From c6d73ac3d5db1f331433f3a47e0b563d04c1ee3d Mon Sep 17 00:00:00 2001 From: Daiki Ueno Date: Wed, 3 Sep 2025 18:33:50 +0900 Subject: [PATCH 1/2] rpc: Fix empty array attribute handling Signed-off-by: Daiki Ueno --- p11-kit-0.25.5-rpc-empty.patch | 62 ++++++++++++++++++++++++++++++++++ p11-kit.spec | 3 ++ 2 files changed, 65 insertions(+) create mode 100644 p11-kit-0.25.5-rpc-empty.patch diff --git a/p11-kit-0.25.5-rpc-empty.patch b/p11-kit-0.25.5-rpc-empty.patch new file mode 100644 index 0000000..63709dc --- /dev/null +++ b/p11-kit-0.25.5-rpc-empty.patch @@ -0,0 +1,62 @@ +From e94c1fb907546faafb3509615943776d1ea37eb8 Mon Sep 17 00:00:00 2001 +From: Daiki Ueno +Date: Wed, 3 Sep 2025 17:10:21 +0900 +Subject: [PATCH] rpc: Fix empty array attribute handling + +When an empty array attribute is exchanged at the RPC level, the +client previously sent the number of elements (= 0) even if it's +empty, while the server doesn't expect it. This fixes the client to +not send it. + +Signed-off-by: Daiki Ueno +--- + p11-kit/rpc-message.c | 2 +- + p11-kit/test-mock.c | 12 ++++++++++++ + 2 files changed, 13 insertions(+), 1 deletion(-) + +diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c +index 049417f..5eaea61 100644 +--- a/p11-kit/rpc-message.c ++++ b/p11-kit/rpc-message.c +@@ -266,7 +266,7 @@ p11_rpc_message_write_attribute_buffer_array (p11_rpc_message *msg, + /* And the attribute buffer length */ + p11_rpc_buffer_add_uint32 (msg->output, attr->pValue ? attr->ulValueLen : 0); + +- if (IS_ATTRIBUTE_ARRAY (attr)) ++ if (attr->pValue && IS_ATTRIBUTE_ARRAY (attr)) + p11_rpc_message_write_attribute_buffer_array ( + msg, attr->pValue, + attr->ulValueLen / sizeof (CK_ATTRIBUTE)); +diff --git a/p11-kit/test-mock.c b/p11-kit/test-mock.c +index b117b92..f174015 100644 +--- a/p11-kit/test-mock.c ++++ b/p11-kit/test-mock.c +@@ -624,6 +624,12 @@ test_get_wrap_template (void) + { CKA_WRAP_TEMPLATE, temp, sizeof (temp) }, + }; + CK_ULONG n_attrs = sizeof (attrs) / sizeof (attrs[0]); ++ CK_OBJECT_CLASS klass = -1ul; ++ CK_ATTRIBUTE attrs_empty_template[] = { ++ { CKA_WRAP_TEMPLATE, NULL, 0 }, ++ { CKA_UNWRAP_TEMPLATE, NULL, 0 }, ++ }; ++ CK_ULONG n_attrs_empty_template = sizeof(attrs_empty_template) / sizeof(attrs_empty_template[0]); + + module = setup_mock_module (&session); + +@@ -664,6 +670,12 @@ test_get_wrap_template (void) + assert (verify == CK_TRUE); + assert (encrypt == CK_TRUE); + ++ rv = (module->C_GetAttributeValue) (session, MOCK_PUBLIC_KEY_CAPITALIZE, attrs_empty_template, n_attrs_empty_template); ++ assert (rv == CKR_ATTRIBUTE_TYPE_INVALID); ++ assert_num_eq (attrs_empty_template[0].type, CKA_WRAP_TEMPLATE); ++ assert_ptr_eq (attrs_empty_template[0].pValue, NULL); ++ assert_num_eq (attrs_empty_template[0].ulValueLen, (CK_ULONG)-1); ++ + teardown_mock_module (module); + } + +-- +2.50.1 + diff --git a/p11-kit.spec b/p11-kit.spec index d93e173..d87c3f0 100644 --- a/p11-kit.spec +++ b/p11-kit.spec @@ -12,6 +12,9 @@ Source2: https://p11-glue.github.io/p11-glue/p11-kit/p11-kit-release-keyr Source3: trust-extract-compat Source4: p11-kit-client.service +# https://github.com/p11-glue/p11-kit/pull/704 +Patch0: p11-kit-0.25.5-rpc-empty.patch + BuildRequires: gcc BuildRequires: libtasn1-devel >= 2.3 BuildRequires: libffi-devel From 32791e79a4838ba14f7ab989869a40c15020ab7b Mon Sep 17 00:00:00 2001 From: Packit Date: Tue, 9 Sep 2025 12:58:58 +0000 Subject: [PATCH 2/2] Update to 0.25.6 upstream release - Resolves: rhbz#2394061 Upstream tag: 0.25.6 Upstream commit: 4f821372 Commit authored by Packit automation (https://packit.dev/) --- .gitignore | 2 + README.packit | 2 +- p11-kit-0.25.6-packaging.patch | 18 +++++ p11-kit.spec | 129 +++++++++++++++++++++++++++++++-- sources | 4 +- 5 files changed, 144 insertions(+), 11 deletions(-) create mode 100644 p11-kit-0.25.6-packaging.patch diff --git a/.gitignore b/.gitignore index 6db1df5..78c0a93 100644 --- a/.gitignore +++ b/.gitignore @@ -46,3 +46,5 @@ /p11-kit-0.25.3.tar.xz.sig /p11-kit-0.25.5.tar.xz /p11-kit-0.25.5.tar.xz.sig +/p11-kit-0.25.6.tar.xz +/p11-kit-0.25.6.tar.xz.sig diff --git a/README.packit b/README.packit index f2be23e..fb341a1 100644 --- a/README.packit +++ b/README.packit @@ -1,3 +1,3 @@ This repository is maintained by packit. https://packit.dev/ -The file was generated using packit 0.97.3.post1.dev7+g1954e49a. +The file was generated using packit 1.11.0.post1.dev7+gfdcdf3a32. diff --git a/p11-kit-0.25.6-packaging.patch b/p11-kit-0.25.6-packaging.patch new file mode 100644 index 0000000..aee2dd8 --- /dev/null +++ b/p11-kit-0.25.6-packaging.patch @@ -0,0 +1,18 @@ +diff --git a/meson.build b/meson.build +index ab28396..b5829ca 100644 +--- a/meson.build ++++ b/meson.build +@@ -459,6 +459,7 @@ with_systemd = false + systemd = dependency('systemd', required: get_option('systemd')) + if systemd.found() + systemduserunitdir = systemd.get_variable(pkgconfig : 'systemduserunitdir') ++ with_systemd = true + endif + + configure_file(output: 'config.h', configuration: conf) +@@ -488,4 +489,4 @@ if get_option('nls') + subdir('po') + endif + subdir('bash-completion') +-subdir('zsh-completion') ++# subdir('zsh-completion') diff --git a/p11-kit.spec b/p11-kit.spec index d87c3f0..1ffa8c4 100644 --- a/p11-kit.spec +++ b/p11-kit.spec @@ -1,5 +1,12 @@ # This spec file has been automatically updated -Version: 0.25.5 +%if 0%{?fedora} +%bcond_without mingw +%else +%bcond_with mingw +%endif + + +Version: 0.25.6 Release: %{?autorelease}%{!?autorelease:1%{?dist}} Name: p11-kit Summary: Library for loading and sharing PKCS#11 modules @@ -12,8 +19,7 @@ Source2: https://p11-glue.github.io/p11-glue/p11-kit/p11-kit-release-keyr Source3: trust-extract-compat Source4: p11-kit-client.service -# https://github.com/p11-glue/p11-kit/pull/704 -Patch0: p11-kit-0.25.5-rpc-empty.patch +Patch: p11-kit-0.25.6-packaging.patch BuildRequires: gcc BuildRequires: libtasn1-devel >= 2.3 @@ -30,12 +36,40 @@ BuildRequires: pkgconfig(systemd) BuildRequires: gnupg2 BuildRequires: /usr/bin/xsltproc +%if %{with mingw} +BuildRequires: ninja-build + +BuildRequires: mingw32-filesystem >= 95 +BuildRequires: mingw32-gcc +BuildRequires: mingw32-binutils +BuildRequires: mingw32-libffi +BuildRequires: mingw32-libtasn1 + +BuildRequires: mingw64-filesystem >= 95 +BuildRequires: mingw64-gcc +BuildRequires: mingw64-binutils +BuildRequires: mingw64-libffi +BuildRequires: mingw64-libtasn1 +%endif + + %description p11-kit provides a way to load and enumerate PKCS#11 modules, as well as a standard configuration setup for installing PKCS#11 modules in such a way that they're discoverable. +%package client +Summary: Client module from %{name} +Requires: %{name}%{?