman_t self:tcp_socket { create_socket_perms accept listen }; + +manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) +manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) +files_tmp_filetrans(openwsman_t, openwsman_tmp_t, { dir file }) + +manage_files_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) +manage_dirs_pattern(openwsman_t, openwsman_tmpfs_t, openwsman_tmpfs_t) +fs_tmpfs_filetrans(openwsman_t, openwsman_tmpfs_t, { dir file }) + +manage_files_pattern(openwsman_t, openwsman_log_t, openwsman_log_t) +logging_log_filetrans(openwsman_t, openwsman_log_t, { file }) + +manage_files_pattern(openwsman_t, openwsman_run_t, openwsman_run_t) +files_pid_filetrans(openwsman_t, openwsman_run_t, { file }) + +auth_use_nsswitch(openwsman_t) +auth_domtrans_chkpwd(openwsman_t) + +corenet_tcp_connect_pegasus_https_port(openwsman_t) +corenet_tcp_bind_vnc_port(openwsman_t) +corenet_tcp_bind_http_port(openwsman_t) + +dev_read_urand(openwsman_t) + +logging_send_syslog_msg(openwsman_t) +logging_send_audit_msgs(openwsman_t) + +optional_policy(` + sblim_stream_connect_sfcbd(openwsman_t) + sblim_rw_semaphores_sfcbd(openwsman_t) + sblim_getattr_exec_sfcbd(openwsman_t) +') + +optional_policy(` + unconfined_domain(openwsman_t) +') + diff --git a/tests/tests-DSP.yml b/tests/tests-DSP.yml new file mode 100644 index 0000000..ec2c494 --- /dev/null +++ b/tests/tests-DSP.yml @@ -0,0 +1,37 @@ +- hosts: localhost + + roles: + - role: standard-test-beakerlib + tags: + - classic + repositories: + - repo: https://pagure.io/DSP_test.git + dest: DSP_test + version: master + + tests: + - DSP_test + environment: + # RPM package containing the policy module + TEST_RPM: openwsman-selinux + # policy module name + TEST_POLICY: openwsman + # policy sources will be extracted from corresponding .src.rpm + # policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz") + # or empty string if policy sources are not inside a tar archive + POLICY_TAR: '' + # path to policy sources (in of the tar archive) -- //.(te|if|fc) + # or path in the src.rpm if there is no tar archive -- //.(te|if|fc) + # can contain wildcards (e.g. for versions etc.) + POLICY_PATH: . + + required_packages: + - policycoreutils + - selinux-policy + - selinux-policy-targeted + - setools-console + - libselinux-utils + - rpm + - tar + - git + - openwsman-server From 7553f989a3654b480c6d766265c885b900ed2fcd Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 14:09:19 +0200 Subject: [PATCH 063/120] selinux: order permissions in av rule as per refpolicy style guide https://github.com/SELinuxProject/refpolicy/wiki/StyleGuide Signed-off-by: Vitezslav Crhonek --- openwsman.te | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.te b/openwsman.te index 3bcd32c..e00816c 100644 --- a/openwsman.te +++ b/openwsman.te @@ -34,7 +34,7 @@ allow openwsman_t self:capability setuid; allow openwsman_t self:process { fork }; allow openwsman_t self:fifo_file rw_fifo_file_perms; allow openwsman_t self:unix_stream_socket create_stream_socket_perms; -allow openwsman_t self:tcp_socket { create_socket_perms accept listen }; +allow openwsman_t self:tcp_socket { accept create_socket_perms listen }; manage_files_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) manage_dirs_pattern(openwsman_t, openwsman_tmp_t, openwsman_tmp_t) From b7c1ef00391897b46bd129a720b694b59a4314ef Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 8 Jun 2021 14:55:12 +0200 Subject: [PATCH 064/120] selinux: update path for interface file Signed-off-by: Vitezslav Crhonek --- openwsman.spec | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 4518aad..400576a 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -4,7 +4,6 @@ # defining macros needed by SELinux %global with_selinux 1 %global selinuxtype targeted -%global moduletype contrib %global modulename openwsman Name: openwsman @@ -242,7 +241,7 @@ cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdi %if 0%{?with_selinux} install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 -install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}/%{name}.if +install -D -p -m 0644 build/selinux/%{modulename}.if %{buildroot}%{_datadir}/selinux/devel/include/distributed/%{name}.if %endif %ldconfig_scriptlets -n libwsman1 @@ -352,7 +351,7 @@ fi %if 0%{?with_selinux} %files selinux %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* -%{_datadir}/selinux/devel/include/%{moduletype}/%{modulename}.if +%{_datadir}/selinux/devel/include/distributed/%{modulename}.if %ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} %endif From 07c9612e44c7c28e69d23a4472dda4a8505c68e8 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 22 Jun 2021 10:24:24 +0200 Subject: [PATCH 065/120] Remove %systemd_postun_with_restart from %postun Signed-off-by: Vitezslav Crhonek --- openwsman.spec | 2 -- 1 file changed, 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 400576a..2809a1b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -279,8 +279,6 @@ fi if [ $1 -eq 0 ]; then %selinux_modules_uninstall -s %{selinuxtype} %{modulename} %selinux_relabel_post -s %{selinuxtype} - # the service needs to be restarted for the custom label to be removed - %systemd_postun_with_restart openwsmand.service fi %endif From 22933028149d76c74456404c0ee5ee34ea9a3d11 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 22 Jul 2021 17:23:40 +0000 Subject: [PATCH 066/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 2809a1b..1284357 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.0 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jul 22 2021 Fedora Release Engineering - 2.7.0-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Tue Jun 08 2021 Vitezslav Crhonek - 2.7.0-4 - Incorporate -selinux subpackage See https://fedoraproject.org/wiki/SELinux/IndependentPolicy From 7be7155ec263c5e9ab48a28c0ece9b012f7b47a6 Mon Sep 17 00:00:00 2001 From: Sahana Prasad Date: Tue, 14 Sep 2021 19:10:16 +0200 Subject: [PATCH 067/120] Rebuilt with OpenSSL 3.0.0 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1284357..f16bb95 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.0 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Tue Sep 14 2021 Sahana Prasad - 2.7.0-6 +- Rebuilt with OpenSSL 3.0.0 + * Thu Jul 22 2021 Fedora Release Engineering - 2.7.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From 4af778748b31036a25f113328e31e730b355b05f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 11 Nov 2021 12:01:58 +0100 Subject: [PATCH 068/120] Update to openwsman-2.7.1 Signed-off-by: Vitezslav Crhonek --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.8-update-ssleay-conf.patch | 11 ++++------- openwsman.spec | 7 +++++-- sources | 3 +-- 5 files changed, 12 insertions(+), 13 deletions(-) diff --git a/.gitignore b/.gitignore index 40748df..98ec9b4 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.0.tar.gz +/v2.7.1.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 6b5ebfb..1689eb8 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/binding major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.0/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.1/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.8-update-ssleay-conf.patch b/openwsman-2.6.8-update-ssleay-conf.patch index 15c5c74..c312af5 100644 --- a/openwsman-2.6.8-update-ssleay-conf.patch +++ b/openwsman-2.6.8-update-ssleay-conf.patch @@ -1,12 +1,9 @@ -diff -up openwsman-2.6.8/etc/ssleay.cnf.orig openwsman-2.6.8/etc/ssleay.cnf ---- openwsman-2.6.8/etc/ssleay.cnf.orig 2018-10-12 12:06:26.000000000 +0200 -+++ openwsman-2.6.8/etc/ssleay.cnf 2020-09-22 14:27:56.216306882 +0200 -@@ -2,10 +2,8 @@ - # SSLeay example configuration file. +diff -up openwsman-2.7.1/etc/ssleay.cnf.orig openwsman-2.7.1/etc/ssleay.cnf +--- openwsman-2.7.1/etc/ssleay.cnf.orig 2021-11-09 08:27:48.577749509 +0100 ++++ openwsman-2.7.1/etc/ssleay.cnf 2021-11-09 08:28:10.499967010 +0100 +@@ -3,7 +3,7 @@ # --RANDFILE = /dev/random -- [ req ] -default_bits = 1024 +default_bits = 2048 diff --git a/openwsman.spec b/openwsman.spec index f16bb95..eba91eb 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -7,8 +7,8 @@ %global modulename openwsman Name: openwsman -Version: 2.7.0 -Release: 6%{?dist} +Version: 2.7.1 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Nov 11 2021 Vitezslav Crhonek - 2.7.1-1 +- Update to openwsman-2.7.1 + * Tue Sep 14 2021 Sahana Prasad - 2.7.0-6 - Rebuilt with OpenSSL 3.0.0 diff --git a/sources b/sources index d5e209f..0675e6c 100644 --- a/sources +++ b/sources @@ -1,3 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.6.8.tar.gz) = 49e8ac9267602e3bedc5cca78f270798cd16cfb6ddf2fc5f2feb8539bb3eba3bbce09931a18c96cd231c4beeffda5c3ae5bb9e8531662c49ca6fd9681538ea31 -SHA512 (v2.7.0.tar.gz) = e61792eafd09e3608c736091d2742049086adaf5fffcda9391e4712ed1dedf3a533546a6af61ea6ce49d4cf4fb3649cb168f20260c4e975797395d6e565c6c37 +SHA512 (v2.7.1.tar.gz) = 37738bc5be7b1c3fa961587fca4db74b8e7714fc0641a550682275fbe925b2c8e18a683cf493f4740e479f7461cc98392d3d675f4769f5cf04e7249f1e9ee880 From 407d3e089bb63974ce4d41b87fe49bc7abbfbf00 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jan 2022 22:32:31 +0000 Subject: [PATCH 069/120] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index eba91eb..9e14061 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jan 20 2022 Fedora Release Engineering - 2.7.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Thu Nov 11 2021 Vitezslav Crhonek - 2.7.1-1 - Update to openwsman-2.7.1 From 38d5a113e7c91052dcc3e849dbff9bddfacbf6c5 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Thu, 27 Jan 2022 11:49:31 +0900 Subject: [PATCH 070/120] F-36: rebuild against ruby31 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 9e14061..65b472b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -8,7 +8,7 @@ Name: openwsman Version: 2.7.1 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -354,6 +354,9 @@ fi %endif %changelog +* Thu Jan 27 2022 Mamoru TASAKA - 2.7.1-3 +- F-36: rebuild against ruby31 + * Thu Jan 20 2022 Fedora Release Engineering - 2.