Compare commits

...
Sign in to create a new pull request.

24 commits

Author SHA1 Message Date
Packit
a33bf8feb9 Update to 0.25.8 upstream release
Upstream tag: 0.25.8
Upstream commit: 2ee61264

Commit authored by Packit automation (https://packit.dev/)
2025-09-13 10:13:07 +09:00
Packit
6d11b1e9cb Update to 0.25.6 upstream release
- Resolves: rhbz#2394061

Upstream tag: 0.25.6
Upstream commit: 4f821372

Commit authored by Packit automation (https://packit.dev/)
2025-09-09 23:36:44 +09:00
Daiki Ueno
8a33186b2f rpc: Fix empty array attribute handling
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2025-09-03 20:26:02 +09:00
Fedora Release Engineering
44c46c2705 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-24 23:50:34 +00:00
Debarshi Ray
27179e46de Split p11-kit-client.so into a separate sub-package
Strictly speaking, the same container or machine doesn't need to have
both the p11-kit-client.so module and the p11-kit-server executable.
eg., Flatpak and Toolbx need only the p11-kit-server executable to be
present on the host machine, and need only the p11-kit-client.so module
inside the container.

Therefore, splitting the 'server' sub-package [1] will avoid having
unexpected content in containers and machines.

A Release number of 8 was chosen for the Version-Release tuple in
'Obsoletes', because that will be the Release number of this commit
according to %{autorelease}:
  $ rpmautospec calculate-release
  Calculated release number: 8

[1] https://docs.fedoraproject.org/en-US/packaging-guidelines/#_one_to_many_replacement

https://src.fedoraproject.org/rpms/p11-kit/pull-request/53
2025-05-15 13:46:54 +02:00
Debarshi Ray
509127e98c Move ownership of %{_libdir}/pkcs11 to the main package
Commit 35e6a95319 made the 'trust' sub-package own the
%{_libdir}/pkcs11 directory at a time when p11-kit-trust.so was the only
PKCS#11 module being shipped by p11-kit.

Since then, commit 7c8cb45032 or p11-kit-0.23.4 introduced the
p11-kit-client.so module.  It was initially part of the main package,
until was split into its own sub-package in commit adb7cbe63f.
Even though it doesn't depend directly on the 'trust' module, it
depended on it to own the %{_libdir}/pkcs11 directory.

It will be better if the main package owns the %{_libdir}/pkcs11
directory, just like it already owns %{_sysconfdir}/pkcs11, so that the
directory doesn't have to be separately owned by multiple sub-packages.

https://src.fedoraproject.org/rpms/p11-kit/pull-request/53
2025-05-15 13:41:15 +02:00
Debarshi Ray
a8fa1a940d Fix the MingGW build with GCC 15.1.1
Otherwise, it leads to:
  [22/338] Compiling C object common/libp11-library.a.p/library.c.obj
  FAILED: common/libp11-library.a.p/library.c.obj
  i686-w64-mingw32-gcc -Icommon/libp11-library.a.p -Icommon -I../common
      -I. -I.. -fvisibility=hidden -fdiagnostics-color=always
      -D_FILE_OFFSET_BITS=64 -Wall -Winvalid-pch -O0 -g -D_GNU_SOURCE
      -DP11_KIT_FUTURE_UNSTABLE_API -O2 -g -pipe -Wall
      -Wp,-D_FORTIFY_SOURCE=2 -fexceptions --param=ssp-buffer-size=4 -MD
      -MQ common/libp11-library.a.p/library.c.obj -MF
      common/libp11-library.a.p/library.c.obj.d -o
      common/libp11-library.a.p/library.c.obj -c ../common/library.c
  ../common/library.c:208:27: error: expected identifier or '(' before
      '=' token
    208 | static DWORD thread_local = TLS_OUT_OF_INDEXES;
        |                           ^
  ../common/library.c: In function '_p11_library_get_thread_local':
  ../common/library.c:217:26: error: expected identifier or '(' before
      '==' token
    217 |         if (thread_local == TLS_OUT_OF_INDEXES)
        |                          ^~
  ../common/library.c:217:13: error: declaration in the controlling
      expression must have an initializer
    217 |         if (thread_local == TLS_OUT_OF_INDEXES)
        |             ^~~~~~~~~~~~
  ../common/library.c:220:29: error: expected expression before
      'thread_local'
    220 |         data = TlsGetValue (thread_local);
        |                             ^~~~~~~~~~~~
  ../common/library.c:223:30: error: expected expression before
      'thread_local'
    223 |                 TlsSetValue (thread_local, data);
        |                              ^~~~~~~~~~~~
  ../common/library.c:223:17: error: too few arguments to function
      'TlsSetValue'; expected 2, have 1
    223 |                 TlsSetValue (thread_local, data);
        |                 ^~~~~~~~~~~

