diff --git a/.gitignore b/.gitignore index dfb8ab3..bc5520f 100644 --- a/.gitignore +++ b/.gitignore @@ -34,19 +34,3 @@ /p11-kit-0.23.20.tar.xz /p11-kit-0.23.21.tar.xz /p11-kit-0.23.22.tar.xz -/p11-kit-0.24.1.tar.xz -/p11-kit-0.25.0.tar.xz -/p11-kit-0.25.0.tar.xz.sig -/p11-kit-release-keyring.gpg -/p11-kit-0.25.1.tar.xz -/p11-kit-0.25.1.tar.xz.sig -/p11-kit-0.25.2.tar.xz -/p11-kit-0.25.2.tar.xz.sig -/p11-kit-0.25.3.tar.xz -/p11-kit-0.25.3.tar.xz.sig -/p11-kit-0.25.5.tar.xz -/p11-kit-0.25.5.tar.xz.sig -/p11-kit-0.25.6.tar.xz -/p11-kit-0.25.6.tar.xz.sig -/p11-kit-0.25.8.tar.xz -/p11-kit-0.25.8.tar.xz.sig diff --git a/.packit.yaml b/.packit.yaml index fff496e..12ba12c 100644 --- a/.packit.yaml +++ b/.packit.yaml @@ -1,13 +1,16 @@ specfile_path: p11-kit.spec +synced_files: + - p11-kit.spec + - .packit.yaml upstream_package_name: p11-kit downstream_package_name: p11-kit # Use only populated spec files and upstream sources. actions: post-upstream-clone: - - wget https://src.fedoraproject.org/rpms/p11-kit/raw/rawhide/f/p11-kit.spec - - wget https://src.fedoraproject.org/rpms/p11-kit/raw/rawhide/f/p11-kit-client.service - - wget https://src.fedoraproject.org/rpms/p11-kit/raw/rawhide/f/trust-extract-compat + - wget https://src.fedoraproject.org/rpms/p11-kit/raw/master/f/p11-kit.spec + - wget https://src.fedoraproject.org/rpms/p11-kit/raw/master/f/p11-kit-client.service + - wget https://src.fedoraproject.org/rpms/p11-kit/raw/master/f/trust-extract-compat get-current-version: - "git describe --abbrev=0" create-archive: diff --git a/README.packit b/README.packit index fb341a1..f2e7df3 100644 --- a/README.packit +++ b/README.packit @@ -1,3 +1,3 @@ This repository is maintained by packit. https://packit.dev/ -The file was generated using packit 1.11.0.post1.dev7+gfdcdf3a32. +The file was generated using packit 0.21.1.dev11+g485bd88. diff --git a/changelog b/changelog deleted file mode 100644 index fe28d02..0000000 --- a/changelog +++ /dev/null @@ -1,364 +0,0 @@ -* Fri Jul 22 2022 Fedora Release Engineering - 0.24.1-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Thu Jan 20 2022 Fedora Release Engineering - 0.24.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Mon Jan 17 2022 Packit Service - 0.24.1-1 -- Release 0.24.1 (Daiki Ueno) -- common: Support copying attribute array recursively (Daiki Ueno) -- common: Add assert_ptr_cmp (Daiki Ueno) -- gtkdoc: remove dependencies on custom target files (Eli Schwartz) -- doc: Replace occurrence of black list with blocklist (Daiki Ueno) -- build: Suppress cppcheck false-positive on array bounds (Daiki Ueno) -- ci: Use Docker image from the same repository (Daiki Ueno) -- ci: Integrate Docker image building to GitHub workflow (Daiki Ueno) -- rpc: Fallback to version 0 if server does not support negotiation (Daiki Ueno) -- build: Port e850e03be65ed573d0b69ee0408e776c08fad8a3 to meson (Daiki Ueno) -- Link libp11-kit so that it cannot unload (Emmanuel Dreyfus) -- trust: Use dngettext for plurals (Daiki Ueno) -- rpc: Support protocol version negotiation (Daiki Ueno) -- rpc: Separate authentication step from transaction (Daiki Ueno) -- Meson: p11_system_config_modules instead of p11_package_config_modules (Issam E. Maghni) -- shell: test -a|o is not POSIX (Issam E. Maghni) -- Meson: Add libtasn1 to trust programs (Issam E. Maghni) -- meson: optionalise glib's development files for gtk_doc (Đoàn Trần Công Danh) - -* Sat Jan 08 2022 Miro Hrončok - 0.23.22-5 -- Rebuilt for https://fedoraproject.org/wiki/Changes/LIBFFI34 - -* Thu Jul 22 2021 Fedora Release Engineering - 0.23.22-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Tue Jan 26 2021 Daiki Ueno - 0.23.22-3 -- Suppress intentional memleak in getprogname emulation (#1905581) - -* Tue Jan 26 2021 Fedora Release Engineering - 0.23.22-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Fri Dec 11 2020 Packit Service - 0.23.22-1 -- Release 0.23.22 (Daiki Ueno) -- Follow-up to arithmetic overflow fix (David Cook) -- Check for arithmetic overflows before allocating (David Cook) -- Check attribute length against buffer size (David Cook) -- Fix bounds check in p11_rpc_buffer_get_byte_array (David Cook) -- Fix buffer overflow in log_token_info (David Cook) -- common: Don't assume __STDC_VERSION__ is always defined (Daiki Ueno) -- compat: getauxval: correct compiler macro for FreeBSD (Daiki Ueno) -- compat: fdwalk: add guard for Linux specific local variables (Daiki Ueno) -- meson: Add missing libtasn1 dependency (Daiki Ueno) -- travis: Add freebsd build (Daiki Ueno) -- anchor: Prefer persistent format when storing anchor (Daiki Ueno) -- travis: Run "make check" along with "make distcheck" for coverage (Daiki Ueno) -- travis: Use python3 as the default Python interpreter (Daiki Ueno) -- travis: Route to Ubuntu 20.04 base image (Daiki Ueno) -- meson: Set -fstack-protector for MinGW64 cross build (Daiki Ueno) -- meson: expand ternary operator in function call for compatibility (Daiki Ueno) -- meson: Use custom_target for generating external XML entities (Daiki Ueno) -- meson: Allow building manpages without gtk-doc (Jan Alexander Steffens (heftig)) -- Rename is_path_component to is_path_separator (Alexander Sosedkin) -- Use is_path_component in one more place (Alexander Sosedkin) -- Remove more duplicate separators in p11_path_build (Alexander Sosedkin) -- common: Fix infloop in p11_path_build (Daiki Ueno) -- proxy: C_CloseAllSessions: Make sure that calloc args are non-zero (Daiki Ueno) -- build: Use calloc in a consistent manner (Daiki Ueno) -- meson: Allow override of default bashcompdir. Fixes meson regression (issue #322). Pass -Dbashcompdir=/xxx to meson. (John Hein) -- common: Check for a NULL locale before freeing it (Tavian Barnes) -- p11_test_copy_setgid: Skip setgid tests on nosuid filesystems (Anders Kaseorg) -- unix-peer: replace incorrect include1 (Rosen Penev) -- test-compat: Skip getprogname test if BUILDDIR contains a symlink (Daiki Ueno) -- add trust-extract-compat into EXTRA-DIST (Xℹ Ruoyao) -- meson: install trust-extract-compat (Xℹ Ruoyao) -- rename trust-extract-compat.in to trust-extract-compat (Xℹ Ruoyao) - -* Thu Nov 12 2020 Alexander Sosedkin - 0.23.21-3 -- Add an explicit build dependency on xsltproc - -* Tue Aug 18 2020 Packit Service - 0.23.21-2 -- new upstream release: 0.23.21 - -* Tue Jul 28 2020 Fedora Release Engineering - 0.23.20-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Wed Jan 29 2020 Daiki Ueno - 0.23.20-1 -- Update to upstream 0.23.20 release - -* Wed Jan 22 2020 Daiki Ueno - 0.23.19-1 -- Update to upstream 0.23.19 release -- Check archive signature in %%prep -- Switch to using Meson as the build system - -* Mon Sep 30 2019 Daiki Ueno - 0.23.18.1-1 -- Update to upstream 0.23.18.1 release - -* Thu Jul 25 2019 Fedora Release Engineering - 0.23.16.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Thu May 23 2019 Daiki Ueno - 0.23.16.1-1 -- Update to upstream 0.23.16.1 release - -* Thu May 23 2019 Daiki Ueno - 0.23.16-1 -- Update to upstream 0.23.16 release - -* Mon Feb 18 2019 Daiki Ueno - 0.23.15-3 -- trust: Ignore unreadable content in anchors - -* Fri Feb 01 2019 Fedora Release Engineering - 0.23.15-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Mon Jan 21 2019 Daiki Ueno - 0.23.15-1 -- Update to upstream 0.23.15 release - -* Fri Jan 11 2019 Nils Philippsen - 0.23.14-3 -- use spaces instead of tabs consistently -- prefer fixed closures to libffi closures (#1656245, patch by Daiki Ueno) - -* Mon Oct 29 2018 James Antill - 0.23.14-2 -- Remove ldconfig scriptlet, now done via. transfiletrigger in glibc. - -* Fri Sep 07 2018 Daiki Ueno - 0.23.14-1 -- Update to upstream 0.23.14 release - -* Wed Aug 15 2018 Daiki Ueno - 0.23.13-3 -- Forcibly link with libpthread to avoid regressions (rhbz#1615038) - -* Wed Aug 15 2018 Daiki Ueno - 0.23.13-2 -- Fix invalid memory access on proxy cleanup - -* Fri Aug 10 2018 Daiki Ueno - 0.23.13-1 -- Update to upstream 0.23.13 release - -* Fri Jul 13 2018 Fedora Release Engineering - 0.23.12-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild - -* Wed May 30 2018 Daiki Ueno - 0.23.12-1 -- Update to upstream 0.23.11 release - -* Wed Feb 28 2018 Daiki Ueno - 0.23.10-1 -- Update to upstream 0.23.10 release - -* Thu Feb 08 2018 Fedora Release Engineering - 0.23.9-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - -* Thu Oct 05 2017 Daiki Ueno - 0.23.9-2 -- server: Make it possible to eval envvar settings - -* Wed Oct 04 2017 Daiki Ueno - 0.23.9-1 -- Update to upstream 0.23.9 - -* Fri Aug 25 2017 Kai Engert - 0.23.8-2 -- Fix a regression caused by a recent nss.rpm change, add a %%ghost file - for %%{_libdir}/libnssckbi.so that p11-kit-trust scripts install. - -* Tue Aug 15 2017 Daiki Ueno - 0.23.8-1 -- Update to 0.23.8 release - -* Thu Aug 03 2017 Fedora Release Engineering - 0.23.7-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild - -* Thu Jul 27 2017 Fedora Release Engineering - 0.23.7-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild - -* Fri Jun 2 2017 Daiki Ueno - 0.23.7-1 -- Update to 0.23.7 release - -* Thu May 18 2017 Daiki Ueno - 0.23.5-3 -- Update p11-kit-modifiable.patch to simplify the logic - -* Thu May 18 2017 Daiki Ueno - 0.23.5-2 -- Make "trust anchor --remove" work again - -* Thu Mar 2 2017 Daiki Ueno - 0.23.5-1 -- Update to 0.23.5 release -- Rename -tools subpackage to -server and remove systemd unit files - -* Fri Feb 24 2017 Daiki Ueno - 0.23.4-3 -- Move p11-kit command back to main package - -* Fri Feb 24 2017 Daiki Ueno - 0.23.4-2 -- Split out command line tools to -tools subpackage, to avoid a - multilib issue with the main package. Suggested by Yanko Kaneti. - -* Wed Feb 22 2017 Daiki Ueno - 0.23.4-1 -- Update to 0.23.4 release - -* Sat Feb 11 2017 Fedora Release Engineering - 0.23.3-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild - -* Fri Jan 6 2017 Daiki Ueno - 0.23.3-2 -- Use internal hash implementation instead of NSS (#1390598) - -* Tue Dec 20 2016 Daiki Ueno - 0.23.3-1 -- Update to 0.23.3 release -- Adjust executables location from %%libdir to %%libexecdir - -* Thu Feb 04 2016 Fedora Release Engineering - 0.23.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild - -* Tue Jan 12 2016 Martin Preisler - 0.23.2-1 -- Update to stable 0.23.2 release - -* Tue Jun 30 2015 Martin Preisler - 0.23.1-4 -- In proxy module don't call C_Finalize on a forked process [#1217915] -- Do not deinitialize libffi's wrapper functions [#1217915] - -* Thu Jun 18 2015 Fedora Release Engineering - 0.23.1-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild - -* Sat Feb 21 2015 Till Maas - 0.23.1-2 -- Rebuilt for Fedora 23 Change - https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code - -* Fri Feb 20 2015 Stef Walter - 0.23.1-1 -- Update to 0.23.1 release - -* Thu Oct 09 2014 Stef Walter - 0.22.1-1 -- Update to 0.22.1 release -- Use SubjectKeyIdentifier as a CKA_ID if possible rhbz#1148895 - -* Sat Oct 04 2014 Stef Walter 0.22.0-1 -- Update to 0.22.0 release - -* Wed Sep 17 2014 Stef Walter 0.21.3-1 -- Update to 0.21.3 release -- Includes definitions for trust extensions rhbz#1136817 - -* Fri Sep 05 2014 Stef Walter 0.21.2-1 -- Update to 0.21.2 release -- Fix problems with erroneous messages printed rhbz#1133857 - -* Sun Aug 17 2014 Fedora Release Engineering - 0.21.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild - -* Thu Aug 07 2014 Stef Walter - 0.21.1-1 -- Update to 0.21.1 release - -* Wed Jul 30 2014 Tom Callaway - 0.20.3-3 -- fix license handling - -* Fri Jul 04 2014 Stef Walter - 0.20.3-2 -- Update to stable 0.20.3 release - -* Fri Jun 06 2014 Fedora Release Engineering - 0.20.