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From ab115b7b54465fc5b04ed4fa5b55e18f7aacdf5b Mon Sep 17 00:00:00 2001 From: Jay W Date: Wed, 9 Feb 2022 12:21:38 +0000 Subject: [PATCH 071/120] Modify openwsman.spec to allow flatpak builds --- openwsman.spec | 66 +++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 62 insertions(+), 4 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 65b472b..1d4fc61 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -2,9 +2,26 @@ %global gem_name %{name} # defining macros needed by SELinux +# unless running a flatpak build. +%if 0%{?flatpak} +%global with_selinux 0 +%else %global with_selinux 1 %global selinuxtype targeted %global modulename openwsman +%endif + +# Bindings install in the wrong path for a flatpak build; this could be fixed, but +# we don't currently need the bindings for any Flatpak'ed application +%if 0%{?flatpak} +%global with_ruby 0 +%global with_perl 0 +%global with_python 0 +%else +%global with_ruby 1 +%global with_perl 1 +%global with_python 1 +%endif Name: openwsman Version: 2.7.1 @@ -22,19 +39,29 @@ Source2: openwsmand.service Source3: owsmantestcert.sh # Source100-102: selinux policy for openwsman, extracted # from https://github.com/fedora-selinux/selinux-policy +%if 0%{with_selinux} Source100: %{modulename}.te Source101: %{modulename}.if Source102: %{modulename}.fc +%endif Patch1: openwsman-2.4.0-pamsetup.patch Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -BuildRequires: make +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel -BuildRequires: python3 python3-devel ruby ruby-devel rubygems-devel perl-interpreter -BuildRequires: perl-devel perl-generators pkgconfig openssl-devel +%if %{with_python} +BuildRequires: python3 python3-devel +%endif +%if %{with_ruby} +BuildRequires: ruby ruby-devel rubygems-devel +%endif +%if %{with_perl} +BuildRequires: perl-interpreter perl-devel perl-generators +%endif +BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ @@ -91,6 +118,7 @@ Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) %description server Openwsman Server and service libraries. +%if %{with_python} %package python3 License: BSD Summary: Python bindings for openwsman client API @@ -100,7 +128,9 @@ Requires: libwsman1 = %{version}-%{release} %description python3 This package provides Python3 bindings to access the openwsman client API. +%endif +%if %{with_ruby} %package -n rubygem-%{gem_name} License: BSD Summary: Ruby client bindings for Openwsman @@ -118,7 +148,9 @@ BuildArch: noarch %description -n rubygem-%{gem_name}-doc Documentation for rubygem-%{gem_name} +%endif +%if %{with_perl} %package perl License: BSD Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) @@ -127,6 +159,7 @@ Requires: libwsman1 = %{version}-%{release} %description perl This package provides Perl bindings to access the openwsman client API. +%endif %package winrs Summary: Windows Remote Shell @@ -171,7 +204,7 @@ export CFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" export CXXFLAGS="$RPM_OPT_FLAGS -fPIC -pie -Wl,-z,relro -Wl,-z,now" cd build cmake \ - -DCMAKE_INSTALL_PREFIX=/usr \ + -DCMAKE_INSTALL_PREFIX=%{_prefix} \ -DCMAKE_VERBOSE_MAKEFILE=TRUE \ -DCMAKE_BUILD_TYPE=Release \ -DCMAKE_C_FLAGS_RELEASE:STRING="$RPM_OPT_FLAGS -fno-strict-aliasing" \ @@ -181,10 +214,20 @@ cmake \ -DLIB=%{_lib} \ -DBUILD_JAVA=no \ -DBUILD_PYTHON=no \ +%if ! %{with_python} + -DBUILD_PYTHON3=no \ +%endif +%if ! %{with_perl} + -DBUILD_PERL=no \ +%endif +%if ! %{with_ruby} + -DBUILD_RUBY=no \ +%endif .. make +%if %{with_ruby} # Make the freshly build openwsman libraries available to build the gem's # binary extension. export LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib @@ -192,6 +235,7 @@ export CPATH=%{_builddir}/%{name}-%{version}/include/ export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/build/src/lib/ %gem_install -n ./bindings/ruby/%{name}-%{version}.gem +%endif %if 0%{?with_selinux} # SELinux policy (originally from selinux-policy-contrib) @@ -205,16 +249,20 @@ bzip2 -9 %{modulename}.pp %install cd build +%if %{with_ruby} # Do not install the ruby extension, we are proviging the rubygem- instead. echo -n > bindings/ruby/cmake_install.cmake +%endif %make_install cd .. rm -f %{buildroot}/%{_libdir}/*.la rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la +%if %{with_ruby} [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb +%endif mkdir -p %{buildroot}%{_sysconfdir}/init.d install -m 644 etc/openwsman.conf %{buildroot}/%{_sysconfdir}/openwsman install -m 644 etc/openwsman_client.conf %{buildroot}/%{_sysconfdir}/openwsman @@ -230,6 +278,7 @@ install -m 644 include/wsman-xml.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-xml-binding.h %{buildroot}/%{_includedir}/openwsman install -m 644 include/wsman-dispatcher.h %{buildroot}/%{_includedir}/openwsman +%if %{with_ruby} mkdir -p %{buildroot}%{gem_dir} cp -pa ./build%{gem_dir}/* \ %{buildroot}%{gem_dir}/ @@ -238,6 +287,7 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%endif %if 0%{?with_selinux} install -D -m 0644 build/%{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 @@ -294,12 +344,15 @@ fi %{_libdir}/pkgconfig/* %{_libdir}/*.so +%if %{with_python} %files python3 %doc AUTHORS COPYING ChangeLog README.md %{python3_sitearch}/*.so %{python3_sitearch}/*.py %{python3_sitearch}/__pycache__/* +%endif +%if %{with_ruby} %files -n rubygem-%{gem_name} %doc AUTHORS COPYING ChangeLog README.md %dir %{gem_instdir} @@ -307,14 +360,19 @@ fi %{gem_extdir_mri} %exclude %{gem_cache} %{gem_spec} +%endif +%if %{with_ruby} %files -n rubygem-%{gem_name}-doc %doc %{gem_docdir} +%endif +%if %{with_perl} %files perl %doc AUTHORS COPYING ChangeLog README.md %{perl_vendorarch}/openwsman.so %{perl_vendorlib}/openwsman.pm +%endif %files server %doc AUTHORS COPYING ChangeLog README.md From 856f24f020b8a4459d4d77e27cf2b1ca69d9bcea Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 30 May 2022 20:12:50 +0200 Subject: [PATCH 072/120] Perl 5.36 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1d4fc61..d96f843 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -412,6 +412,9 @@ fi %endif %changelog +* Mon May 30 2022 Jitka Plesnikova - 2.7.1-4 +- Perl 5.36 rebuild + * Thu Jan 27 2022 Mamoru TASAKA - 2.7.1-3 - F-36: rebuild against ruby31 From 54805781bcca865d2046ac22ce54636f4cc44377 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 15 Jun 2022 18:15:51 +0200 Subject: [PATCH 073/120] Rebuilt for Python 3.11 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index d96f843..b5bd85d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -412,6 +412,9 @@ fi %endif %changelog +* Wed Jun 15 2022 Python Maint - 2.7.1-5 +- Rebuilt for Python 3.11 + * Mon May 30 2022 Jitka Plesnikova - 2.7.1-4 - Perl 5.36 rebuild From 586aec19b11a97ce3a13d97470df136d36f6dda7 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 20 Jul 2022 08:37:49 +0200 Subject: [PATCH 074/120] Improve handling of HTTP 401 Unauthorized Signed-off-by: Vitezslav Crhonek --- ...sman-2.7.1-http-unauthorized-improve.patch | 56 +++++++++++++++++++ openwsman.spec | 7 ++- 2 files changed, 62 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.1-http-unauthorized-improve.patch diff --git a/openwsman-2.7.1-http-unauthorized-improve.patch b/openwsman-2.7.1-http-unauthorized-improve.patch new file mode 100644 index 0000000..2351ada --- /dev/null +++ b/openwsman-2.7.1-http-unauthorized-improve.patch @@ -0,0 +1,56 @@ +diff -up openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig openwsman-2.7.1/src/lib/wsman-curl-client-transport.c +--- openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig 2021-04-07 17:25:55.000000000 +0200 ++++ openwsman-2.7.1/src/lib/wsman-curl-client-transport.c 2022-07-19 09:25:22.435355610 +0200 +@@ -459,6 +459,7 @@ wsmc_handler( WsManClient *cl, + long http_code; + long auth_avail = 0; + char *_user = NULL, *_pass = NULL; ++ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */ + u_buf_t *response = NULL; + //char *soapaction; + char *tmp_str = NULL; +@@ -564,6 +565,7 @@ wsmc_handler( WsManClient *cl, + _user = wsmc_get_user(cl); + _pass = wsmc_get_password(cl); + if (_user && _pass && cl->data.auth_set) { ++ _no_auth = 0; + r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set); + if (r != CURLE_OK) { + cl->fault_string = u_strdup(curl_easy_strerror(r)); +@@ -584,6 +586,11 @@ wsmc_handler( WsManClient *cl, + curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed"); + goto DONE; + } ++ } else { ++ /* request without user credentials, remember this for ++ * later use when it might become necessary to print an error message ++ */ ++ _no_auth = 1; + } + + if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) { +@@ -616,6 +623,24 @@ wsmc_handler( WsManClient *cl, + break; + case 401: + // The server requires authentication. ++ /* RFC 2616 states: ++ * ++ * If the request already included Authorization credentials, then the 401 ++ * response indicates that authorization has been refused for those ++ * credentials. If the 401 response contains the same challenge as the ++ * prior response, and the user agent has already attempted ++ * authentication at least once, then the user SHOULD be presented the ++ * entity that was given in the response, since that entity might ++ * include relevant diagnostic information. ++ */ ++ if (_no_auth == 0) { ++ /* no authentication credentials were used. It is only ++ * possible to write a message about the current situation. There ++ * is no information about the last attempt to access the resource. ++ * Maybe at a later point in time I will implement more state information. ++ */ ++ fprintf(stdout,"Authentication failed, please retry\n"); ++ } + break; + default: + // The status code does not indicate success. diff --git a/openwsman.spec b/openwsman.spec index b5bd85d..04da9cf 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -49,6 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch +Patch6: openwsman-2.7.1-http-unauthorized-improve.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -191,6 +192,7 @@ Custom SELinux policy module %patch3 -p1 -b .openssl-1.1-fix %patch4 -p1 -b .http-status-line %patch5 -p1 -b .update-ssleay-conf +%patch6 -p1 -b .http-unauthorized-improve %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -412,6 +414,9 @@ fi %endif %changelog +* Wed Jul 20 2022 Vitezslav Crhonek - 2.7.1-6 +- Improve handling of HTTP 401 Unauthorized + * Wed Jun 15 2022 Python Maint - 2.7.1-5 - Rebuilt for Python 3.11 From 28fe0b0300d558cb9f3c9e22f54034673901a7a8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 22 Jul 2022 02:18:49 +0000 Subject: [PATCH 075/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 04da9cf..91f530f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -414,6 +414,9 @@ fi %endif %changelog +* Fri Jul 22 2022 Fedora Release Engineering - 2.7.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Wed Jul 20 2022 Vitezslav Crhonek - 2.7.1-6 - Improve handling of HTTP 401 Unauthorized From ebc4ead18b074854b39064ea8ec05c3e70778c20 Mon Sep 17 00:00:00 2001 From: Nikola Knazekova Date: Mon, 26 Sep 2022 17:59:21 +0200 Subject: [PATCH 076/120] selinux: Exclude installed policy module file from RPM verification Update based on latest packaging guide: https://fedoraproject.org/wiki/SELinux/IndependentPolicy Signed-off-by: Nikola Knazekova --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 91f530f..daa8736 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -410,7 +410,7 @@ fi %files selinux %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* %{_datadir}/selinux/devel/include/distributed/%{modulename}.if -%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} +%ghost %verify(not md5 size mode mtime) %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} %endif %changelog From d81a62d50bd6e14f84975b6c255b7db6c15314bd Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 21 Oct 2022 08:56:44 +0200 Subject: [PATCH 077/120] Fix Ruby bindings for swig 4.1 Signed-off-by: Vitezslav Crhonek --- ...sman-2.7.1-fix-ruby-bindings-for-swig-41.patch | 12 ++++++++++++ openwsman.spec | 15 +++++++++++---- 2 files changed, 23 insertions(+), 4 deletions(-) create mode 100644 openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch diff --git a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch new file mode 100644 index 0000000..de7a199 --- /dev/null +++ b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.1/bindings/ruby/helpers.h.orig openwsman-2.7.1/bindings/ruby/helpers.h +--- openwsman-2.7.1/bindings/ruby/helpers.h.orig 2021-04-07 17:25:55.000000000 +0200 ++++ openwsman-2.7.1/bindings/ruby/helpers.h 2022-10-21 08:36:24.901459057 +0200 +@@ -47,7 +47,7 @@ + * + */ + +-#if SWIGVERSION > 0x020004 ++#if SWIG_VERSION > 0x020004 + #define KLASS_DECL(k,t) swig_class *k = (swig_class *)(t->clientdata) + #define KLASS_OF(x) x->klass + #else diff --git a/openwsman.spec b/openwsman.spec index daa8736..05e2110 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -50,17 +50,18 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.1-http-unauthorized-improve.patch -BuildRequires: make +Patch7: openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch +BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel %if %{with_python} BuildRequires: python3 python3-devel %endif %if %{with_ruby} -BuildRequires: ruby ruby-devel rubygems-devel +BuildRequires: ruby ruby-devel rubygems-devel %endif %if %{with_perl} -BuildRequires: perl-interpreter perl-devel perl-generators +BuildRequires: perl-interpreter perl-devel perl-generators %endif BuildRequires: pkgconfig openssl-devel BuildRequires: cmake @@ -193,6 +194,7 @@ Custom SELinux policy module %patch4 -p1 -b .http-status-line %patch5 -p1 -b .update-ssleay-conf %patch6 -p1 -b .http-unauthorized-improve +%patch7 -p1 -b .fix-ruby-bindings-for-swig-41 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -414,6 +416,11 @@ fi %endif %changelog +* Fri Oct 21 2022 Vitezslav Crhonek - 2.7.1-8 +- Fix Ruby bindings for swig 4.1 (backported from upstream) + Resolves: #2136510 +- Remove mixed use of spaces and tabs from spec file + * Fri Jul 22 2022 Fedora Release Engineering - 2.7.