https://src.fedoraproject.org/rpms/p11-kit/pull-request/54
2025-05-14 18:39:18 +02:00
Fedora Release Engineering
b4943bcb3d Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-17 22:08:21 +00:00
Zoltan Fridrich
8a8660a738 Integrate mingw-p11-kit into spec file
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2024-10-08 11:07:04 +02:00
Fedora Release Engineering
1c9cf0a627 Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-18 21:16:09 +00:00
Zbigniew Jędrzejewski-Szmek
89bca1f9d6 Call alternatives without full path
As part of https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin,
alternatives is moved from /usr/sbin/alternatives to /usr/bin/alternatives.
(This happened when alternatives rpm was rebuilt in a build
environment with the updated definitions.)
On traditional systems a compat symlink is created, so both paths
work. This means that packages that use paths into /usr/sbin do not
need to be rebuilt and will continue to work fine. Unfortunately, on
ostree systems, the compat symlinks are missing, so calls to
/usr/sbin/alternatives fail.

In addition, when _this_ package will be rebuilt in an environment
with the updated definitions, its script will try to call
/usr/bin/alternatives, which in turn will not work on systems with an
older build of alternatives, where only /usr/sbin/alternatives exists,
but not /usr/bin/alternatives, and /usr/sbin is not a symlink to
/usr/bin.

There is no reason for or benefit from specifying the full path to
binaries in scriptlets because the scriptlets are called with a
well-defined $PATH. So drop the full path, so that the package
works fine no matter where exactly alternatives is installed.
2024-07-12 14:51:36 +02:00
Packit
83f95a1eee Update to 0.25.5 upstream release
Upstream tag: 0.25.5
Upstream commit: 0dd11336

Commit authored by Packit automation (https://packit.dev/)
2024-07-04 13:08:10 +02:00
Yaakov Selkowitz
5037388f87 Fix bash-completion build dependency
The pkgconfig data has been split out into bash-completion-devel for F41.
2024-06-21 15:31:43 -04:00
Daiki Ueno
4591e32cb1 import-object: Avoid integer truncation on 32-bit platforms
Fixes: #2261437
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2024-01-31 11:09:29 +09:00
Fedora Release Engineering
a088c987f2 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-25 11:44:40 +00:00
Fedora Release Engineering
34faad315d Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-21 11:39:08 +00:00
Packit
ed0f630c7a [packit] 0.25.3 upstream release
Upstream tag: 0.25.3
Upstream commit: 917e02a3
2023-11-15 12:51:54 +00:00
Zoltan Fridrich
813fe621e6 Replace "black list" with "blocklist" in package description
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2023-11-08 11:08:29 +01:00
Packit
dd7fdb54d6 [packit] 0.25.2 upstream release
Upstream tag: 0.25.2
Upstream commit: 66d6b42e
2023-10-31 09:27:24 +00:00
Packit
aab0f5c7d6 [packit] 0.25.1 upstream release
Upstream tag: 0.25.1
Upstream commit: 3ee32232
2023-10-26 10:03:53 +00:00
Daiki Ueno
93cc8c15ca Migrate License field to SPDX license identifier
Signed-off-by: Daiki Ueno <dueno@redhat.com>
2023-08-24 10:37:57 +09:00
Zoltan Fridrich
c65bf3c0a5 Merge #25 [packit] 0.25.0 upstream release 2023-07-24 07:24:22 +00:00
Fedora Release Engineering
8c546cbf7c Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-20 18:27:01 +00:00
Packit
b1c8544e78 [packit] 0.25.0 upstream release
Upstream tag: 0.25.0
Upstream commit: a8cce8bd
2023-07-14 13:40:25 +02:00
14 changed files with 364 additions and 141 deletions