_isa} = %{version}-%{release} +Obsoletes: %{name}-server < 0.25.5-8 + +%description client +The %{name}-client package contains a PKCS#11 module that enables +accessing other PKCS#11 modules over a Unix domain socket. Note that +this feature is still experimental. + + %package devel Summary: Development files for %{name} Requires: %{name}%{?_isa} = %{version}-%{release} @@ -58,8 +92,9 @@ contains certificate anchors and blocklists. %package server -Summary: Server and client commands for %{name} +Summary: Server command for %{name} Requires: %{name}%{?_isa} = %{version}-%{release} +Obsoletes: %{name}-server < 0.25.5-8 %description server The %{name}-server package contains command line tools that enable to @@ -67,6 +102,33 @@ export PKCS#11 modules through a Unix domain socket. Note that this feature is still experimental. +%if %{with mingw} +%package -n mingw32-%{name} +Summary: MinGW Library for loading and sharing PKCS#11 modules +Requires: pkgconfig +BuildArch: noarch + +%description -n mingw32-%{name} +p11-kit provides a way to load and enumerate PKCS#11 modules, as well as +a standard configuration setup for installing PKCS#11 modules in such a +way that they're discoverable. This library is cross-compiled for MinGW. + + +%package -n mingw64-%{name} +Summary: MinGW Library for loading and sharing PKCS#11 modules +Requires: pkgconfig +BuildArch: noarch + +%description -n mingw64-%{name} +p11-kit provides a way to load and enumerate PKCS#11 modules, as well as +a standard configuration setup for installing PKCS#11 modules in such a +way that they're discoverable. This library is cross-compiled for MinGW. + + +%{?mingw_debug_package} +%endif + + # solution taken from icedtea-web.spec %define multilib_arches ppc64 sparc64 x86_64 ppc64le %ifarch %{multilib_arches} @@ -82,11 +144,16 @@ gpgv2 --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %autosetup -p1 %build -# These paths are the source paths that come from the plan here: +# These paths are the source paths that come from the plan here: # https://fedoraproject.org/wiki/Features/SharedSystemCertificates:SubTasks %meson -Dgtk_doc=true -Dman=true -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source %meson_build +%if %{with mingw} +%mingw_meson -Dgtk_doc=false -Dman=false -Dnls=false -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source +%mingw_ninja +%endif + %install %meson_install mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pkcs11/modules @@ -98,6 +165,12 @@ mkdir -p $RPM_BUILD_ROOT%{_userunitdir} install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_userunitdir} %find_lang %{name} +%if %{with mingw} +%mingw_ninja_install + +%{?mingw_debug_install_post} +%endif + %check %meson_test @@ -121,6 +194,7 @@ fi %dir %{_sysconfdir}/pkcs11/modules %dir %{_datadir}/p11-kit %dir %{_datadir}/p11-kit/modules +%dir %{_libdir}/pkcs11 %dir %{_libexecdir}/p11-kit %{_bindir}/p11-kit %{_libdir}/libp11-kit.so.