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild - -* Sat Jan 25 2014 Ville Skyttä - 0.20.2-2 -- Own the %%{_libdir}/pkcs11 dir in -trust. - -* Tue Jan 14 2014 Stef Walter - 0.20.2-1 -- Update to upstream stable 0.20.2 release -- Fix regression involving blacklisted anchors [#1041328] -- Support ppc64le in build [#1052707] - -* Mon Sep 09 2013 Stef Walter - 0.20.1-1 -- Update to upstream stable 0.20.1 release -- Extract compat trust data after we've changes -- Skip compat extraction if running as non-root -- Better failure messages when removing anchors - -* Thu Aug 29 2013 Stef Walter - 0.19.4-1 -- Update to new upstream 0.19.4 release - -* Sat Aug 03 2013 Fedora Release Engineering - 0.19.3-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild - -* Wed Jul 24 2013 Stef Walter - 0.19.3-1 -- Update to new upstream 0.19.3 release (#967822) - -* Wed Jun 05 2013 Stef Walter - 0.18.3-1 -- Update to new upstream stable release -- Fix intermittent firefox cert validation issues (#960230) -- Include the manual pages in the package - -* Tue May 14 2013 Stef Walter - 0.18.2-1 -- Update to new upstream stable release -- Reduce the libtasn1 dependency minimum version - -* Thu May 02 2013 Stef Walter - 0.18.1-1 -- Update to new upstream stable release -- 'p11-kit extract-trust' lives in libdir - -* Thu Apr 04 2013 Stef Walter - 0.18.0-1 -- Update to new upstream stable release -- Various logging tweaks (#928914, #928750) -- Make the 'p11-kit extract-trust' explicitly reject - additional arguments - -* Thu Mar 28 2013 Stef Walter - 0.17.5-1 -- Make 'p11-kit extract-trust' call update-ca-trust -- Work around 32-bit oveflow of certificate dates -- Build fixes - -* Tue Mar 26 2013 Stef Walter - 0.17.4-2 -- Pull in patch from upstream to fix build on ppc (#927394) - -* Wed Mar 20 2013 Stef Walter - 0.17.4-1 -- Update to upstream version 0.17.4 - -* Mon Mar 18 2013 Stef Walter - 0.17.3-1 -- Update to upstream version 0.17.3 -- Put the trust input paths in the right order - -* Tue Mar 12 2013 Stef Walter - 0.16.4-1 -- Update to upstream version 0.16.4 - -* Fri Mar 08 2013 Stef Walter - 0.16.3-1 -- Update to upstream version 0.16.3 -- Split out system trust module into its own package. -- p11-kit-trust provides an alternative to an nss module - -* Tue Mar 05 2013 Stef Walter - 0.16.1-1 -- Update to upstream version 0.16.1 -- Setup source directories as appropriate for Shared System Certificates feature - -* Tue Mar 05 2013 Stef Walter - 0.16.0-1 -- Update to upstream version 0.16.0 - -* Thu Feb 14 2013 Fedora Release Engineering - 0.14-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild - -* Mon Sep 17 2012 Kalev Lember - 0.14-1 -- Update to 0.14 - -* Fri Jul 20 2012 Fedora Release Engineering - 0.13-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild - -* Mon Jul 16 2012 Kalev Lember - 0.13-1 -- Update to 0.13 - -* Tue Mar 27 2012 Kalev Lember - 0.12-1 -- Update to 0.12 -- Run self tests in %%check - -* Sat Feb 11 2012 Kalev Lember - 0.11-1 -- Update to 0.11 - -* Fri Jan 13 2012 Fedora Release Engineering - 0.9-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild - -* Tue Dec 20 2011 Matthias Clasen - 0.9-1 -- Update to 0.9 - -* Wed Oct 26 2011 Kalev Lember - 0.8-1 -- Update to 0.8 - -* Mon Sep 19 2011 Matthias Clasen - 0.6-1 -- Update to 0.6 - -* Sun Sep 04 2011 Kalev Lember - 0.5-1 -- Update to 0.5 - -* Sun Aug 21 2011 Kalev Lember - 0.4-1 -- Update to 0.4 -- Install the example config file to documentation directory - -* Wed Aug 17 2011 Kalev Lember - 0.3-2 -- Tighten -devel subpackage deps (#725905) - -* Fri Jul 29 2011 Kalev Lember - 0.3-1 -- Update to 0.3 -- Upstream rewrote the ASL 2.0 bits, which makes the whole package - BSD-licensed - -* Tue Jul 12 2011 Kalev Lember - 0.2-1 -- Initial RPM release diff --git a/gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg b/gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg new file mode 100644 index 0000000..30cd729 Binary files /dev/null and b/gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg differ diff --git a/p11-kit-0.23.20.tar.xz.sig b/p11-kit-0.23.20.tar.xz.sig new file mode 100644 index 0000000..f1e2607 Binary files /dev/null and b/p11-kit-0.23.20.tar.xz.sig differ diff --git a/p11-kit-0.23.21.tar.xz.sig b/p11-kit-0.23.21.tar.xz.sig new file mode 100644 index 0000000..599cbca Binary files /dev/null and b/p11-kit-0.23.21.tar.xz.sig differ diff --git a/p11-kit-0.23.22-progname-leak.patch b/p11-kit-0.23.22-progname-leak.patch new file mode 100644 index 0000000..0f1dd6e --- /dev/null +++ b/p11-kit-0.23.22-progname-leak.patch @@ -0,0 +1,87 @@ +From 40fbf74b02b8ad6625e3aa49d2cdef2b52e47a04 Mon Sep 17 00:00:00 2001 +From: Daiki Ueno +Date: Mon, 25 Jan 2021 18:24:01 +0100 +Subject: [PATCH] compat: Pacify ASan complaints on intentionally leaked buffer + +Reported by Viktor Ashirov in: +https://bugzilla.redhat.com/show_bug.cgi?id=1905581 +--- + common/compat.c | 25 +++++++++++++++++++------ + common/library.c | 9 +++++++++ + 2 files changed, 28 insertions(+), 6 deletions(-) + +diff --git a/common/compat.c b/common/compat.c +index 4390cef..d6c5af6 100644 +--- a/common/compat.c ++++ b/common/compat.c +@@ -100,6 +100,19 @@ extern char *program_invocation_short_name; + extern char *__progname; + #endif + ++#ifdef __linux__ ++/* This symbol is also defined in library.c so as to be freed by the library ++ * destructor. If weak symbols are not supported nor library.c is not linked we ++ * simply leak the memory allocated with realpath(). */ ++#ifdef __GNUC__ ++extern char *p11_program_realpath; ++ ++char *p11_program_realpath __attribute__((weak)); ++#else ++static char *p11_program_realpath; ++#endif ++#endif ++ + const char * + getprogname (void) + { +@@ -124,14 +137,14 @@ getprogname (void) + * Logic borrowed from: + * . + */ +- static char *buf; +- +- if (!buf) +- buf = realpath ("/proc/self/exe", NULL); ++ if (!p11_program_realpath) ++ p11_program_realpath = realpath ("/proc/self/exe", NULL); + +- if (buf && strncmp (buf, name, strlen (buf)) == 0) ++ if (p11_program_realpath && ++ strncmp (p11_program_realpath, name, ++ strlen (p11_program_realpath)) == 0) + /* Use the executable path if the prefix matches. */ +- name = strrchr (buf, '/') + 1; ++ name = strrchr (p11_program_realpath, '/') + 1; + else + /* Otherwise fall back to + * program_invocation_short_name. */ +diff --git a/common/library.c b/common/library.c +index 891344a..1581702 100644 +--- a/common/library.c ++++ b/common/library.c +@@ -82,6 +82,11 @@ unsigned int p11_forkid = 1; + extern locale_t p11_message_locale; + #endif + ++#ifdef __linux__ ++/* used only under __linux__ in the getprogname() emulation in compat.c. */ ++char *p11_program_realpath; ++#endif ++ + static char * + thread_local_message (void) + { +@@ -190,6 +195,10 @@ p11_library_uninit (void) + #endif + p11_mutex_uninit (&p11_virtual_mutex); + p11_mutex_uninit (&p11_library_mutex); ++ ++#ifdef __linux__ ++ free (p11_program_realpath); ++#endif + } + + #endif /* OS_UNIX */ +-- +2.29.2 + diff --git a/p11-kit-0.23.22.tar.xz.sig b/p11-kit-0.23.22.tar.xz.sig new file mode 100644 index 0000000..6ef001e Binary files /dev/null and b/p11-kit-0.23.22.tar.xz.sig differ diff --git a/p11-kit-0.25.5-rpc-empty.patch b/p11-kit-0.25.5-rpc-empty.patch deleted file mode 100644 index 63709dc..0000000 --- a/p11-kit-0.25.5-rpc-empty.patch +++ /dev/null @@ -1,62 +0,0 @@ -From e94c1fb907546faafb3509615943776d1ea37eb8 Mon Sep 17 00:00:00 2001 -From: Daiki Ueno -Date: Wed, 3 Sep 2025 17:10:21 +0900 -Subject: [PATCH] rpc: Fix empty array attribute handling - -When an empty array attribute is exchanged at the RPC level, the -client previously sent the number of elements (= 0) even if it's -empty, while the server doesn't expect it. This fixes the client to -not send it. - -Signed-off-by: Daiki Ueno ---- - p11-kit/rpc-message.c | 2 +- - p11-kit/test-mock.c | 12 ++++++++++++ - 2 files changed, 13 insertions(+), 1 deletion(-) - -diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c -index 049417f..5eaea61 100644 ---- a/p11-kit/rpc-message.c -+++ b/p11-kit/rpc-message.c -@@ -266,7 +266,7 @@ p11_rpc_message_write_attribute_buffer_array (p11_rpc_message *msg, - /* And the attribute buffer length */ - p11_rpc_buffer_add_uint32 (msg->output, attr->pValue ? attr->ulValueLen : 0); - -- if (IS_ATTRIBUTE_ARRAY (attr)) -+ if (attr->pValue && IS_ATTRIBUTE_ARRAY (attr)) - p11_rpc_message_write_attribute_buffer_array ( - msg, attr->pValue, - attr->ulValueLen / sizeof (CK_ATTRIBUTE)); -diff --git a/p11-kit/test-mock.c b/p11-kit/test-mock.c -index b117b92..f174015 100644 ---- a/p11-kit/test-mock.c -+++ b/p11-kit/test-mock.c -@@ -624,6 +624,12 @@ test_get_wrap_template (void) - { CKA_WRAP_TEMPLATE, temp, sizeof (temp) }, - }; - CK_ULONG n_attrs = sizeof (attrs) / sizeof (attrs[0]); -+ CK_OBJECT_CLASS klass = -1ul; -+ CK_ATTRIBUTE attrs_empty_template[] = { -+ { CKA_WRAP_TEMPLATE, NULL, 0 }, -+ { CKA_UNWRAP_TEMPLATE, NULL, 0 }, -+ }; -+ CK_ULONG n_attrs_empty_template = sizeof(attrs_empty_template) / sizeof(attrs_empty_template[0]); - - module = setup_mock_module (&session); - -@@ -664,6 +670,12 @@ test_get_wrap_template (void) - assert (verify == CK_TRUE); - assert (encrypt == CK_TRUE); - -+ rv = (module->C_GetAttributeValue) (session, MOCK_PUBLIC_KEY_CAPITALIZE, attrs_empty_template, n_attrs_empty_template); -+ assert (rv == CKR_ATTRIBUTE_TYPE_INVALID); -+ assert_num_eq (attrs_empty_template[0].type, CKA_WRAP_TEMPLATE); -+ assert_ptr_eq (attrs_empty_template[0].pValue, NULL); -+ assert_num_eq (attrs_empty_template[0].ulValueLen, (CK_ULONG)-1); -+ - teardown_mock_module (module); - } - --- -2.50.1 - diff --git a/p11-kit-0.25.6-packaging.patch b/p11-kit-0.25.6-packaging.patch deleted file mode 100644 index aee2dd8..0000000 --- a/p11-kit-0.25.6-packaging.patch +++ /dev/null @@ -1,18 +0,0 @@ -diff --git a/meson.build b/meson.build -index ab28396..b5829ca 100644 ---- a/meson.build -+++ b/meson.build -@@ -459,6 +459,7 @@ with_systemd = false - systemd = dependency('systemd', required: get_option('systemd')) - if systemd.found() - systemduserunitdir = systemd.get_variable(pkgconfig : 'systemduserunitdir') -+ with_systemd = true - endif - - configure_file(output: 'config.h', configuration: conf) -@@ -488,4 +489,4 @@ if get_option('nls') - subdir('po') - endif - subdir('bash-completion') --subdir('zsh-completion') -+# subdir('zsh-completion') diff --git a/p11-kit-0.25.6-thread-local-var.patch b/p11-kit-0.25.6-thread-local-var.patch deleted file mode 100644 index 77acdbc..0000000 --- a/p11-kit-0.25.6-thread-local-var.patch +++ /dev/null @@ -1,134 +0,0 @@ -From fd7ad3969f68ea24e54d242a08b089039555f7bb Mon Sep 17 00:00:00 2001 -From: Brecht Sanders -Date: Tue, 31 Dec 2024 16:28:31 +0100 -Subject: [PATCH] avoid using already defined thread_local as variable name - -Building p11-kit 0.25.5 with GCC15 on MinGW-w64 failed because `thread_local` is already defined for this platform. - -Resolved by changing the variable name from `thread_local` to `threadlocal`. ---- - common/library.c | 36 ++++++++++++++++++------------------ - 1 file changed, 18 insertions(+), 18 deletions(-) - -diff --git a/common/library.c b/common/library.c -index 1581702b62db..723b05f33699 100644 ---- a/common/library.c -+++ b/common/library.c -@@ -124,7 +124,7 @@ _p11_library_get_thread_local (void) - return &local; - } - #else --static pthread_key_t thread_local = 0; -+static pthread_key_t threadlocal = 0; - - static p11_local * - _p11_library_get_thread_local (void) -@@ -133,10 +133,10 @@ _p11_library_get_thread_local (void) - - p11_library_init_once (); - -- local = pthread_getspecific (thread_local); -+ local = pthread_getspecific (threadlocal); - if (local == NULL) { - local = calloc (1, sizeof (p11_local)); -- pthread_setspecific (thread_local, local); -+ pthread_setspecific (threadlocal, local); - } - - return local; -@@ -158,7 +158,7 @@ p11_library_init_impl (void) - P11_RECURSIVE_MUTEX_INIT (p11_library_mutex); - P11_RECURSIVE_MUTEX_INIT (p11_virtual_mutex); - #ifndef P11_TLS_KEYWORD -- pthread_key_create (&thread_local, free); -+ pthread_key_create (&threadlocal, free); - #endif - p11_message_storage = thread_local_message; - #ifdef HAVE_STRERROR_L -@@ -181,8 +181,8 @@ p11_library_uninit (void) - - #ifndef P11_TLS_KEYWORD - /* Some cleanup to pacify valgrind */ -- free (pthread_getspecific (thread_local)); -- pthread_setspecific (thread_local, NULL); -+ free (pthread_getspecific (threadlocal)); -+ pthread_setspecific (threadlocal, NULL); - #endif - - #ifdef HAVE_STRERROR_L -@@ -191,7 +191,7 @@ p11_library_uninit (void) - #endif - p11_message_storage = dont_store_message; - #ifndef P11_TLS_KEYWORD -- pthread_key_delete (thread_local); -+ pthread_key_delete (threadlocal); - #endif - p11_mutex_uninit (&p11_virtual_mutex); - p11_mutex_uninit (&p11_library_mutex); -@@ -205,7 +205,7 @@ p11_library_uninit (void) - - #ifdef OS_WIN32 - --static DWORD thread_local = TLS_OUT_OF_INDEXES; -+static DWORD threadlocal = TLS_OUT_OF_INDEXES; - - BOOL WINAPI DllMain (HINSTANCE, DWORD, LPVOID); - -@@ -214,13 +214,13 @@ _p11_library_get_thread_local (void) - { - LPVOID data; - -- if (thread_local == TLS_OUT_OF_INDEXES) -+ if (threadlocal == TLS_OUT_OF_INDEXES) - return NULL; - -- data = TlsGetValue (thread_local); -+ data = TlsGetValue (threadlocal); - if (data == NULL) { - data = LocalAlloc (LPTR, sizeof (p11_local)); -- TlsSetValue (thread_local, data); -+ TlsSetValue (threadlocal, data); - } - - return (p11_local *)data; -@@ -233,8 +233,8 @@ p11_library_init (void) - p11_debug ("initializing library"); - P11_RECURSIVE_MUTEX_INIT (p11_library_mutex); - P11_RECURSIVE_MUTEX_INIT (p11_virtual_mutex); -- thread_local = TlsAlloc (); -- if (thread_local == TLS_OUT_OF_INDEXES) -+ threadlocal = TlsAlloc (); -+ if (threadlocal == TLS_OUT_OF_INDEXES) - p11_debug ("couldn't setup tls"); - else - p11_message_storage = thread_local_message; -@@ -244,9 +244,9 @@ void - p11_library_thread_cleanup (void) - { - p11_local *local; -- if (thread_local != TLS_OUT_OF_INDEXES) { -+ if (threadlocal != TLS_OUT_OF_INDEXES) { - p11_debug ("thread stopped, freeing tls"); -- local = TlsGetValue (thread_local); -+ local = TlsGetValue (threadlocal); - LocalFree (local); - } - } -@@ -258,11 +258,11 @@ p11_library_uninit (void) - - uninit_common (); - -- if (thread_local != TLS_OUT_OF_INDEXES) { -+ if (threadlocal != TLS_OUT_OF_INDEXES) { - p11_message_storage = dont_store_message; -- data = TlsGetValue (thread_local); -+ data = TlsGetValue (threadlocal); - LocalFree (data); -- TlsFree (thread_local); -+ TlsFree (threadlocal); - } - p11_mutex_uninit (&p11_virtual_mutex); - p11_mutex_uninit (&p11_library_mutex); --- -2.49.0 - diff --git a/p11-kit.spec b/p11-kit.spec index 3dc3568..3b87417 100644 --- a/p11-kit.spec +++ b/p11-kit.spec @@ -1,23 +1,17 @@ # This spec file has been automatically updated -%if 0%{?fedora} -%bcond_without mingw -%else -%bcond_with mingw -%endif - - -Version: 0.25.8 -Release: %{?autorelease}%{!?autorelease:1%{?dist}} +Version: 0.23.22 +Release: 2%{?dist} Name: p11-kit Summary: Library for loading and sharing PKCS#11 modules -License: BSD-3-Clause +License: BSD URL: http://p11-glue.freedesktop.org/p11-kit.html Source0: https://github.com/p11-glue/p11-kit/releases/download/%{version}/p11-kit-%{version}.tar.xz Source1: https://github.com/p11-glue/p11-kit/releases/download/%{version}/p11-kit-%{version}.tar.xz.sig -Source2: https://p11-glue.github.io/p11-glue/p11-kit/p11-kit-release-keyring.gpg +Source2: gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg Source3: trust-extract-compat Source4: p11-kit-client.service +Patch0: p11-kit-0.23.22-progname-leak.patch BuildRequires: gcc BuildRequires: libtasn1-devel >= 2.3 @@ -26,48 +20,19 @@ BuildRequires: gettext BuildRequires: gtk-doc BuildRequires: meson BuildRequires: systemd-devel -BuildRequires: pkgconfig(bash-completion) +BuildRequires: bash-completion # Work around for https://bugzilla.redhat.com/show_bug.cgi?id=1497147 # Remove this once it is fixed BuildRequires: pkgconfig(glib-2.0) -BuildRequires: pkgconfig(systemd) BuildRequires: gnupg2 BuildRequires: /usr/bin/xsltproc -%if %{with mingw} -BuildRequires: ninja-build - -BuildRequires: mingw32-filesystem >= 95 -BuildRequires: mingw32-gcc -BuildRequires: mingw32-binutils -BuildRequires: mingw32-libffi -BuildRequires: mingw32-libtasn1 - -BuildRequires: mingw64-filesystem >= 95 -BuildRequires: mingw64-gcc -BuildRequires: mingw64-binutils -BuildRequires: mingw64-libffi -BuildRequires: mingw64-libtasn1 -%endif - - %description p11-kit provides a way to load and enumerate PKCS#11 modules, as well as a standard configuration setup for installing PKCS#11 modules in such a way that they're discoverable. -%package client -Summary: Client module from %{name} -Requires: %{name}%{?_isa} = %{version}-%{release} -Obsoletes: %{name}-server < 0.25.5-8 - -%description client -The %{name}-client package contains a PKCS#11 module that enables -accessing other PKCS#11 modules over a Unix domain socket. Note that -this feature is still experimental. - - %package devel Summary: Development files for %{name} Requires: %{name}%{?_isa} = %{version}-%{release} @@ -80,19 +45,18 @@ developing applications that use %{name}. %package trust Summary: System trust module from %{name} Requires: %{name}%{?