15
.gitignore vendored
View file

@ -35,3 +35,18 @@
/p11-kit-0.23.21.tar.xz
/p11-kit-0.23.22.tar.xz
/p11-kit-0.24.1.tar.xz
/p11-kit-0.25.0.tar.xz
/p11-kit-0.25.0.tar.xz.sig
/p11-kit-release-keyring.gpg
/p11-kit-0.25.1.tar.xz
/p11-kit-0.25.1.tar.xz.sig
/p11-kit-0.25.2.tar.xz
/p11-kit-0.25.2.tar.xz.sig
/p11-kit-0.25.3.tar.xz
/p11-kit-0.25.3.tar.xz.sig
/p11-kit-0.25.5.tar.xz
/p11-kit-0.25.5.tar.xz.sig
/p11-kit-0.25.6.tar.xz
/p11-kit-0.25.6.tar.xz.sig
/p11-kit-0.25.8.tar.xz
/p11-kit-0.25.8.tar.xz.sig

View file

@ -1,3 +1,3 @@
This repository is maintained by packit.
https://packit.dev/
The file was generated using packit 0.43.1.dev8+ga0f2a9f.
The file was generated using packit 1.11.0.post1.dev7+gfdcdf3a32.

Binary file not shown.

Binary file not shown.

View file

@ -1,87 +0,0 @@
From 40fbf74b02b8ad6625e3aa49d2cdef2b52e47a04 Mon Sep 17 00:00:00 2001
From: Daiki Ueno <ueno@gnu.org>
Date: Mon, 25 Jan 2021 18:24:01 +0100
Subject: [PATCH] compat: Pacify ASan complaints on intentionally leaked buffer
Reported by Viktor Ashirov in:
https://bugzilla.redhat.com/show_bug.cgi?id=1905581
---
common/compat.c | 25 +++++++++++++++++++------
common/library.c | 9 +++++++++
2 files changed, 28 insertions(+), 6 deletions(-)
diff --git a/common/compat.c b/common/compat.c
index 4390cef..d6c5af6 100644
--- a/common/compat.c
+++ b/common/compat.c
@@ -100,6 +100,19 @@ extern char *program_invocation_short_name;
extern char *__progname;
#endif
+#ifdef __linux__
+/* This symbol is also defined in library.c so as to be freed by the library
+ * destructor. If weak symbols are not supported nor library.c is not linked we
+ * simply leak the memory allocated with realpath(). */
+#ifdef __GNUC__
+extern char *p11_program_realpath;
+
+char *p11_program_realpath __attribute__((weak));
+#else
+static char *p11_program_realpath;
+#endif
+#endif
+
const char *
getprogname (void)
{
@@ -124,14 +137,14 @@ getprogname (void)
* Logic borrowed from:
* <https://github.com/mesa3d/mesa/commit/759b94038987bb983398cd4b1d2cb1c8f79817a9>.
*/
- static char *buf;
-
- if (!buf)
- buf = realpath ("/proc/self/exe", NULL);
+ if (!p11_program_realpath)
+ p11_program_realpath = realpath ("/proc/self/exe", NULL);
- if (buf && strncmp (buf, name, strlen (buf)) == 0)
+ if (p11_program_realpath &&
+ strncmp (p11_program_realpath, name,
+ strlen (p11_program_realpath)) == 0)
/* Use the executable path if the prefix matches. */
- name = strrchr (buf, '/') + 1;
+ name = strrchr (p11_program_realpath, '/') + 1;
else
/* Otherwise fall back to
* program_invocation_short_name. */
diff --git a/common/library.c b/common/library.c
index 891344a..1581702 100644
--- a/common/library.c
+++ b/common/library.c
@@ -82,6 +82,11 @@ unsigned int p11_forkid = 1;
extern locale_t p11_message_locale;
#endif
+#ifdef __linux__
+/* used only under __linux__ in the getprogname() emulation in compat.c. */
+char *p11_program_realpath;
+#endif
+
static char *
thread_local_message (void)
{
@@ -190,6 +195,10 @@ p11_library_uninit (void)
#endif
p11_mutex_uninit (&p11_virtual_mutex);
p11_mutex_uninit (&p11_library_mutex);
+
+#ifdef __linux__
+ free (p11_program_realpath);
+#endif
}
#endif /* OS_UNIX */
--
2.29.2

Binary file not shown.

Binary file not shown.