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From e38142b56779ccc20d2ddbbbcd6b9752f1aa6484 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 4 Jan 2023 14:57:56 +0900 Subject: [PATCH 078/120] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 05e2110..df6a11b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -416,6 +416,9 @@ fi %endif %changelog +* Wed Jan 04 2023 Mamoru TASAKA - 2.7.1-9 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 + * Fri Oct 21 2022 Vitezslav Crhonek - 2.7.1-8 - Fix Ruby bindings for swig 4.1 (backported from upstream) Resolves: #2136510 From d661b6107722dfbf32f702f1983872d9c62969e9 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Fri, 13 Jan 2023 09:53:10 +0100 Subject: [PATCH 079/120] Remove perl(MODULE_COMPAT), it will be replaced by generators --- openwsman.spec | 1 - 1 file changed, 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index df6a11b..b824ecc 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -155,7 +155,6 @@ Documentation for rubygem-%{gem_name} %if %{with_perl} %package perl License: BSD -Requires: perl(:MODULE_COMPAT_%(eval "`%{__perl} -V:version`"; echo $version)) Summary: Perl bindings for openwsman client API Requires: libwsman1 = %{version}-%{release} From 7c91375304f8fc1b899ef7953a5834718019698d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 19 Jan 2023 23:01:43 +0000 Subject: [PATCH 080/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index b824ecc..bb20ea6 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD @@ -415,6 +415,9 @@ fi %endif %changelog +* Thu Jan 19 2023 Fedora Release Engineering - 2.7.1-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Wed Jan 04 2023 Mamoru TASAKA - 2.7.1-9 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.2 From 768470808f66e51078d4fcc6284ecf40de0de0e9 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 14 Feb 2023 15:52:09 +0100 Subject: [PATCH 081/120] SPDX migration --- openwsman.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index bb20ea6..f0aba66 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,10 +25,10 @@ Name: openwsman Version: 2.7.1 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management -License: BSD +License: BSD-3-Clause AND MIT URL: http://www.openwsman.org/ Source0: https://github.com/Openwsman/openwsman/archive/v%{version}.tar.gz # help2man generated manpage for openwsmand binary @@ -415,6 +415,9 @@ fi %endif %changelog +* Tue Feb 14 2023 Vitezslav Crhonek - 2.7.1-11 +- SPDX migration + * Thu Jan 19 2023 Fedora Release Engineering - 2.7.1-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From f5e4d0862f3740911db1f662e2d620c980c36111 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Wed, 14 Jun 2023 23:08:01 +0200 Subject: [PATCH 082/120] Rebuilt for Python 3.12 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index f0aba66..f5b36b7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Wed Jun 14 2023 Python Maint - 2.7.1-12 +- Rebuilt for Python 3.12 + * Tue Feb 14 2023 Vitezslav Crhonek - 2.7.1-11 - SPDX migration From d06bc607f88879eee316332fbd0c90959bd8a394 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Tue, 11 Jul 2023 15:32:34 +0200 Subject: [PATCH 083/120] Perl 5.38 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index f5b36b7..c353677 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Tue Jul 11 2023 Jitka Plesnikova - 2.7.1-13 +- Perl 5.38 rebuild + * Wed Jun 14 2023 Python Maint - 2.7.1-12 - Rebuilt for Python 3.12 From 82ef81bd164ccf4ae6a959cbe29715213e216dbe Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 20 Jul 2023 18:16:04 +0000 Subject: [PATCH 084/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c353677..b1e7d55 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.1 -Release: 13%{?dist} +Release: 14%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -415,6 +415,9 @@ fi %endif %changelog +* Thu Jul 20 2023 Fedora Release Engineering - 2.7.1-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Tue Jul 11 2023 Jitka Plesnikova - 2.7.1-13 - Perl 5.38 rebuild From 25ae2ebc1409893f79acd719cc288c2ddcc60e75 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 31 Aug 2023 09:50:31 +0200 Subject: [PATCH 085/120] Update to openwsman-2.7.2, replace deprecated patchN Signed-off-by: Vitezslav Crhonek --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 8 +-- ...-2.7.1-fix-ruby-bindings-for-swig-41.patch | 12 ---- ...sman-2.7.1-http-unauthorized-improve.patch | 56 ------------------- openwsman.spec | 17 ++---- sources | 2 +- 6 files changed, 12 insertions(+), 85 deletions(-) delete mode 100644 openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch delete mode 100644 openwsman-2.7.1-http-unauthorized-improve.patch diff --git a/.gitignore b/.gitignore index 98ec9b4..b3868d7 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.1.tar.gz +/v2.7.2.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 1689eb8..87c890d 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -1,12 +1,12 @@ -diff -up openwsman-2.4.12/bindings/ruby/extconf.rb.orig openwsman-2.4.12/bindings/ruby/extconf.rb ---- openwsman-2.4.12/bindings/ruby/extconf.rb.orig 2015-02-09 09:28:58.232581263 +0100 -+++ openwsman-2.4.12/bindings/ruby/extconf.rb 2015-02-09 09:38:22.836772879 +0100 +diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ruby/extconf.rb +--- openwsman-2.7.2/bindings/ruby/extconf.rb.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/bindings/ruby/extconf.rb 2023-08-09 12:50:21.361216733 +0200 @@ -32,7 +32,7 @@ swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.1/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch b/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch deleted file mode 100644 index de7a199..0000000 --- a/openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.1/bindings/ruby/helpers.h.orig openwsman-2.7.1/bindings/ruby/helpers.h ---- openwsman-2.7.1/bindings/ruby/helpers.h.orig 2021-04-07 17:25:55.000000000 +0200 -+++ openwsman-2.7.1/bindings/ruby/helpers.h 2022-10-21 08:36:24.901459057 +0200 -@@ -47,7 +47,7 @@ - * - */ - --#if SWIGVERSION > 0x020004 -+#if SWIG_VERSION > 0x020004 - #define KLASS_DECL(k,t) swig_class *k = (swig_class *)(t->clientdata) - #define KLASS_OF(x) x->klass - #else diff --git a/openwsman-2.7.1-http-unauthorized-improve.patch b/openwsman-2.7.1-http-unauthorized-improve.patch deleted file mode 100644 index 2351ada..0000000 --- a/openwsman-2.7.1-http-unauthorized-improve.patch +++ /dev/null @@ -1,56 +0,0 @@ -diff -up openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig openwsman-2.7.1/src/lib/wsman-curl-client-transport.c ---- openwsman-2.7.1/src/lib/wsman-curl-client-transport.c.orig 2021-04-07 17:25:55.000000000 +0200 -+++ openwsman-2.7.1/src/lib/wsman-curl-client-transport.c 2022-07-19 09:25:22.435355610 +0200 -@@ -459,6 +459,7 @@ wsmc_handler( WsManClient *cl, - long http_code; - long auth_avail = 0; - char *_user = NULL, *_pass = NULL; -+ int _no_auth = 0; /* 0 if authentication is used, 1 if no authentication was used */ - u_buf_t *response = NULL; - //char *soapaction; - char *tmp_str = NULL; -@@ -564,6 +565,7 @@ wsmc_handler( WsManClient *cl, - _user = wsmc_get_user(cl); - _pass = wsmc_get_password(cl); - if (_user && _pass && cl->data.auth_set) { -+ _no_auth = 0; - r = curl_easy_setopt(curl, CURLOPT_HTTPAUTH, cl->data.auth_set); - if (r != CURLE_OK) { - cl->fault_string = u_strdup(curl_easy_strerror(r)); -@@ -584,6 +586,11 @@ wsmc_handler( WsManClient *cl, - curl_err("curl_easy_setopt(curl, CURLOPT_USERPWD, ..) failed"); - goto DONE; - } -+ } else { -+ /* request without user credentials, remember this for -+ * later use when it might become necessary to print an error message -+ */ -+ _no_auth = 1; - } - - if (wsman_debug_level_debugged(DEBUG_LEVEL_MESSAGE)) { -@@ -616,6 +623,24 @@ wsmc_handler( WsManClient *cl, - break; - case 401: - // The server requires authentication. -+ /* RFC 2616 states: -+ * -+ * If the request already included Authorization credentials, then the 401 -+ * response indicates that authorization has been refused for those -+ * credentials. If the 401 response contains the same challenge as the -+ * prior response, and the user agent has already attempted -+ * authentication at least once, then the user SHOULD be presented the -+ * entity that was given in the response, since that entity might -+ * include relevant diagnostic information. -+ */ -+ if (_no_auth == 0) { -+ /* no authentication credentials were used. It is only -+ * possible to write a message about the current situation. There -+ * is no information about the last attempt to access the resource. -+ * Maybe at a later point in time I will implement more state information. -+ */ -+ fprintf(stdout,"Authentication failed, please retry\n"); -+ } - break; - default: - // The status code does not indicate success. diff --git a/openwsman.spec b/openwsman.spec index b1e7d55..a058e19 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -24,8 +24,8 @@ %endif Name: openwsman -Version: 2.7.1 -Release: 14%{?dist} +Version: 2.7.2 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,8 +49,6 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -Patch6: openwsman-2.7.1-http-unauthorized-improve.patch -Patch7: openwsman-2.7.1-fix-ruby-bindings-for-swig-41.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -187,13 +185,7 @@ Custom SELinux policy module %prep %setup -q -%patch1 -p1 -b .pamsetup -%patch2 -p1 -b .ruby-binding-build -%patch3 -p1 -b .openssl-1.1-fix -%patch4 -p1 -b .http-status-line -%patch5 -p1 -b .update-ssleay-conf -%patch6 -p1 -b .http-unauthorized-improve -%patch7 -p1 -b .fix-ruby-bindings-for-swig-41 +%autopatch -p1 %build # Removing executable permissions on .c and .h files to fix rpmlint warnings. @@ -415,6 +407,9 @@ fi %endif %changelog +* Thu Aug 31 2023 Vitezslav Crhonek - 2.7.2-1 +- Update to openwsman-2.7.2 + * Thu Jul 20 2023 Fedora Release Engineering - 2.7.1-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild diff --git a/sources b/sources index 0675e6c..250b1fa 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.7.1.tar.gz) = 37738bc5be7b1c3fa961587fca4db74b8e7714fc0641a550682275fbe925b2c8e18a683cf493f4740e479f7461cc98392d3d675f4769f5cf04e7249f1e9ee880 +SHA512 (v2.7.2.tar.gz) = ffd6a0d00a00b00e321b2b55e0c77326f5943ca3224eee74c706e53a1c5c44ef0e8b1cfde5d631966769eefd4e567b0db8713085b7a8b386c2871ab4ada83046 From 1d9613dae754e8b9201dd873735375e4ea52cbb9 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 3 Jan 2024 23:27:00 +0900 Subject: [PATCH 086/120] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index a058e19..629cc52 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -407,6 +407,9 @@ fi %endif %changelog +* Wed Jan 03 2024 Mamoru TASAKA - 2.7.2-2 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 + * Thu Aug 31 2023 Vitezslav Crhonek - 2.7.2-1 - Update to openwsman-2.7.2 From 7c23549251ef299057ab33fd28030db442ab06f3 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 21 Jan 2024 11:26:56 +0000 Subject: [PATCH 087/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 629cc52..b927214 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -407,6 +407,9 @@ fi %endif %changelog +* Sun Jan 21 2024 Fedora Release Engineering - 2.7.