_isa} = %{version}-%{release} -Requires(post): %{_sbindir}/alternatives -Requires(postun): %{_sbindir}/alternatives +Requires(post): %{_sbindir}/update-alternatives +Requires(postun): %{_sbindir}/update-alternatives Conflicts: nss < 3.14.3-9 %description trust The %{name}-trust package contains a system trust PKCS#11 module which -contains certificate anchors and blocklists. +contains certificate anchors and black lists. %package server -Summary: Server command for %{name} +Summary: Server and client commands for %{name} Requires: %{name}%{?_isa} = %{version}-%{release} -Obsoletes: %{name}-server < 0.25.5-8 %description server The %{name}-server package contains command line tools that enable to @@ -100,33 +64,6 @@ export PKCS#11 modules through a Unix domain socket. Note that this feature is still experimental. -%if %{with mingw} -%package -n mingw32-%{name} -Summary: MinGW Library for loading and sharing PKCS#11 modules -Requires: pkgconfig -BuildArch: noarch - -%description -n mingw32-%{name} -p11-kit provides a way to load and enumerate PKCS#11 modules, as well as -a standard configuration setup for installing PKCS#11 modules in such a -way that they're discoverable. This library is cross-compiled for MinGW. - - -%package -n mingw64-%{name} -Summary: MinGW Library for loading and sharing PKCS#11 modules -Requires: pkgconfig -BuildArch: noarch - -%description -n mingw64-%{name} -p11-kit provides a way to load and enumerate PKCS#11 modules, as well as -a standard configuration setup for installing PKCS#11 modules in such a -way that they're discoverable. This library is cross-compiled for MinGW. - - -%{?mingw_debug_package} -%endif - - # solution taken from icedtea-web.spec %define multilib_arches ppc64 sparc64 x86_64 ppc64le %ifarch %{multilib_arches} @@ -142,16 +79,11 @@ gpgv2 --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %autosetup -p1 %build -# These paths are the source paths that come from the plan here: +# These paths are the source paths that come from the plan here: # https://fedoraproject.org/wiki/Features/SharedSystemCertificates:SubTasks %meson -Dgtk_doc=true -Dman=true -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source %meson_build -%if %{with mingw} -%mingw_meson -Dgtk_doc=false -Dman=false -Dnls=false -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source -Dzsh_completion=disabled -%mingw_ninja -%endif - %install %meson_install mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pkcs11/modules @@ -163,23 +95,18 @@ mkdir -p $RPM_BUILD_ROOT%{_userunitdir} install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_userunitdir} %find_lang %{name} -%if %{with mingw} -%mingw_ninja_install - -%{?mingw_debug_install_post} -%endif - %check %meson_test %post trust -alternatives --install %{_libdir}/libnssckbi.so %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so 30 +%{_sbindir}/update-alternatives --install %{_libdir}/libnssckbi.so \ + %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so 30 %postun trust if [ $1 -eq 0 ] ; then # package removal - alternatives --remove %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so + %{_sbindir}/update-alternatives --remove %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so fi @@ -192,7 +119,6 @@ fi %dir %{_sysconfdir}/pkcs11/modules %dir %{_datadir}/p11-kit %dir %{_datadir}/p11-kit/modules -%dir %{_libdir}/pkcs11 %dir %{_libexecdir}/p11-kit %{_bindir}/p11-kit %{_libdir}/libp11-kit.so.* @@ -202,11 +128,6 @@ fi %{_mandir}/man8/p11-kit.8.gz %{_mandir}/man5/pkcs11.conf.5.gz %{_datadir}/bash-completion/completions/p11-kit -%{_datadir}/zsh/site-functions/_p11-kit - -%files client -%{_libdir}/pkcs11/p11-kit-client.so -%{_userunitdir}/p11-kit-client.service %files devel %{_includedir}/p11-kit-1/ @@ -216,56 +137,342 @@ fi %files trust %{_bindir}/trust +%dir %{_libdir}/pkcs11 %ghost %{_libdir}/libnssckbi.so %{_libdir}/pkcs11/p11-kit-trust.so %{_datadir}/p11-kit/modules/p11-kit-trust.module %{_libexecdir}/p11-kit/trust-extract-compat %{_datadir}/bash-completion/completions/trust -%{_datadir}/zsh/site-functions/_trust %files server +%{_libdir}/pkcs11/p11-kit-client.so +%{_userunitdir}/p11-kit-client.service %{_libexecdir}/p11-kit/p11-kit-server %{_userunitdir}/p11-kit-server.service %{_userunitdir}/p11-kit-server.socket -%if %{with mingw} -%files -n mingw32-%{name} -%{!?_licensedir:%global license %%doc} -%license COPYING -%{mingw32_bindir}/libp11-kit-0.dll -%{mingw32_bindir}/p11-kit.exe -%{mingw32_bindir}/trust.exe -%{mingw32_libdir}/libp11-kit.dll.a -%dir %{mingw32_libdir}/pkcs11/ -%{mingw32_libdir}/pkcs11/p11-kit-trust.dll -%{mingw32_libdir}/pkcs11/p11-kit-trust.dll.a -%{mingw32_libdir}/pkgconfig/p11-kit-1.pc -%dir %{mingw32_libexecdir}/p11-kit/ -%{mingw32_libexecdir}/p11-kit/*.exe -%{mingw32_libexecdir}/p11-kit/trust-extract-compat -%{mingw32_includedir}/p11-kit-1/ -%{mingw32_datadir}/p11-kit/ -%{mingw32_sysconfdir}/pkcs11/ - -%files -n mingw64-%{name} -%{!?_licensedir:%global license %%doc} -%license COPYING -%{mingw64_bindir}/libp11-kit-0.dll -%{mingw64_bindir}/p11-kit.exe -%{mingw64_bindir}/trust.exe -%{mingw64_libdir}/libp11-kit.dll.a -%dir %{mingw64_libdir}/pkcs11/ -%{mingw64_libdir}/pkcs11/p11-kit-trust.dll -%{mingw64_libdir}/pkcs11/p11-kit-trust.dll.a -%{mingw64_libdir}/pkgconfig/p11-kit-1.pc -%dir %{mingw64_libexecdir}/p11-kit/ -%{mingw64_libexecdir}/p11-kit/*.exe -%{mingw64_libexecdir}/p11-kit/trust-extract-compat -%{mingw64_includedir}/p11-kit-1/ -%{mingw64_datadir}/p11-kit/ -%{mingw64_sysconfdir}/pkcs11/ -%endif - %changelog -%autochangelog +* Tue Jan 26 2021 Daiki Ueno - 0.23.22-2 +- Suppress intentional memleak in getprogname emulation (#1905581) + +* Fri Dec 11 2020 Packit Service - 0.23.22-1 +- Release 0.23.22 (Daiki Ueno) +- Follow-up to arithmetic overflow fix (David Cook) +- Check for arithmetic overflows before allocating (David Cook) +- Check attribute length against buffer size (David Cook) +- Fix bounds check in p11_rpc_buffer_get_byte_array (David Cook) +- Fix