* @@ -131,6 +205,10 @@ fi %{_mandir}/man5/pkcs11.conf.5.gz %{_datadir}/bash-completion/completions/p11-kit +%files client +%{_libdir}/pkcs11/p11-kit-client.so +%{_userunitdir}/p11-kit-client.service + %files devel %{_includedir}/p11-kit-1/ %{_libdir}/libp11-kit.so @@ -139,7 +217,6 @@ fi %files trust %{_bindir}/trust -%dir %{_libdir}/pkcs11 %ghost %{_libdir}/libnssckbi.so %{_libdir}/pkcs11/p11-kit-trust.so %{_datadir}/p11-kit/modules/p11-kit-trust.module @@ -147,12 +224,48 @@ fi %{_datadir}/bash-completion/completions/trust %files server -%{_libdir}/pkcs11/p11-kit-client.so -%{_userunitdir}/p11-kit-client.service %{_libexecdir}/p11-kit/p11-kit-server %{_userunitdir}/p11-kit-server.service %{_userunitdir}/p11-kit-server.socket +%if %{with mingw} +%files -n mingw32-%{name} +%{!?_licensedir:%global license %%doc} +%license COPYING +%{mingw32_bindir}/libp11-kit-0.dll +%{mingw32_bindir}/p11-kit.exe +%{mingw32_bindir}/trust.exe +%{mingw32_libdir}/libp11-kit.dll.a +%dir %{mingw32_libdir}/pkcs11/ +%{mingw32_libdir}/pkcs11/p11-kit-trust.dll +%{mingw32_libdir}/pkcs11/p11-kit-trust.dll.a +%{mingw32_libdir}/pkgconfig/p11-kit-1.pc +%dir %{mingw32_libexecdir}/p11-kit/ +%{mingw32_libexecdir}/p11-kit/*.exe +%{mingw32_libexecdir}/p11-kit/trust-extract-compat +%{mingw32_includedir}/p11-kit-1/ +%{mingw32_datadir}/p11-kit/ +%{mingw32_sysconfdir}/pkcs11/ + +%files -n mingw64-%{name} +%{!?_licensedir:%global license %%doc} +%license COPYING +%{mingw64_bindir}/libp11-kit-0.dll +%{mingw64_bindir}/p11-kit.exe +%{mingw64_bindir}/trust.exe +%{mingw64_libdir}/libp11-kit.dll.a +%dir %{mingw64_libdir}/pkcs11/ +%{mingw64_libdir}/pkcs11/p11-kit-trust.dll +%{mingw64_libdir}/pkcs11/p11-kit-trust.dll.a +%{mingw64_libdir}/pkgconfig/p11-kit-1.pc +%dir %{mingw64_libexecdir}/p11-kit/ +%{mingw64_libexecdir}/p11-kit/*.exe +%{mingw64_libexecdir}/p11-kit/trust-extract-compat +%{mingw64_includedir}/p11-kit-1/ +%{mingw64_datadir}/p11-kit/ +%{mingw64_sysconfdir}/pkcs11/ +%endif + %changelog %autochangelog diff --git a/sources b/sources index bed7eca..c7c1c77 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (p11-kit-0.25.5.tar.xz) = 177ec6ff5eb891901078306dce2bf3f5c1a0e5c2a8c493bdf5a08ae1ff1240fdf6952961e973c373f80ac3d1d5a9927e07f4da49e4ff92269d992e744889fc94 -SHA512 (p11-kit-0.25.5.tar.xz.sig) = 2be5aa4ccbb889e32aed88fc1f7926c3ccaadc90cc6b15a187358c812eee4ce1712068d1f271766ac51366112c0619aad46cff345ed2edd009fb2fe7fb804493 +SHA512 (p11-kit-0.25.6.tar.xz) = 71b5b83f0f241a28db66dcb940690ee6d23bbeebdd7d3f6772f1f444e2410c3b6e00f6a2530baef639816e4e05fe2189d340dae7c688f0d751c423c51d20ef16 +SHA512 (p11-kit-0.25.6.tar.xz.sig) = 99d06ee64de815bcb4e6bd861f2e11940103896f87b206b9ae221b91f706dc810fef7e7f5341570b8c447093e34defa8918693b1e14c8659aab1cd1d65768fb7 SHA512 (p11-kit-release-keyring.gpg) = 9a832a8ac3a139cbbf1ecb66573f0709847ebfef4975777cf82b4dca09af1ad8e6400f0af0bcdb92860e7ed4fc05082ba1edda0238a21fe24d49555a1069e881