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Wed Jan 03 2024 Mamoru TASAKA - 2.7.2-2 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.3 From 049821cecda67a7aafd88d4eaa7ad5122eb52976 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 22 Jan 2024 11:02:23 +0100 Subject: [PATCH 088/120] Fix FTBFS --- openwsman-2.7.2-fix-ftbfs.patch | 12 ++++++++++++ openwsman.spec | 7 ++++++- 2 files changed, 18 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.2-fix-ftbfs.patch diff --git a/openwsman-2.7.2-fix-ftbfs.patch b/openwsman-2.7.2-fix-ftbfs.patch new file mode 100644 index 0000000..b30b3cf --- /dev/null +++ b/openwsman-2.7.2-fix-ftbfs.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.2/bindings/openwsman.i.orig openwsman-2.7.2/bindings/openwsman.i +--- openwsman-2.7.2/bindings/openwsman.i.orig 2024-01-22 09:36:42.764721705 +0100 ++++ openwsman-2.7.2/bindings/openwsman.i 2024-01-22 09:37:29.970817151 +0100 +@@ -109,7 +109,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S + + %typemap(in) FILE* { + #if RUBY_VERSION > 18 +- struct rb_io_t *fptr; ++ struct rb_io *fptr; + #else + struct OpenFile *fptr; + #endif diff --git a/openwsman.spec b/openwsman.spec index b927214..cdd8bb0 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,6 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch +Patch6: openwsman-2.7.2-fix-ftbfs.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -407,6 +408,10 @@ fi %endif %changelog +* Mon Jan 22 2024 Vitezslav Crhonek - 2.7.2-4 +- Fix FTBFS + Resolves: #2259165 + * Sun Jan 21 2024 Fedora Release Engineering - 2.7.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From ba629d7155d27d1af28b9e573454f008d1e80d6a Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 25 Jan 2024 11:33:40 +0000 Subject: [PATCH 089/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index cdd8bb0..93339aa 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Thu Jan 25 2024 Fedora Release Engineering - 2.7.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Mon Jan 22 2024 Vitezslav Crhonek - 2.7.2-4 - Fix FTBFS Resolves: #2259165 From b606719aa298cd4920ae7964e56f170d9777eac1 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 10 May 2024 09:04:19 +0200 Subject: [PATCH 090/120] Update license tags in subpackages to SPDX format --- openwsman.spec | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 93339aa..58c7772 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -77,7 +77,7 @@ requirements that exposes a set of operations focused on and covers all system management aspects. %package -n libwsman1 -License: BSD +License: BSD-3-Clause AND MIT Summary: Open source Implementation of WS-Management Provides: %{name} = %{version}-%{release} Obsoletes: %{name} < %{version}-%{release} @@ -86,7 +86,7 @@ Obsoletes: %{name} < %{version}-%{release} Openwsman library for packages dependent on openwsman. %package -n libwsman-devel -License: BSD +License: BSD-3-Clause AND MIT Summary: Open source Implementation of WS-Management Provides: %{name}-devel = %{version}-%{release} Obsoletes: %{name}-devel < %{version}-%{release} @@ -100,14 +100,14 @@ Requires: libcurl-devel Development files for openwsman. %package client -License: BSD +License: BSD-3-Clause AND MIT Summary: Openwsman Client libraries %description client Openwsman Client libraries. %package server -License: BSD +License: BSD-3-Clause AND MIT Summary: Openwsman Server and service libraries Requires: libwsman1 = %{version}-%{release} %if 0%{?with_selinux} @@ -121,7 +121,7 @@ Openwsman Server and service libraries. %if %{with_python} %package python3 -License: BSD +License: BSD-3-Clause AND MIT Summary: Python bindings for openwsman client API Requires: %{__python3} Requires: libwsman1 = %{version}-%{release} @@ -133,7 +133,7 @@ This package provides Python3 bindings to access the openwsman client API. %if %{with_ruby} %package -n rubygem-%{gem_name} -License: BSD +License: BSD-3-Clause AND MIT Summary: Ruby client bindings for Openwsman Obsoletes: %{name}-ruby < %{version}-%{release} Requires: libwsman1 = %{version}-%{release} @@ -153,7 +153,7 @@ Documentation for rubygem-%{gem_name} %if %{with_perl} %package perl -License: BSD +License: BSD-3-Clause AND MIT Summary: Perl bindings for openwsman client API Requires: libwsman1 = %{version}-%{release} @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri May 10 2024 Vitezslav Crhonek - 2.7.2-6 +- Update license tags in subpackages to SPDX format + * Thu Jan 25 2024 Fedora Release Engineering - 2.7.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 4fd758ebc8e0aaa1259e8e7245eae4fff59c32ff Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 7 Jun 2024 18:57:17 +0200 Subject: [PATCH 091/120] Rebuilt for Python 3.13 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 58c7772..fd6401d 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri Jun 07 2024 Python Maint - 2.7.2-7 +- Rebuilt for Python 3.13 + * Fri May 10 2024 Vitezslav Crhonek - 2.7.2-6 - Update license tags in subpackages to SPDX format From b4f95a4140a568c6b4835eac3ba3d35a520af089 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Wed, 12 Jun 2024 13:06:09 +0200 Subject: [PATCH 092/120] Perl 5.40 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index fd6401d..1ed52ef 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Wed Jun 12 2024 Jitka Plesnikova - 2.7.2-8 +- Perl 5.40 rebuild + * Fri Jun 07 2024 Python Maint - 2.7.2-7 - Rebuilt for Python 3.13 From d0cea79dae8fa8bb068709ec382fe8a9c2ece0ba Mon Sep 17 00:00:00 2001 From: Python Maint Date: Tue, 18 Jun 2024 09:37:36 +0200 Subject: [PATCH 093/120] Rebuilt for Python 3.13 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 1ed52ef..c3c8151 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Tue Jun 18 2024 Python Maint - 2.7.2-9 +- Rebuilt for Python 3.13 + * Wed Jun 12 2024 Jitka Plesnikova - 2.7.2-8 - Perl 5.40 rebuild From 12519f950e1acb89cb5e5523685cb43cd2145ab4 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Sun, 23 Jun 2024 14:12:10 -0400 Subject: [PATCH 094/120] Fix build with RPM 4.20 %_builddir now contains a build-specific path: https://github.com/rpm-software-management/rpm/issues/2078 --- openwsman-2.4.12-ruby-binding-build.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 87c890d..eb52678 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2-build/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." From 613e85663e0ac14622a5f8d5a453fdaeff77d89f Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 25 Jun 2024 13:08:46 +0200 Subject: [PATCH 095/120] Rebuild --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c3c8151..042d506 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,10 @@ fi %endif %changelog +* Tue Jun 25 2024 Vitezslav Crhonek - 2.7.2-10 +- Rebuild + Resolves: #2290726 + * Tue Jun 18 2024 Python Maint - 2.7.2-9 - Rebuilt for Python 3.13 From 1d0094977b201dc1c28090228955dff13a3852c8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 18 Jul 2024 21:04:40 +0000 Subject: [PATCH 096/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 042d506..12af969 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Thu Jul 18 2024 Fedora Release Engineering - 2.7.2-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Tue Jun 25 2024 Vitezslav Crhonek - 2.7.2-10 - Rebuild Resolves: #2290726 From 053236801c43a40453faf3c15973e6e79419ef36 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 30 Aug 2024 13:50:15 +0200 Subject: [PATCH 097/120] Add rpminspect.yaml --- rpminspect.yaml | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 rpminspect.yaml diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..765cfc9 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,5 @@ +--- +badfuncs: + allowed: + /usr/sbin/openwsmand: + - inet_ntoa From d5765d29775a9e409b291aebcec24b95a75cfed5 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Wed, 8 Jan 2025 11:07:07 +0900 Subject: [PATCH 098/120] Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 12af969..8121b65 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Wed Jan 08 2025 Mamoru TASAKA - 2.7.2-12 +- Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 + * Thu Jul 18 2024 Fedora Release Engineering - 2.7.2-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From c98dedc9447a7aab4c756c3e3f9052d8596c4a63 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jan 2025 21:55:13 +0000 Subject: [PATCH 099/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8121b65..87c9846 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -408,6 +408,9 @@ fi %endif %changelog +* Fri Jan 17 2025 Fedora Release Engineering - 2.7.2-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Jan 08 2025 Mamoru TASAKA - 2.7.2-12 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_3.4 From 531f9577de2ad94453385bd79510ce2238821648 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 23 Jan 2025 12:52:51 +0100 Subject: [PATCH 100/120] Fix FTBFS with GCC 15, bin and sbin unification --- openwsman-2.7.2-gcc15-fix.patch | 24 ++++++++++++++++++++++++ openwsman.spec | 8 ++++++-- 2 files changed, 30 insertions(+), 2 deletions(-) create mode 100644 openwsman-2.7.2-gcc15-fix.patch diff --git a/openwsman-2.7.2-gcc15-fix.patch b/openwsman-2.7.2-gcc15-fix.patch new file mode 100644 index 0000000..6dc4078 --- /dev/null +++ b/openwsman-2.7.2-gcc15-fix.patch @@ -0,0 +1,24 @@ +diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2/src/plugins/swig/src/target_ruby.c +--- openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/src/plugins/swig/src/target_ruby.c 2025-01-23 11:53:58.082946042 +0100 +@@ -49,7 +49,7 @@ + */ + + static VALUE +-load_module() ++load_module(VALUE) + { + ruby_script(PLUGIN_FILE); + return rb_require(PLUGIN_FILE); +diff -up openwsman-2.7.2/src/server/CMakeLists.txt.orig openwsman-2.7.2/src/server/CMakeLists.txt +--- openwsman-2.7.2/src/server/CMakeLists.txt.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/src/server/CMakeLists.txt 2025-01-23 12:08:44.042639395 +0100 +@@ -47,7 +47,7 @@ if( HAVE_LIBDL ) + TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) + endif( HAVE_LIBDL ) + +-INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin) ++INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin) + + # + # diff --git a/openwsman.spec b/openwsman.spec index 87c9846..324a1dd 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 13%{?dist} +Release: 14%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -50,6 +50,7 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-fix-ftbfs.patch +Patch7: openwsman-2.7.2-gcc15-fix.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -388,7 +389,7 @@ fi %dir %{_libdir}/openwsman/plugins %{_libdir}/openwsman/plugins/*.so %{_libdir}/openwsman/plugins/*.so.* -%{_sbindir}/openwsmand +%{_bindir}/openwsmand %{_libdir}/libwsman_server.so.