buffer overflow in log_token_info (David Cook) +- common: Don't assume __STDC_VERSION__ is always defined (Daiki Ueno) +- compat: getauxval: correct compiler macro for FreeBSD (Daiki Ueno) +- compat: fdwalk: add guard for Linux specific local variables (Daiki Ueno) +- meson: Add missing libtasn1 dependency (Daiki Ueno) +- travis: Add freebsd build (Daiki Ueno) +- anchor: Prefer persistent format when storing anchor (Daiki Ueno) +- travis: Run "make check" along with "make distcheck" for coverage (Daiki Ueno) +- travis: Use python3 as the default Python interpreter (Daiki Ueno) +- travis: Route to Ubuntu 20.04 base image (Daiki Ueno) +- meson: Set -fstack-protector for MinGW64 cross build (Daiki Ueno) +- meson: expand ternary operator in function call for compatibility (Daiki Ueno) +- meson: Use custom_target for generating external XML entities (Daiki Ueno) +- meson: Allow building manpages without gtk-doc (Jan Alexander Steffens (heftig)) +- Rename is_path_component to is_path_separator (Alexander Sosedkin) +- Use is_path_component in one more place (Alexander Sosedkin) +- Remove more duplicate separators in p11_path_build (Alexander Sosedkin) +- common: Fix infloop in p11_path_build (Daiki Ueno) +- proxy: C_CloseAllSessions: Make sure that calloc args are non-zero (Daiki Ueno) +- build: Use calloc in a consistent manner (Daiki Ueno) +- meson: Allow override of default bashcompdir. Fixes meson regression (issue #322). Pass -Dbashcompdir=/xxx to meson. (John Hein) +- common: Check for a NULL locale before freeing it (Tavian Barnes) +- p11_test_copy_setgid: Skip setgid tests on nosuid filesystems (Anders Kaseorg) +- unix-peer: replace incorrect include1 (Rosen Penev) +- test-compat: Skip getprogname test if BUILDDIR contains a symlink (Daiki Ueno) +- add trust-extract-compat into EXTRA-DIST (Xℹ Ruoyao) +- meson: install trust-extract-compat (Xℹ Ruoyao) +- rename trust-extract-compat.in to trust-extract-compat (Xℹ Ruoyao) + +* Tue Aug 18 2020 Packit Service - 0.23.21-2 +- new upstream release: 0.23.21 + +* Wed Jan 29 2020 Daiki Ueno - 0.23.20-1 +- Update to upstream 0.23.20 release + +* Wed Jan 22 2020 Daiki Ueno - 0.23.19-1 +- Update to upstream 0.23.19 release +- Check archive signature in %%prep +- Switch to using Meson as the build system + +* Mon Sep 30 2019 Daiki Ueno - 0.23.18.1-1 +- Update to upstream 0.23.18.1 release + +* Thu Jul 25 2019 Fedora Release Engineering - 0.23.16.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Thu May 23 2019 Daiki Ueno - 0.23.16.1-1 +- Update to upstream 0.23.16.1 release + +* Thu May 23 2019 Daiki Ueno - 0.23.16-1 +- Update to upstream 0.23.16 release + +* Mon Feb 18 2019 Daiki Ueno - 0.23.15-3 +- trust: Ignore unreadable content in anchors + +* Fri Feb 01 2019 Fedora Release Engineering - 0.23.15-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Mon Jan 21 2019 Daiki Ueno - 0.23.15-1 +- Update to upstream 0.23.15 release + +* Fri Jan 11 2019 Nils Philippsen - 0.23.14-3 +- use spaces instead of tabs consistently +- prefer fixed closures to libffi closures (#1656245, patch by Daiki Ueno) + +* Mon Oct 29 2018 James Antill - 0.23.14-2 +- Remove ldconfig scriptlet, now done via. transfiletrigger in glibc. + +* Fri Sep 07 2018 Daiki Ueno - 0.23.14-1 +- Update to upstream 0.23.14 release + +* Wed Aug 15 2018 Daiki Ueno - 0.23.13-3 +- Forcibly link with libpthread to avoid regressions (rhbz#1615038) + +* Wed Aug 15 2018 Daiki Ueno - 0.23.13-2 +- Fix invalid memory access on proxy cleanup + +* Fri Aug 10 2018 Daiki Ueno - 0.23.13-1 +- Update to upstream 0.23.13 release + +* Fri Jul 13 2018 Fedora Release Engineering - 0.23.12-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Wed May 30 2018 Daiki Ueno - 0.23.12-1 +- Update to upstream 0.23.11 release + +* Wed Feb 28 2018 Daiki Ueno - 0.23.10-1 +- Update to upstream 0.23.10 release + +* Thu Feb 08 2018 Fedora Release Engineering - 0.23.9-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Thu Oct 05 2017 Daiki Ueno - 0.23.9-2 +- server: Make it possible to eval envvar settings + +* Wed Oct 04 2017 Daiki Ueno - 0.23.9-1 +- Update to upstream 0.23.9 + +* Fri Aug 25 2017 Kai Engert - 0.23.8-2 +- Fix a regression caused by a recent nss.rpm change, add a %%ghost file + for %%{_libdir}/libnssckbi.so that p11-kit-trust scripts install. + +* Tue Aug 15 2017 Daiki Ueno - 0.23.8-1 +- Update to 0.23.8 release + +* Thu Aug 03 2017 Fedora Release Engineering - 0.23.7-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 0.23.7-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Fri Jun 2 2017 Daiki Ueno - 0.23.7-1 +- Update to 0.23.7 release + +* Thu May 18 2017 Daiki Ueno - 0.23.5-3 +- Update p11-kit-modifiable.patch to simplify the logic + +* Thu May 18 2017 Daiki Ueno - 0.23.5-2 +- Make "trust anchor --remove" work again + +* Thu Mar 2 2017 Daiki Ueno - 0.23.5-1 +- Update to 0.23.5 release +- Rename -tools subpackage to -server and remove systemd unit files + +* Fri Feb 24 2017 Daiki Ueno - 0.23.4-3 +- Move p11-kit command back to main package + +* Fri Feb 24 2017 Daiki Ueno - 0.23.4-2 +- Split out command line tools to -tools subpackage, to avoid a + multilib issue with the main package. Suggested by Yanko Kaneti. + +* Wed Feb 22 2017 Daiki Ueno - 0.23.4-1 +- Update to 0.23.4 release + +* Sat Feb 11 2017 Fedora Release Engineering - 0.23.3-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Jan 6 2017 Daiki Ueno - 0.23.3-2 +- Use internal hash implementation instead of NSS (#1390598) + +* Tue Dec 20 2016 Daiki Ueno - 0.23.3-1 +- Update to 0.23.3 release +- Adjust executables location from %%libdir to %%libexecdir + +* Thu Feb 04 2016 Fedora Release Engineering - 0.23.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Tue Jan 12 2016 Martin Preisler - 0.23.2-1 +- Update to stable 0.23.2 release + +* Tue Jun 30 2015 Martin Preisler - 0.23.1-4 +- In proxy module don't call C_Finalize on a forked process [#1217915] +- Do not deinitialize libffi's wrapper functions [#1217915] + +* Thu Jun 18 2015 Fedora Release Engineering - 0.23.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Sat Feb 21 2015 Till Maas - 0.23.1-2 +- Rebuilt for Fedora 23 Change + https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code + +* Fri Feb 20 2015 Stef Walter - 0.23.1-1 +- Update to 0.23.1 release + +* Thu Oct 09 2014 Stef Walter - 0.22.1-1 +- Update to 0.22.1 release +- Use SubjectKeyIdentifier as a CKA_ID if possible rhbz#1148895 + +* Sat Oct 04 2014 Stef Walter 0.22.0-1 +- Update to 0.22.0 release + +* Wed Sep 17 2014 Stef Walter 0.21.3-1 +- Update to 0.21.3 release +- Includes definitions for trust extensions rhbz#1136817 + +* Fri Sep 05 2014 Stef Walter 0.21.2-1 +- Update to 0.21.2 release +- Fix problems with erroneous messages printed rhbz#1133857 + +* Sun Aug 17 2014 Fedora Release Engineering - 0.21.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Thu Aug 07 2014 Stef Walter - 0.21.1-1 +- Update to 0.21.1 release + +* Wed Jul 30 2014 Tom Callaway - 0.20.3-3 +- fix license handling + +* Fri Jul 04 2014 Stef Walter - 0.20.3-2 +- Update to stable 0.20.3 release + +* Fri Jun 06 2014 Fedora Release Engineering - 0.20.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sat Jan 25 2014 Ville Skyttä - 0.20.2-2 +- Own the %%{_libdir}/pkcs11 dir in -trust. + +* Tue Jan 14 2014 Stef Walter - 0.20.2-1 +- Update to upstream stable 0.20.2 release +- Fix regression involving blacklisted anchors [#1041328] +- Support ppc64le in build [#1052707] + +* Mon Sep 09 2013 Stef Walter - 0.20.1-1 +- Update to upstream stable 0.20.1 release +- Extract compat trust data after we've changes +- Skip compat extraction if running as non-root +- Better failure messages when removing anchors + +* Thu Aug 29 2013 Stef Walter - 0.19.4-1 +- Update to new upstream 0.19.4 release + +* Sat Aug 03 2013 Fedora Release Engineering - 0.19.3-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Wed Jul 24 2013 Stef Walter - 0.19.3-1 +- Update to new upstream 0.19.3 release (#967822) + +* Wed Jun 05 2013 Stef Walter - 0.18.3-1 +- Update to new upstream stable release +- Fix intermittent firefox cert validation issues (#960230) +- Include the manual pages in the package + +* Tue May 14 2013 Stef Walter - 0.18.2-1 +- Update to new upstream stable release +- Reduce the libtasn1 dependency minimum version + +* Thu May 02 2013 Stef Walter - 0.18.1-1 +- Update to new upstream stable release +- 'p11-kit extract-trust' lives in libdir + +* Thu Apr 04 2013 Stef Walter - 0.18.0-1 +- Update to new upstream stable release +- Various logging tweaks (#928914, #928750) +- Make the 'p11-kit extract-trust' explicitly reject + additional arguments + +* Thu Mar 28 2013 Stef Walter - 0.17.5-1 +- Make 'p11-kit extract-trust' call update-ca-trust +- Work around 32-bit oveflow of certificate dates +- Build fixes + +* Tue Mar 26 2013 Stef Walter - 0.17.4-2 +- Pull in patch from upstream to fix build on ppc (#927394) + +* Wed Mar 20 2013 Stef Walter - 0.17.4-1 +- Update to upstream version 0.17.4 + +* Mon Mar 18 2013 Stef Walter - 0.17.3-1 +- Update to upstream version 0.17.3 +- Put the trust input paths in the right order + +* Tue Mar 12 2013 Stef Walter - 0.16.4-1 +- Update to upstream version 0.16.4 + +* Fri Mar 08 2013 Stef Walter - 0.16.3-1 +- Update to upstream version 0.16.3 +- Split out system trust module into its own package. +- p11-kit-trust provides an alternative to an nss module + +* Tue Mar 05 2013 Stef Walter - 0.16.1-1 +- Update to upstream version 0.16.1 +- Setup source directories as appropriate for Shared System Certificates feature + +* Tue Mar 05 2013 Stef Walter - 0.16.0-1 +- Update to upstream version 0.16.0 + +* Thu Feb 14 2013 Fedora Release Engineering - 0.14-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Mon Sep 17 2012 Kalev Lember - 0.14-1 +- Update to 0.14 + +* Fri Jul 20 2012 Fedora Release Engineering - 0.13-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Mon Jul 16 2012 Kalev Lember - 0.13-1 +- Update to 0.13 + +* Tue Mar 27 2012 Kalev Lember - 0.12-1 +- Update to 0.12 +- Run self tests in %%check + +* Sat Feb 11 2012 Kalev Lember - 0.11-1 +- Update to 0.11 + +* Fri Jan 13 2012 Fedora Release Engineering - 0.9-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Tue Dec 20 2011 Matthias Clasen - 0.9-1 +- Update to 0.9 + +* Wed Oct 26 2011 Kalev Lember - 0.8-1 +- Update to 0.8 + +* Mon Sep 19 2011 Matthias Clasen - 0.6-1 +- Update to 0.6 + +* Sun Sep 04 2011 Kalev Lember - 0.5-1 +- Update to 0.5 + +* Sun Aug 21 2011 Kalev Lember - 0.4-1 +- Update to 0.4 +- Install the example config file to documentation directory + +* Wed Aug 17 2011 Kalev Lember - 0.3-2 +- Tighten -devel subpackage deps (#725905) + +* Fri Jul 29 2011 Kalev Lember - 0.3-1 +- Update to 0.3 +- Upstream rewrote the ASL 2.0 bits, which makes the whole package + BSD-licensed + +* Tue Jul 12 2011 Kalev Lember - 0.2-1 +- Initial RPM release diff --git a/sources b/sources index 418f67a..66d9389 100644 --- a/sources +++ b/sources @@ -1,3 +1 @@ -SHA512 (p11-kit-0.25.8.tar.xz) = 4a3852459a4a5e4ea71eea5d23ef74deeb51c66b28d095be30a263f10d1f47853341f8628eb0c43c88247503059a4c1f67017965a70cd3c7df31d86e458a8162 -SHA512 (p11-kit-0.25.8.tar.xz.sig) = 97f47324cd7578833b751ab1fee55a9a538ba94b52ec4729249a9e5494c60cceef6c60999b495299f2b9ae0d0cda60d5db713d82e0b7991112b7b4b46ad46d1d -SHA512 (p11-kit-release-keyring.gpg) = 9a832a8ac3a139cbbf1ecb66573f0709847ebfef4975777cf82b4dca09af1ad8e6400f0af0bcdb92860e7ed4fc05082ba1edda0238a21fe24d49555a1069e881 +SHA512 (p11-kit-0.23.22.tar.xz) = 098819e6ca4ad9cc2a0bc2e478aea67354d051a4f03e6c7d75d13d2469b6dc7654f26b15530052f6ed51acb35531c2539e0f971b31e29e6673e857c903afb080