* %{_mandir}/man8/* @@ -408,6 +409,9 @@ fi %endif %changelog +* Thu Jan 23 2025 Vitezslav Crhonek - 2.7.2-14 +- Fix FTBFS with GCC 15, bin and sbin unification + * Fri Jan 17 2025 Fedora Release Engineering - 2.7.2-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 6862d70ca029052ba6bad839a5e9e18dafbe4316 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 1 Feb 2025 19:56:20 +0100 Subject: [PATCH 101/120] Add explicit BR: libxcrypt-devel MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Björn Esser --- openwsman.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 324a1dd..8f2b45e 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 14%{?dist} +Release: 15%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -67,6 +67,7 @@ BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ +BuildRequires: libxcrypt-devel %description Openwsman is a project intended to provide an open-source @@ -409,6 +410,9 @@ fi %endif %changelog +* Sat Feb 01 2025 Björn Esser - 2.7.2-15 +- Add explicit BR: libxcrypt-devel + * Thu Jan 23 2025 Vitezslav Crhonek - 2.7.2-14 - Fix FTBFS with GCC 15, bin and sbin unification From d6df136fc0005c0176c598fd3a021accfe9155d2 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 28 Feb 2025 13:34:54 +0100 Subject: [PATCH 102/120] Fix mixed use of tabs and spaces in specfile --- openwsman.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 8f2b45e..9595f66 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -67,7 +67,7 @@ BuildRequires: pkgconfig openssl-devel BuildRequires: cmake BuildRequires: systemd-units BuildRequires: gcc gcc-c++ -BuildRequires: libxcrypt-devel +BuildRequires: libxcrypt-devel %description Openwsman is a project intended to provide an open-source From 8a58111e8d2f7b1cae5794e53371be5136ad1015 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 28 Feb 2025 14:27:25 +0100 Subject: [PATCH 103/120] Update minimum required cmake version --- openwsman-2.7.2-cmake-minimum.patch | 12 ++++++++++++ openwsman.spec | 6 +++++- 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.7.2-cmake-minimum.patch diff --git a/openwsman-2.7.2-cmake-minimum.patch b/openwsman-2.7.2-cmake-minimum.patch new file mode 100644 index 0000000..fdf9a1f --- /dev/null +++ b/openwsman-2.7.2-cmake-minimum.patch @@ -0,0 +1,12 @@ +diff -up openwsman-2.7.2/CMakeLists.txt.orig openwsman-2.7.2/CMakeLists.txt +--- openwsman-2.7.2/CMakeLists.txt.orig 2025-02-28 13:39:53.472585928 +0100 ++++ openwsman-2.7.2/CMakeLists.txt 2025-02-28 13:41:25.004762276 +0100 +@@ -6,7 +6,7 @@ PROJECT(openwsman) + + # 2.6 minimum because of CMP0005 (escaping defines) + # 2.8.12 minimum because CMake 3.19.7 says so +-cmake_minimum_required(VERSION 2.8.12) ++cmake_minimum_required(VERSION 3.12) + + include(CTest) + enable_testing() diff --git a/openwsman.spec b/openwsman.spec index 9595f66..32dcc79 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.7.2 -Release: 15%{?dist} +Release: 16%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -51,6 +51,7 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-fix-ftbfs.patch Patch7: openwsman-2.7.2-gcc15-fix.patch +Patch8: openwsman-2.7.2-cmake-minimum.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -410,6 +411,9 @@ fi %endif %changelog +* Fri Feb 28 2025 Vitezslav Crhonek - 2.7.2-16 +- Update minimum required cmake version + * Sat Feb 01 2025 Björn Esser - 2.7.2-15 - Add explicit BR: libxcrypt-devel From 98cf5bcd843d02c3b246b32cc366b9a7be6da740 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 7 Apr 2025 13:38:27 +0200 Subject: [PATCH 104/120] Update to openwsman-2.8.1 --- .gitignore | 2 +- openwsman-2.4.12-ruby-binding-build.patch | 2 +- openwsman-2.6.2-openssl-1.1-fix.patch | 28 +++++++++++------------ openwsman-2.7.2-cmake-minimum.patch | 12 ---------- openwsman-2.7.2-fix-ftbfs.patch | 12 ---------- openwsman-2.7.2-gcc15-fix.patch | 18 +++++++-------- openwsman.spec | 14 +++++++----- sources | 2 +- 8 files changed, 34 insertions(+), 56 deletions(-) delete mode 100644 openwsman-2.7.2-cmake-minimum.patch delete mode 100644 openwsman-2.7.2-fix-ftbfs.patch diff --git a/.gitignore b/.gitignore index b3868d7..67bb856 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ /openwsmand.8.gz -/v2.7.2.tar.gz +/v2.8.1.tar.gz diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index eb52678..20f3b47 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -6,7 +6,7 @@ diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.7.2-build/openwsman-2.7.2/include/ -o openwsman_wrap.c openwsman.i") ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.8.1-build/openwsman-2.8.1/include -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." diff --git a/openwsman-2.6.2-openssl-1.1-fix.patch b/openwsman-2.6.2-openssl-1.1-fix.patch index 5d64644..9322adb 100644 --- a/openwsman-2.6.2-openssl-1.1-fix.patch +++ b/openwsman-2.6.2-openssl-1.1-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/src/server/shttpd/compat_unix.h ---- openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/compat_unix.h 2021-03-09 09:15:26.750942006 +0100 +diff -up openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig openwsman-2.8.1/src/server/shttpd/compat_unix.h +--- openwsman-2.8.1/src/server/shttpd/compat_unix.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/compat_unix.h 2025-02-03 09:11:35.072818890 +0100 @@ -27,10 +27,6 @@ pthread_create(&tid, NULL, (void *(*)(void *))a, c); } while (0) #endif /* !NO_THREADS */ @@ -12,9 +12,9 @@ diff -up openwsman-2.7.0/src/server/shttpd/compat_unix.h.orig openwsman-2.7.0/sr #define DIRSEP '/' #define IS_DIRSEP_CHAR(c) ((c) == '/') #define O_BINARY 0 -diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/server/shttpd/io_ssl.c ---- openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/io_ssl.c 2021-03-09 09:15:26.750942006 +0100 +diff -up openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig openwsman-2.8.1/src/server/shttpd/io_ssl.c +--- openwsman-2.8.1/src/server/shttpd/io_ssl.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/io_ssl.c 2025-02-03 09:12:22.387355905 +0100 @@ -11,28 +11,6 @@ #include "defs.h" @@ -44,10 +44,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/io_ssl.c.orig openwsman-2.7.0/src/ser void _shttpd_ssl_handshake(struct stream *stream) { -diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/server/shttpd/shttpd.c ---- openwsman-2.7.0/src/server/shttpd/shttpd.c.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/shttpd.c 2021-03-09 09:16:58.843241510 +0100 -@@ -1489,25 +1489,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch +diff -up openwsman-2.8.1/src/server/shttpd/shttpd.c.orig openwsman-2.8.1/src/server/shttpd/shttpd.c +--- openwsman-2.8.1/src/server/shttpd/shttpd.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/shttpd.c 2025-02-03 09:13:43.415562784 +0100 +@@ -1510,25 +1510,13 @@ set_ssl(struct shttpd_ctx *ctx, const ch int retval = FALSE; EC_KEY* key; @@ -73,10 +73,10 @@ diff -up openwsman-2.7.0/src/server/shttpd/shttpd.c.orig openwsman-2.7.0/src/ser + OPENSSL_init_ssl(0, NULL); if ((CTX = SSL_CTX_new(TLS_server_method())) == NULL) #endif - _shttpd_elog(E_LOG, NULL, "SSL_CTX_new error"); -diff -up openwsman-2.7.0/src/server/shttpd/ssl.h.orig openwsman-2.7.0/src/server/shttpd/ssl.h ---- openwsman-2.7.0/src/server/shttpd/ssl.h.orig 2020-05-25 15:16:28.000000000 +0200 -+++ openwsman-2.7.0/src/server/shttpd/ssl.h 2021-03-09 09:15:26.750942006 +0100 + _shttpd_report_ssl_error("SSL_CTX_new failed", NULL); +diff -up openwsman-2.8.1/src/server/shttpd/ssl.h.orig openwsman-2.8.1/src/server/shttpd/ssl.h +--- openwsman-2.8.1/src/server/shttpd/ssl.h.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/shttpd/ssl.h 2025-02-03 09:14:43.142975166 +0100 @@ -12,55 +12,4 @@ #include diff --git a/openwsman-2.7.2-cmake-minimum.patch b/openwsman-2.7.2-cmake-minimum.patch deleted file mode 100644 index fdf9a1f..0000000 --- a/openwsman-2.7.2-cmake-minimum.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.2/CMakeLists.txt.orig openwsman-2.7.2/CMakeLists.txt ---- openwsman-2.7.2/CMakeLists.txt.orig 2025-02-28 13:39:53.472585928 +0100 -+++ openwsman-2.7.2/CMakeLists.txt 2025-02-28 13:41:25.004762276 +0100 -@@ -6,7 +6,7 @@ PROJECT(openwsman) - - # 2.6 minimum because of CMP0005 (escaping defines) - # 2.8.12 minimum because CMake 3.19.7 says so --cmake_minimum_required(VERSION 2.8.12) -+cmake_minimum_required(VERSION 3.12) - - include(CTest) - enable_testing() diff --git a/openwsman-2.7.2-fix-ftbfs.patch b/openwsman-2.7.2-fix-ftbfs.patch deleted file mode 100644 index b30b3cf..0000000 --- a/openwsman-2.7.2-fix-ftbfs.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -up openwsman-2.7.2/bindings/openwsman.i.orig openwsman-2.7.2/bindings/openwsman.i ---- openwsman-2.7.2/bindings/openwsman.i.orig 2024-01-22 09:36:42.764721705 +0100 -+++ openwsman-2.7.2/bindings/openwsman.i 2024-01-22 09:37:29.970817151 +0100 -@@ -109,7 +109,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S - - %typemap(in) FILE* { - #if RUBY_VERSION > 18 -- struct rb_io_t *fptr; -+ struct rb_io *fptr; - #else - struct OpenFile *fptr; - #endif diff --git a/openwsman-2.7.2-gcc15-fix.patch b/openwsman-2.7.2-gcc15-fix.patch index 6dc4078..590ff14 100644 --- a/openwsman-2.7.2-gcc15-fix.patch +++ b/openwsman-2.7.2-gcc15-fix.patch @@ -1,6 +1,6 @@ -diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2/src/plugins/swig/src/target_ruby.c ---- openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/src/plugins/swig/src/target_ruby.c 2025-01-23 11:53:58.082946042 +0100 +diff -up openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig openwsman-2.8.1/src/plugins/swig/src/target_ruby.c +--- openwsman-2.8.1/src/plugins/swig/src/target_ruby.c.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/plugins/swig/src/target_ruby.c 2025-02-03 09:30:36.905616375 +0100 @@ -49,7 +49,7 @@ */ @@ -10,12 +10,12 @@ diff -up openwsman-2.7.2/src/plugins/swig/src/target_ruby.c.orig openwsman-2.7.2 { ruby_script(PLUGIN_FILE); return rb_require(PLUGIN_FILE); -diff -up openwsman-2.7.2/src/server/CMakeLists.txt.orig openwsman-2.7.2/src/server/CMakeLists.txt ---- openwsman-2.7.2/src/server/CMakeLists.txt.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/src/server/CMakeLists.txt 2025-01-23 12:08:44.042639395 +0100 -@@ -47,7 +47,7 @@ if( HAVE_LIBDL ) - TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) - endif( HAVE_LIBDL ) +diff -up openwsman-2.8.1/src/server/CMakeLists.txt.orig openwsman-2.8.1/src/server/CMakeLists.txt +--- openwsman-2.8.1/src/server/CMakeLists.txt.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/src/server/CMakeLists.txt 2025-02-03 09:31:15.258241237 +0100 +@@ -48,7 +48,7 @@ IF( HAVE_LIBDL ) + TARGET_LINK_LIBRARIES(openwsmand ${DL_LIBRARIES}) + ENDIF( HAVE_LIBDL ) -INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/sbin) +INSTALL(TARGETS openwsmand DESTINATION ${CMAKE_INSTALL_PREFIX}/bin) diff --git a/openwsman.spec b/openwsman.spec index 32dcc79..c65645f 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -18,14 +18,14 @@ %global with_perl 0 %global with_python 0 %else -%global with_ruby 1 +%global with_ruby 0 %global with_perl 1 %global with_python 1 %endif Name: openwsman -Version: 2.7.2 -Release: 16%{?dist} +Version: 2.8.1 +Release: 1%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -49,9 +49,7 @@ Patch2: openwsman-2.4.12-ruby-binding-build.patch Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch -Patch6: openwsman-2.7.2-fix-ftbfs.patch -Patch7: openwsman-2.7.2-gcc15-fix.patch -Patch8: openwsman-2.7.2-cmake-minimum.patch +Patch6: openwsman-2.7.2-gcc15-fix.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -260,6 +258,7 @@ rm -f %{buildroot}/%{_libdir}/openwsman/plugins/*.la rm -f %{buildroot}/%{_libdir}/openwsman/authenticators/*.la %if %{with_ruby} [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsmanplugin.rb +[ -d %{buildroot}/%{ruby_sitelibdir} ] && rm -f %{buildroot}/%{ruby_sitelibdir}/openwsmanplugin.rb [ -d %{buildroot}/%{ruby_vendorlibdir} ] && rm -f %{buildroot}/%{ruby_vendorlibdir}/openwsman.rb %endif mkdir -p %{buildroot}%{_sysconfdir}/init.d @@ -411,6 +410,9 @@ fi %endif %changelog +* Mon Apr 07 2025 Vitezslav Crhonek - 2.8.1-1 +- Update to openwsman-2.8.1 + * Fri Feb 28 2025 Vitezslav Crhonek - 2.7.2-16 - Update minimum required cmake version diff --git a/sources b/sources index 250b1fa..383285d 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (openwsmand.8.gz) = 751c40060781e8b5a847e09aee94833ed1e4fbe966f052e5023cb209361acc312078d0d75c0806bd9990da061d3048566418135d3670dd620c6b809e5d0e594c -SHA512 (v2.7.2.tar.gz) = ffd6a0d00a00b00e321b2b55e0c77326f5943ca3224eee74c706e53a1c5c44ef0e8b1cfde5d631966769eefd4e567b0db8713085b7a8b386c2871ab4ada83046 +SHA512 (v2.8.1.tar.gz) = 3c72b6778269186108e48203a9c37f1e4ea8ff532013a80be6af3c6e8d2bf89343233287bc4eb2e955b8db4b7cf6d20818f77423781f6fdb52a6317a7e8bc972 From 47117d833d7268863141dea9d0195dfccad99c43 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 10 Apr 2025 14:31:06 +0200 Subject: [PATCH 105/120] Build winrs only when ruby binding is enabled --- openwsman.spec | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c65645f..c7908dd 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -162,6 +162,7 @@ Requires: libwsman1 = %{version}-%{release} This package provides Perl bindings to access the openwsman client API. %endif +%if %{with_ruby} %package winrs Summary: Windows Remote Shell Requires: rubygem-%{gem_name} = %{version}-%{release} @@ -169,6 +170,7 @@ Requires: rubygem-%{gem_name} = %{version}-%{release} %description winrs This is a command line tool for the Windows Remote Shell protocol. You can use it to send shell commands to a remote Windows hosts. +%endif %if 0%{?with_selinux} # SELinux subpackage @@ -285,6 +287,8 @@ rm -rf %{buildroot}%{gem_instdir}/ext mkdir -p %{buildroot}%{gem_extdir_mri} cp -a ./build%{gem_extdir_mri}/{gem.build_complete,*.so} %{buildroot}%{gem_extdir_mri}/ +%else +rm -f %{buildroot}%{_bindir}/winrs %endif %if 0%{?with_selinux} @@ -399,8 +403,10 @@ fi %{_libdir}/libwsman_clientpp.so.* %config(noreplace) %{_sysconfdir}/openwsman/openwsman_client.conf +%if %{with_ruby} %files winrs %{_bindir}/winrs +%endif %if 0%{?with_selinux} %files selinux @@ -410,6 +416,9 @@ fi %endif %changelog +* Thu Apr 10 2025 Vitezslav Crhonek - 2.8.1-2 +- Build winrs only when ruby binding is enabled + * Mon Apr 07 2025 Vitezslav Crhonek - 2.8.1-1 - Update to openwsman-2.8.1 From d5b12f392fafe0e0de8069239e86fdb473e83091 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Tue, 3 Jun 2025 12:20:17 +0200 Subject: [PATCH 106/120] Rebuilt for Python 3.14 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index c7908dd..d06a310 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Tue Jun 03 2025 Python Maint - 2.8.1-3 +- Rebuilt for Python 3.14 + * Thu Apr 10 2025 Vitezslav Crhonek - 2.8.1-2 - Build winrs only when ruby binding is enabled From e7504d677c87dbfc2f265ab5a9b4c55081e414a7 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 9 Jun 2025 09:49:40 +0200 Subject: [PATCH 107/120] Remove deprecated path from systemd service file --- openwsman.spec | 5 ++++- openwsmand.service | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index d06a310..62b8780 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Mon Jun 09 2025 Vitezslav Crhonek - 2.8.1-4 +- Remove deprecated path from systemd service file + * Tue Jun 03 2025 Python Maint - 2.8.1-3 - Rebuilt for Python 3.14 diff --git a/openwsmand.service b/openwsmand.service index e10c75d..a42b11f 100644 --- a/openwsmand.service +++ b/openwsmand.service @@ -6,7 +6,7 @@ After=syslog.target Type=forking ExecStart=/usr/sbin/openwsmand -S ExecStartPre=/etc/openwsman/owsmantestcert.sh -PIDFile=/var/run/wsmand.pid +PIDFile=/run/wsmand.pid [Install] WantedBy=multi-user.target From a15c71912aa31e8269192ba6bdd8b614ba050f69 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Mon, 9 Jun 2025 11:44:53 +0200 Subject: [PATCH 108/120] Rebuilt for Python 3.14 --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 62b8780..9d8e2d7 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -416,6 +416,9 @@ fi %endif %changelog +* Mon Jun 09 2025 Python Maint - 2.8.1-5 +- Rebuilt for Python 3.14 + * Mon Jun 09 2025 Vitezslav Crhonek - 2.8.1-4 - Remove deprecated path from systemd service file From f7085bf7cf35c7c94ffcd5c48af2167645c36911 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 17 Jun 2025 14:40:11 +0200 Subject: [PATCH 109/120] Update to better support post-quantum cryptography --- openwsman-2.8.1-post-quantum.patch | 101 +++++++++++++++++++++++++++++ openwsman.spec | 6 +- 2 files changed, 106 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.8.1-post-quantum.patch diff --git a/openwsman-2.8.1-post-quantum.patch b/openwsman-2.8.1-post-quantum.patch new file mode 100644 index 0000000..0b9b7bb --- /dev/null +++ b/openwsman-2.8.1-post-quantum.patch @@ -0,0 +1,101 @@ +diff -up openwsman-2.7.2/etc/openwsman.conf.orig openwsman-2.7.2/etc/openwsman.conf +--- openwsman-2.7.2/etc/openwsman.conf.orig 2022-12-28 16:43:03.000000000 +0100 ++++ openwsman-2.7.2/etc/openwsman.conf 2025-05-27 08:03:57.890057721 +0200 +@@ -32,8 +32,12 @@ ipv6 = yes + + # the openwsman server certificate file, in .pem format + ssl_cert_file = /etc/openwsman/servercert.pem ++# the openwsman server certificate fallback file, in .pem format ++#ssl_cert_fallback_file = /etc/openwsman/servercert-fallback.pem + # the openwsman server private key, in .pem format + ssl_key_file = /etc/openwsman/serverkey.pem ++# the openwsman server private key fallback, in .pem format ++#ssl_key_fallback_file = /etc/openwsman/serverkey-fallback.pem + + # space-separated list of SSL protocols to *dis*able + # possible values: SSLv2 SSLv3 TLSv1 TLSv1_1 TLSv1_2 +diff -up openwsman-2.7.2/src/server/shttpd/shttpd.c.orig openwsman-2.7.2/src/server/shttpd/shttpd.c +--- openwsman-2.7.2/src/server/shttpd/shttpd.c.orig 2025-05-21 10:07:40.404532496 +0200 ++++ openwsman-2.7.2/src/server/shttpd/shttpd.c 2025-06-12 12:27:44.785904555 +0200 +@@ -1491,7 +1491,6 @@ set_ssl(struct shttpd_ctx *ctx, const ch + char *ssl_disabled_protocols = wsmand_options_get_ssl_disabled_protocols(); + char *ssl_cipher_list = wsmand_options_get_ssl_cipher_list(); + int retval = FALSE; +- EC_KEY* key; + + /* Initialize SSL crap */ + +@@ -1510,11 +1509,15 @@ set_ssl(struct shttpd_ctx *ctx, const ch + else + retval = TRUE; + +- /* This enables ECDH Perfect Forward secrecy. Currently with just the most generic p256 prime curve */ +- key = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); +- if (key != NULL) { +- SSL_CTX_set_tmp_ecdh(CTX, key); +- EC_KEY_free(key); ++ /* Add fall back certificate/key pair */ ++ if (wsmand_options_get_ssl_cert_fallback_file() && ++ wsmand_options_get_ssl_key_fallback_file()) { ++ if (SSL_CTX_use_certificate_file(CTX, wsmand_options_get_ssl_cert_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open certificate fallback file %s", pem); ++ else if (SSL_CTX_use_PrivateKey_file(CTX, wsmand_options_get_ssl_key_fallback_file(), SSL_FILETYPE_PEM) != 1) ++ _shttpd_elog(E_LOG, NULL, "cannot open fallback PrivateKey %s", pem); ++ else ++ retval = TRUE; + } + + while (ssl_disabled_protocols) { +diff -up openwsman-2.7.2/src/server/wsmand-daemon.c.orig openwsman-2.7.2/src/server/wsmand-daemon.c +--- openwsman-2.7.2/src/server/wsmand-daemon.c.orig 2025-05-27 07:18:16.878974761 +0200 ++++ openwsman-2.7.2/src/server/wsmand-daemon.c 2025-05-27 07:22:06.832235764 +0200 +@@ -76,8 +76,10 @@ static int use_ipv6 = 0; + #endif + static int use_digest = 0; + static char *ssl_key_file = NULL; ++static char *ssl_key_fallback_file = NULL; + static char *service_path = DEFAULT_SERVICE_PATH; + static char *ssl_cert_file = NULL; ++static char *ssl_cert_fallback_file = NULL; + static char *ssl_disabled_protocols = NULL; + static char *ssl_cipher_list = NULL; + static char *pid_file = DEFAULT_PID_PATH; +@@ -186,7 +188,9 @@ int wsmand_read_config(dictionary * ini) + service_path = + iniparser_getstring(ini, "server:service_path", "/wsman"); + ssl_key_file = iniparser_getstr(ini, "server:ssl_key_file"); ++ ssl_key_fallback_file = iniparser_getstr(ini, "server:ssl_key_fallback_file"); + ssl_cert_file = iniparser_getstr(ini, "server:ssl_cert_file"); ++ ssl_cert_fallback_file = iniparser_getstr(ini, "server:ssl_cert_fallback_file"); + ssl_disabled_protocols = iniparser_getstr(ini, "server:ssl_disabled_protocols"); + ssl_cipher_list = iniparser_getstr(ini, "server:ssl_cipher_list"); + use_ipv4 = iniparser_getboolean(ini, "server:ipv4", 1); +@@ -364,6 +368,16 @@ char *wsmand_options_get_ssl_cert_file(v + return ssl_cert_file; + } + ++char *wsmand_options_get_ssl_key_fallback_file(void) ++{ ++ return ssl_key_fallback_file; ++} ++ ++char *wsmand_options_get_ssl_cert_fallback_file(void) ++{ ++ return ssl_cert_fallback_file; ++} ++ + char *wsmand_options_get_ssl_disabled_protocols(void) + { + return ssl_disabled_protocols; +diff -up openwsman-2.7.2/src/server/wsmand-daemon.h.orig openwsman-2.7.2/src/server/wsmand-daemon.h +--- openwsman-2.7.2/src/server/wsmand-daemon.h.orig 2025-05-27 07:15:56.869002037 +0200 ++++ openwsman-2.7.2/src/server/wsmand-daemon.h 2025-05-27 07:18:06.429846617 +0200 +@@ -76,6 +76,8 @@ int wsmand_options_get_server_port(void) + int wsmand_options_get_server_ssl_port(void); + char *wsmand_options_get_ssl_key_file(void); + char *wsmand_options_get_ssl_cert_file(void); ++char *wsmand_options_get_ssl_key_fallback_file(void); ++char *wsmand_options_get_ssl_cert_fallback_file(void); + char *wsmand_options_get_ssl_disabled_protocols(void); + char *wsmand_options_get_ssl_cipher_list(void); + int wsmand_options_get_digest(void); diff --git a/openwsman.spec b/openwsman.spec index 9d8e2d7..7ce8a06 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -50,6 +50,7 @@ Patch3: openwsman-2.6.2-openssl-1.1-fix.patch Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-gcc15-fix.patch +Patch7: openwsman-2.8.1-post-quantum.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -416,6 +417,9 @@ fi %endif %changelog +* Tue Jun 17 2025 Vitezslav Crhonek - 2.8.1-6 +- Update to better support post-quantum cryptography + * Mon Jun 09 2025 Python Maint - 2.8.1-5 - Rebuilt for Python 3.14 From 94e2a92bdcd11a2fe8863ca28cf16d610891a585 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Tue, 17 Jun 2025 14:42:02 +0200 Subject: [PATCH 110/120] Add post-quantum support test --- .fmf/version | 1 + plans/basic.fmf | 9 +++ tests/post-quantum-cryptography/main.fmf | 6 ++ tests/post-quantum-cryptography/runtest.sh | 92 ++++++++++++++++++++++ 4 files changed, 108 insertions(+) create mode 100644 .fmf/version create mode 100644 plans/basic.fmf create mode 100644 tests/post-quantum-cryptography/main.fmf create mode 100755 tests/post-quantum-cryptography/runtest.sh diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/plans/basic.fmf b/plans/basic.fmf new file mode 100644 index 0000000..efb100f --- /dev/null +++ b/plans/basic.fmf @@ -0,0 +1,9 @@ +summary: Basic test plan +prepare: + how: install + package: + - openwsman-server +discover: + how: fmf +execute: + how: tmt diff --git a/tests/post-quantum-cryptography/main.fmf b/tests/post-quantum-cryptography/main.fmf new file mode 100644 index 0000000..51ba4e2 --- /dev/null +++ b/tests/post-quantum-cryptography/main.fmf @@ -0,0 +1,6 @@ +summary: Post-quantum cryptography support test +author: Vitezslav Crhonek +contact: Vitezslav Crhonek +require: patch +duration: 10m +test: ./runtest.sh diff --git a/tests/post-quantum-cryptography/runtest.sh b/tests/post-quantum-cryptography/runtest.sh new file mode 100755 index 0000000..6588a8a --- /dev/null +++ b/tests/post-quantum-cryptography/runtest.sh @@ -0,0 +1,92 @@ +#!/bin/sh -eux + +function check_key_and_cert() +{ + echo -e "\n===== key info" + ssh-keygen -l -f /etc/openwsman/serverkey.pem || : + file /etc/openwsman/serverkey.pem + echo -e "\n\n\n" + + echo -e "\n===== cert info" + openssl x509 -in /etc/openwsman/servercert.pem --text --noout + echo -e "\n\n\n" +} + +function test_key_exchange() +{ + echo -e "\n===== check that it uses TLS 1.3 and the X25519MLKEM768 key exchange by default if the peer supports it" + openssl s_client -connect localhost:5986 -CAfile /etc/openwsman/servercert.pem Date: Tue, 24 Jun 2025 10:38:48 +0200 Subject: [PATCH 111/120] Remove STI DSP test --- tests/tests-DSP.yml | 37 ------------------------------------- 1 file changed, 37 deletions(-) delete mode 100644 tests/tests-DSP.yml diff --git a/tests/tests-DSP.yml b/tests/tests-DSP.yml deleted file mode 100644 index ec2c494..0000000 --- a/tests/tests-DSP.yml +++ /dev/null @@ -1,37 +0,0 @@ -- hosts: localhost - - roles: - - role: standard-test-beakerlib - tags: - - classic - repositories: - - repo: https://pagure.io/DSP_test.git - dest: DSP_test - version: master - - tests: - - DSP_test - environment: - # RPM package containing the policy module - TEST_RPM: openwsman-selinux - # policy module name - TEST_POLICY: openwsman - # policy sources will be extracted from corresponding .src.rpm - # policy tar filename regexp (e.g. "usbguard-selinux*.tar.gz") - # or empty string if policy sources are not inside a tar archive - POLICY_TAR: '' - # path to policy sources (in of the tar archive) -- //.(te|if|fc) - # or path in the src.rpm if there is no tar archive -- //.(te|if|fc) - # can contain wildcards (e.g. for versions etc.) - POLICY_PATH: . - - required_packages: - - policycoreutils - - selinux-policy - - selinux-policy-targeted - - setools-console - - libselinux-utils - - rpm - - tar - - git - - openwsman-server From f8a5615d0ad53945db9edbf18c29ab56e1247880 Mon Sep 17 00:00:00 2001 From: Jitka Plesnikova Date: Mon, 7 Jul 2025 16:23:01 +0200 Subject: [PATCH 112/120] Perl 5.42 rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 7ce8a06..77b2ec0 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Mon Jul 07 2025 Jitka Plesnikova - 2.8.1-7 +- Perl 5.42 rebuild + * Tue Jun 17 2025 Vitezslav Crhonek - 2.8.1-6 - Update to better support post-quantum cryptography From 3b4a6e4ac53232d1ef88c8e95110dc5cf364fae4 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 24 Jul 2025 23:42:46 +0000 Subject: [PATCH 113/120] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 77b2ec0..4f09c46 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 2.8.1-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Mon Jul 07 2025 Jitka Plesnikova - 2.8.1-7 - Perl 5.42 rebuild From c6d83b0c57be70794cbfcb98b10ded1610c65c01 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 15 Aug 2025 13:04:34 +0200 Subject: [PATCH 114/120] Rebuilt for Python 3.14.0rc2 bytecode --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 4f09c46..149923b 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Fri Aug 15 2025 Python Maint - 2.8.1-9 +- Rebuilt for Python 3.14.0rc2 bytecode + * Thu Jul 24 2025 Fedora Release Engineering - 2.8.1-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 655676c16c7012056ab76cecd4beedffb4f0cdb8 Mon Sep 17 00:00:00 2001 From: Python Maint Date: Fri, 19 Sep 2025 12:35:09 +0200 Subject: [PATCH 115/120] Rebuilt for Python 3.14.0rc3 bytecode --- openwsman.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/openwsman.spec b/openwsman.spec index 149923b..299a0bc 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -417,6 +417,9 @@ fi %endif %changelog +* Fri Sep 19 2025 Python Maint - 2.8.1-10 +- Rebuilt for Python 3.14.0rc3 bytecode + * Fri Aug 15 2025 Python Maint - 2.8.1-9 - Rebuilt for Python 3.14.0rc2 bytecode From d198b44b1b7f3d1d0472568ab78b41937bfac83c Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Wed, 12 Nov 2025 07:56:03 +0100 Subject: [PATCH 116/120] Update OpenSSL certificates set up, fix and enable ruby binding again --- openwsman-2.4.12-ruby-binding-build.patch | 71 +++++++++++++- openwsman-2.7.2-ssl-certs-gen-changes.patch | 102 ++++++++++++++++++++ openwsman-2.8.1-fix-ruby-io.patch | 33 +++++++ openwsman-2.8.1-rdoc-ruby34.patch | 29 ++++++ openwsman.spec | 11 ++- 5 files changed, 239 insertions(+), 7 deletions(-) create mode 100644 openwsman-2.7.2-ssl-certs-gen-changes.patch create mode 100644 openwsman-2.8.1-fix-ruby-io.patch create mode 100644 openwsman-2.8.1-rdoc-ruby34.patch diff --git a/openwsman-2.4.12-ruby-binding-build.patch b/openwsman-2.4.12-ruby-binding-build.patch index 20f3b47..2c2e25b 100644 --- a/openwsman-2.4.12-ruby-binding-build.patch +++ b/openwsman-2.4.12-ruby-binding-build.patch @@ -1,12 +1,73 @@ -diff -up openwsman-2.7.2/bindings/ruby/extconf.rb.orig openwsman-2.7.2/bindings/ruby/extconf.rb ---- openwsman-2.7.2/bindings/ruby/extconf.rb.orig 2022-12-28 16:43:03.000000000 +0100 -+++ openwsman-2.7.2/bindings/ruby/extconf.rb 2023-08-09 12:50:21.361216733 +0200 -@@ -32,7 +32,7 @@ swig = find_executable("swig") +--- openwsman-2.8.1/bindings/ruby/extconf.rb.orig 2025-11-11 11:49:59.880195434 +0100 ++++ openwsman-2.8.1/bindings/ruby/extconf.rb 2025-11-11 11:50:46.870685458 +0100 +@@ -5,20 +5,41 @@ + require 'mkmf' + # $CFLAGS = "#{$CFLAGS} -Werror" + ++# libwsman requires 'int facility' to be defined by the application ++# Add syslog.h for LOG_DAEMON constant ++$CFLAGS = "#{$CFLAGS} -include syslog.h" ++ + # requires wsman, wsman_client, and libxml2 ++# Use CPATH and LIBRARY_PATH environment variables set by the build system ++if ENV['CPATH'] ++ ENV['CPATH'].split(':').each do |path| ++ $CPPFLAGS = "#{$CPPFLAGS} -I#{path}" ++ end ++end ++if ENV['LIBRARY_PATH'] ++ ENV['LIBRARY_PATH'].split(':').each do |path| ++ $LDFLAGS = "#{$LDFLAGS} -L#{path}" ++ end ++end + +-unless have_library('wsman', 'wsman_create_doc') ++# Custom test for libwsman that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsman_create_doc(\"test\");\n return 0;\n}", '-lwsman') + STDERR.puts "Cannot find wsman_create_doc() in libwsman" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 + end ++# Explicitly add libwsman to linker flags since we used try_link instead of have_library ++$libs = append_library($libs, "wsman") + find_header 'wsman-xml-api.h', '/usr/include/openwsman' + +-unless have_library('wsman_client', 'wsmc_create') ++# Custom test for libwsman_client that includes facility definition ++unless try_link("#include \n#include \nint facility = LOG_DAEMON;\nint main() {\n wsmc_create(\"localhost\", 80, \"/wsman\", \"http\", \"user\", \"pass\");\n return 0;\n}", '-lwsman_client -lwsman') + STDERR.puts "Cannot find wsmc_create() in libwsman_client" + STDERR.puts "Is openwsman-devel installed ?" + exit 1 + end ++# Explicitly add libwsman_client to linker flags since we used try_link instead of have_library ++$libs = append_library($libs, "wsman_client") + find_header 'wsman-client-api.h', '/usr/include/openwsman' + + unless have_library('xml2', 'xmlNewDoc') +@@ -28,12 +49,25 @@ + end + find_header 'libxml/parser.h', '/usr/include/libxml2' + ++# Check for Ruby 3.3+ IO types ++have_type('rb_io_t', 'ruby/io.h') ++have_header 'ruby/thread.h' ++ + swig = find_executable("swig") raise "SWIG not found" unless swig major, minor, path = RUBY_VERSION.split(".") -raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -o openwsman_wrap.c openwsman.i") -+raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} -I. -I/usr/include/openwsman -I/builddir/build/BUILD/openwsman-2.8.1-build/openwsman-2.8.1/include -o openwsman_wrap.c openwsman.i") ++ ++# Build SWIG include paths from CPATH environment variable ++swig_includes = "-I. -I/usr/include/openwsman" ++if ENV['CPATH'] ++ ENV['CPATH'].split(':').each do |path| ++ swig_includes += " -I#{path}" ++ end ++end ++raise "SWIG failed to run" unless system("#{swig} -ruby -autorename -DRUBY_VERSION=#{major}#{minor} #{swig_includes} -o openwsman_wrap.c openwsman.i") $CPPFLAGS = "-I/usr/include/openwsman -I.." + create_makefile('_openwsman') ++ diff --git a/openwsman-2.7.2-ssl-certs-gen-changes.patch b/openwsman-2.7.2-ssl-certs-gen-changes.patch new file mode 100644 index 0000000..11de1d5 --- /dev/null +++ b/openwsman-2.7.2-ssl-certs-gen-changes.patch @@ -0,0 +1,102 @@ +diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/owsmangencert.sh.cmake +--- openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/etc/owsmangencert.sh.cmake 2025-10-17 10:16:34.482996406 +0200 +@@ -1,10 +1,74 @@ +-#!/bin/sh +- + #!/bin/sh -e + + CERTFILE=@WSMANCONF_DIR@/servercert.pem + KEYFILE=@WSMANCONF_DIR@/serverkey.pem + CNFFILE=@WSMANCONF_DIR@/ssleay.cnf ++CAFILE=@WSMANCONF_DIR@/ca.crt ++DAYS=365 ++ ++function create_ssl_cnf ++{ ++ # Get minimum RSA key length at current security level ++ # This workarounds openssl not enforcing min. key length enforced by current security level ++ KEYSIZE=`grep min_rsa_size /etc/crypto-policies/state/CURRENT.pol | cut -d ' ' -f 3` ++ ++ # Create OpenSSL configuration files for generating certificates ++ echo "[ req ]" > $CNFFILE ++ echo "default_bits = $KEYSIZE" >> $CNFFILE ++ echo "default_keyfile = privkey.pem" >> $CNFFILE ++ echo "distinguished_name = req_distinguished_name" >> $CNFFILE ++ ++ echo "[ req_distinguished_name ]" >> $CNFFILE ++ echo "countryName = Country Name (2 letter code)" >> $CNFFILE ++ echo "countryName_default = GB" >> $CNFFILE ++ echo "countryName_min = 2" >> $CNFFILE ++ echo "countryName_max = 2" >> $CNFFILE ++ ++ echo "stateOrProvinceName = State or Province Name (full name)" >> $CNFFILE ++ echo "stateOrProvinceName_default = Some-State" >> $CNFFILE ++ ++ echo "localityName = Locality Name (eg, city)" >> $CNFFILE ++ ++ echo "organizationName = Organization Name (eg, company; recommended)" >> $CNFFILE ++ echo "organizationName_max = 64" >> $CNFFILE ++ ++ echo "organizationalUnitName = Organizational Unit Name (eg, section)" >> $CNFFILE ++ echo "organizationalUnitName_max = 64" >> $CNFFILE ++ ++ echo "commonName = server name (eg. ssl.domain.tld; required!!!)" >> $CNFFILE ++ echo "commonName_max = 80" >> $CNFFILE ++ ++ echo "emailAddress = Email Address" >> $CNFFILE ++ echo "emailAddress_max = 85" >> $CNFFILE ++} ++ ++function selfsign_sscg() ++{ ++ sscg --quiet \ ++ --lifetime "${DAYS}" \ ++ --cert-key-file "${KEYFILE}" \ ++ --cert-file "${CERTFILE}" \ ++ --ca-file "${CAFILE}" ++} ++ ++function selfsign_openssl() ++{ ++ ++ echo ++ echo creating selfsigned certificate ++ echo "replace it with one signed by a certification authority (CA)" ++ echo ++ echo enter your ServerName at the Common Name prompt ++ echo ++ ++ # use special .cnf, because with normal one no valid selfsigned ++ # certificate is created ++ ++ openssl req -days $DAYS $@ -config $CNFFILE \ ++ -new -x509 -nodes -out $CERTFILE \ ++ -keyout $KEYFILE ++ chmod 600 $KEYFILE ++} + + if [ "$1" != "--force" -a -f $KEYFILE ]; then + echo "$KEYFILE exists! Use \"$0 --force.\"" +@@ -15,18 +79,7 @@ if [ "$1" = "--force" ]; then + shift + fi + +-echo +-echo creating selfsigned certificate +-echo "replace it with one signed by a certification authority (CA)" +-echo +-echo enter your ServerName at the Common Name prompt +-echo +- +-# use special .cnf, because with normal one no valid selfsigned +-# certificate is created +- +-openssl req -days 365 $@ -config $CNFFILE \ +- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ +- -keyout $KEYFILE +-chmod 600 $KEYFILE ++create_ssl_cnf + ++# If sscg fails, try openssl ++selfsign_sscg || selfsign_openssl diff --git a/openwsman-2.8.1-fix-ruby-io.patch b/openwsman-2.8.1-fix-ruby-io.patch new file mode 100644 index 0000000..605bf91 --- /dev/null +++ b/openwsman-2.8.1-fix-ruby-io.patch @@ -0,0 +1,33 @@ +diff -up openwsman-2.8.1/bindings/openwsman.i.orig openwsman-2.8.1/bindings/openwsman.i +--- openwsman-2.8.1/bindings/openwsman.i.orig 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/bindings/openwsman.i 2025-10-21 16:56:01.025576984 +0200 +@@ -105,15 +105,8 @@ SWIGINTERNINLINE SV *SWIG_From_double S + #if HAVE_RUBY_THREAD_H /* New threading model */ + #include + #endif +-#if RUBY_VERSION > 18 +- #if HAVE_RB_IO_T +- #define rb_fptr_t rb_io_t +- #else +- #define rb_fptr_t struct rb_io +- #endif +-#else +- #define rb_fptr_t struct OpenFile +-#endif ++/* Use rb_io_t for Ruby 1.9+ */ ++#define rb_fptr_t rb_io_t + %} + + %typemap(in) FILE* { +@@ -122,11 +115,7 @@ SWIGINTERNINLINE SV *SWIG_From_double S + Check_Type($input, T_FILE); + GetOpenFile($input, fptr); + /*rb_io_check_writable(fptr);*/ +-#if RUBY_VERSION > 18 + $1 = rb_io_stdio_file(fptr); +-#else +- $1 = GetReadFile(fptr); +-#endif + } + + #endif /* SWIGRUBY */ diff --git a/openwsman-2.8.1-rdoc-ruby34.patch b/openwsman-2.8.1-rdoc-ruby34.patch new file mode 100644 index 0000000..de30428 --- /dev/null +++ b/openwsman-2.8.1-rdoc-ruby34.patch @@ -0,0 +1,29 @@ +--- openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-01-23 10:23:52.000000000 +0100 ++++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2025-11-10 15:00:00.000000000 +0100 +@@ -108,10 +108,24 @@ class RDoc::Parser::SWIG < RDoc::Parser + ## + # Prepare to parse a SWIG file + +- def initialize(top_level, file_name, content, options, stats) +- super ++ def initialize(top_level, file_name, content, options, stats = nil) ++ # RDoc 6.6+ (Ruby 3.3+) removed the stats parameter from Parser.initialize ++ # Check the arity of the parent class initialize method to determine which API we're using ++ parent_arity = RDoc::Parser.instance_method(:initialize).arity ++ ++ if parent_arity == 4 || parent_arity == -5 ++ # RDoc 6.6+: only pass 4 arguments to super ++ super(top_level, file_name, content, options) ++ # Create a dummy stats object for compatibility ++ @stats = Object.new ++ def @stats.method_missing(m, *args); end ++ else ++ # Older RDoc: pass all 5 arguments including stats ++ super(top_level, file_name, content, options, stats) ++ @stats = stats ++ end + + @known_classes = RDoc::KNOWN_CLASSES.dup + @content = handle_tab_width handle_ifdefs_in(@content) + @renames = {} # maps old_name => [ new_name, args ] + @aliases = {} # maps name => [ alias_name, args ] diff --git a/openwsman.spec b/openwsman.spec index 299a0bc..9fb5371 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -18,14 +18,14 @@ %global with_perl 0 %global with_python 0 %else -%global with_ruby 0 +%global with_ruby 1 %global with_perl 1 %global with_python 1 %endif Name: openwsman Version: 2.8.1 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -51,6 +51,9 @@ Patch4: openwsman-2.6.5-http-status-line.patch Patch5: openwsman-2.6.8-update-ssleay-conf.patch Patch6: openwsman-2.7.2-gcc15-fix.patch Patch7: openwsman-2.8.1-post-quantum.patch +Patch8: openwsman-2.7.2-ssl-certs-gen-changes.patch +Patch9: openwsman-2.8.1-rdoc-ruby34.patch +Patch10: openwsman-2.8.1-fix-ruby-io.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -417,6 +420,10 @@ fi %endif %changelog +* Wed Nov 12 2025 Vitezslav Crhonek - 2.8.1-11 +- Update OpenSSL certificates set up +- Fix ruby binding, enable it + * Fri Sep 19 2025 Python Maint - 2.8.1-10 - Rebuilt for Python 3.14.0rc3 bytecode From 7df5ef0bbeedb5eecf13cc015b4dc78b283f6d19 Mon Sep 17 00:00:00 2001 From: Mamoru TASAKA Date: Sat, 3 Jan 2026 09:58:06 +0900 Subject: [PATCH 117/120] Support rdoc 6.16 and above (for ruby4.0) --- openwsman-2.8.1-rdoc-6_16.patch | 18 ++++++++++++++++++ openwsman.spec | 6 +++++- 2 files changed, 23 insertions(+), 1 deletion(-) create mode 100644 openwsman-2.8.1-rdoc-6_16.patch diff --git a/openwsman-2.8.1-rdoc-6_16.patch b/openwsman-2.8.1-rdoc-6_16.patch new file mode 100644 index 0000000..c0dc8b4 --- /dev/null +++ b/openwsman-2.8.1-rdoc-6_16.patch @@ -0,0 +1,18 @@ +diff -urp '--exclude=*~' openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb +--- openwsman-2.8.1.orig/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:43:41.804273994 +0900 ++++ openwsman-2.8.1/bindings/ruby/rdoc_parser_swig.rb 2026-01-02 23:56:06.991238037 +0900 +@@ -377,7 +377,13 @@ class RDoc::Parser::SWIG < RDoc::Parser + find_modifiers comment, meth_obj if comment + + #meth_obj.params = params +- meth_obj.start_collecting_tokens ++ # https://github.com/ruby/rdoc/pull/1471 changes the parameter for ++ # RDoc::TokenStream.start_collecting_tokens ++ if meth_obj.method(:start_collecting_tokens).arity == 1 ++ meth_obj.start_collecting_tokens :ruby ++ else ++ meth_obj.start_collecting_tokens ++ end + begin + RDoc::const_get "RubyToken" + tk = RDoc::RubyToken::Token.new nil, 1, 1 diff --git a/openwsman.spec b/openwsman.spec index 9fb5371..94298f8 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -54,6 +54,7 @@ Patch7: openwsman-2.8.1-post-quantum.patch Patch8: openwsman-2.7.2-ssl-certs-gen-changes.patch Patch9: openwsman-2.8.1-rdoc-ruby34.patch Patch10: openwsman-2.8.1-fix-ruby-io.patch +Patch11: openwsman-2.8.1-rdoc-6_16.patch BuildRequires: make BuildRequires: swig BuildRequires: libcurl-devel libxml2-devel pam-devel sblim-sfcc-devel @@ -420,6 +421,9 @@ fi %endif %changelog +* Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 +- Support rdoc 6.16 and above (for ruby4.0) + * Wed Nov 12 2025 Vitezslav Crhonek - 2.8.1-11 - Update OpenSSL certificates set up - Fix ruby binding, enable it From 724b68ff8066812f071e553bd9a50ff00d1e56ec Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Thu, 8 Jan 2026 09:55:02 +0100 Subject: [PATCH 118/120] Update post-quantum support test --- openwsman.spec | 5 ++++- tests/post-quantum-cryptography/runtest.sh | 20 ++++++++++---------- 2 files changed, 14 insertions(+), 11 deletions(-) diff --git a/openwsman.spec b/openwsman.spec index 94298f8..75d8459 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -25,7 +25,7 @@ Name: openwsman Version: 2.8.1 -Release: 12%{?dist} +Release: 13%{?dist} Summary: Open source Implementation of WS-Management License: BSD-3-Clause AND MIT @@ -421,6 +421,9 @@ fi %endif %changelog +* Thu Jan 08 2026 Vitezslav Crhonek - 2.8.1-13 +- Fix PQC test + * Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 - Support rdoc 6.16 and above (for ruby4.0) diff --git a/tests/post-quantum-cryptography/runtest.sh b/tests/post-quantum-cryptography/runtest.sh index 6588a8a..a09dda5 100755 --- a/tests/post-quantum-cryptography/runtest.sh +++ b/tests/post-quantum-cryptography/runtest.sh @@ -52,17 +52,17 @@ rm -rf /etc/openwsman/{servercert,serverkey}.pem # update genOpenPegasusSSLCerts to generate a new key using ML-DSA-65 # and issue a self-signed certificate for localhost using this key patch /etc/openwsman/owsmangencert.sh << 'EOF' ---- /etc/openwsman/owsmangencert.sh.orig 2025-06-25 04:03:22.295778704 -0400 -+++ /etc/openwsman/owsmangencert.sh 2025-06-25 04:05:12.181435542 -0400 -@@ -26,7 +26,7 @@ - # certificate is created +--- owsmangencert.sh.orig 2026-01-08 03:50:31.852413993 -0500 ++++ owsmangencert.sh 2026-01-08 03:52:41.883088457 -0500 +@@ -65,7 +65,7 @@ + # certificate is created - openssl req -days 365 $@ -config $CNFFILE \ -- -newkey rsa:2048 -x509 -nodes -out $CERTFILE \ -+ -newkey mldsa65 -x509 -nodes -out $CERTFILE \ - -keyout $KEYFILE - chmod 600 $KEYFILE - + openssl req -days $DAYS $@ -config $CNFFILE \ +- -new -x509 -nodes -out $CERTFILE \ ++ -newkey mldsa65 -x509 -nodes -out $CERTFILE \ + -keyout $KEYFILE + chmod 600 $KEYFILE + } EOF (echo CZ; echo "Czech Republic"; echo Brno; echo "Red Hat"; echo "Core Services"; echo localhost; echo joe@example.com; ) | /etc/openwsman/owsmangencert.sh From 901f747d526d3e5ee60ff3171cf398186ddfe3e1 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Mon, 12 Jan 2026 08:39:40 +0100 Subject: [PATCH 119/120] Fix bogus 'sscg' arguments --- openwsman-2.7.2-ssl-certs-gen-changes.patch | 8 ++++---- openwsman.spec | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/openwsman-2.7.2-ssl-certs-gen-changes.patch b/openwsman-2.7.2-ssl-certs-gen-changes.patch index 11de1d5..0f0b96a 100644 --- a/openwsman-2.7.2-ssl-certs-gen-changes.patch +++ b/openwsman-2.7.2-ssl-certs-gen-changes.patch @@ -51,10 +51,10 @@ diff -up openwsman-2.8.1/etc/owsmangencert.sh.cmake.orig openwsman-2.8.1/etc/ows +function selfsign_sscg() +{ + sscg --quiet \ -+ --lifetime "${DAYS}" \ -+ --cert-key-file "${KEYFILE}" \ -+ --cert-file "${CERTFILE}" \ -+ --ca-file "${CAFILE}" ++ --lifetime "$DAYS" \ ++ --cert-key-file "$KEYFILE" \ ++ --cert-file "$CERTFILE" \ ++ --ca-file "$CAFILE" +} + +function selfsign_openssl() diff --git a/openwsman.spec b/openwsman.spec index 75d8459..1a56b52 100644 --- a/openwsman.spec +++ b/openwsman.spec @@ -422,7 +422,7 @@ fi %changelog * Thu Jan 08 2026 Vitezslav Crhonek - 2.8.1-13 -- Fix PQC test +- Fix bogus 'sscg' arguments * Fri Jan 02 2026 Mamoru TASAKA - 2.8.1-12 - Support rdoc 6.16 and above (for ruby4.0) From 897a78ebf80fc3e450fcb17a0ab65e4047147985 Mon Sep 17 00:00:00 2001 From: Vitezslav Crhonek Date: Fri, 9 Jan 2026 07:49:16 +0100 Subject: [PATCH 120/120] Add 'sscg' SSL files generation test --- tests/sscg-generated-certificates/main.fmf | 6 ++++++ tests/sscg-generated-certificates/runtest.sh | 17 +++++++++++++++++ 2 files changed, 23 insertions(+) create mode 100644 tests/sscg-generated-certificates/main.fmf create mode 100755 tests/sscg-generated-certificates/runtest.sh diff --git a/tests/sscg-generated-certificates/main.fmf b/tests/sscg-generated-certificates/main.fmf new file mode 100644 index 0000000..0b30fd6 --- /dev/null +++ b/tests/sscg-generated-certificates/main.fmf @@ -0,0 +1,6 @@ +summary: Service works with 'sscg' generated SSL certificates +author: Vitezslav Crhonek +contact: Vitezslav Crhonek +require: sscg +duration: 10m +test: ./runtest.sh diff --git a/tests/sscg-generated-certificates/runtest.sh b/tests/sscg-generated-certificates/runtest.sh new file mode 100755 index 0000000..459ba4b --- /dev/null +++ b/tests/sscg-generated-certificates/runtest.sh @@ -0,0 +1,17 @@ +#!/bin/sh -ux + +# remove previously generated SSL files +rm -rf /etc/openwsman/{servercert,serverkey}*.pem /etc/openwsman/ca.crt + +# remove SSL fallback to relly really just on sscg +cp /etc/openwsman/owsmangencert.sh /etc/openwsman/test-script.sh +sed -i 's/^selfsign_sscg ||.*/selfsign_sscg/' /etc/openwsman/test-script.sh + +# generate new SSL files using sscg +/etc/openwsman/test-script.sh + +# check that SSL files were generated +[ -f /etc/openwsman/servercert.pem ] && [ -f /etc/openwsman/serverkey.pem ] || { echo "Error: SSL files missing"; exit 1; } + +# try to start the service +systemctl start openwsmand