View file

@ -0,0 +1,62 @@
From e94c1fb907546faafb3509615943776d1ea37eb8 Mon Sep 17 00:00:00 2001
From: Daiki Ueno <ueno@gnu.org>
Date: Wed, 3 Sep 2025 17:10:21 +0900
Subject: [PATCH] rpc: Fix empty array attribute handling
When an empty array attribute is exchanged at the RPC level, the
client previously sent the number of elements (= 0) even if it's
empty, while the server doesn't expect it. This fixes the client to
not send it.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
---
p11-kit/rpc-message.c | 2 +-
p11-kit/test-mock.c | 12 ++++++++++++
2 files changed, 13 insertions(+), 1 deletion(-)
diff --git a/p11-kit/rpc-message.c b/p11-kit/rpc-message.c
index 049417f..5eaea61 100644
--- a/p11-kit/rpc-message.c
+++ b/p11-kit/rpc-message.c
@@ -266,7 +266,7 @@ p11_rpc_message_write_attribute_buffer_array (p11_rpc_message *msg,
/* And the attribute buffer length */
p11_rpc_buffer_add_uint32 (msg->output, attr->pValue ? attr->ulValueLen : 0);
- if (IS_ATTRIBUTE_ARRAY (attr))
+ if (attr->pValue && IS_ATTRIBUTE_ARRAY (attr))
p11_rpc_message_write_attribute_buffer_array (
msg, attr->pValue,
attr->ulValueLen / sizeof (CK_ATTRIBUTE));
diff --git a/p11-kit/test-mock.c b/p11-kit/test-mock.c
index b117b92..f174015 100644
--- a/p11-kit/test-mock.c
+++ b/p11-kit/test-mock.c
@@ -624,6 +624,12 @@ test_get_wrap_template (void)
{ CKA_WRAP_TEMPLATE, temp, sizeof (temp) },
};
CK_ULONG n_attrs = sizeof (attrs) / sizeof (attrs[0]);
+ CK_OBJECT_CLASS klass = -1ul;
+ CK_ATTRIBUTE attrs_empty_template[] = {
+ { CKA_WRAP_TEMPLATE, NULL, 0 },
+ { CKA_UNWRAP_TEMPLATE, NULL, 0 },
+ };
+ CK_ULONG n_attrs_empty_template = sizeof(attrs_empty_template) / sizeof(attrs_empty_template[0]);
module = setup_mock_module (&session);
@@ -664,6 +670,12 @@ test_get_wrap_template (void)
assert (verify == CK_TRUE);
assert (encrypt == CK_TRUE);
+ rv = (module->C_GetAttributeValue) (session, MOCK_PUBLIC_KEY_CAPITALIZE, attrs_empty_template, n_attrs_empty_template);
+ assert (rv == CKR_ATTRIBUTE_TYPE_INVALID);
+ assert_num_eq (attrs_empty_template[0].type, CKA_WRAP_TEMPLATE);
+ assert_ptr_eq (attrs_empty_template[0].pValue, NULL);
+ assert_num_eq (attrs_empty_template[0].ulValueLen, (CK_ULONG)-1);
+
teardown_mock_module (module);
}
--
2.50.1

View file

@ -0,0 +1,18 @@
diff --git a/meson.build b/meson.build
index ab28396..b5829ca 100644
--- a/meson.build
+++ b/meson.build
@@ -459,6 +459,7 @@ with_systemd = false
systemd = dependency('systemd', required: get_option('systemd'))
if systemd.found()
systemduserunitdir = systemd.get_variable(pkgconfig : 'systemduserunitdir')
+ with_systemd = true
endif
configure_file(output: 'config.h', configuration: conf)
@@ -488,4 +489,4 @@ if get_option('nls')
subdir('po')
endif
subdir('bash-completion')
-subdir('zsh-completion')
+# subdir('zsh-completion')

View file

@ -0,0 +1,134 @@
From fd7ad3969f68ea24e54d242a08b089039555f7bb Mon Sep 17 00:00:00 2001
From: Brecht Sanders <brecht@sanders.org>
Date: Tue, 31 Dec 2024 16:28:31 +0100
Subject: [PATCH] avoid using already defined thread_local as variable name
Building p11-kit 0.25.5 with GCC15 on MinGW-w64 failed because `thread_local` is already defined for this platform.
Resolved by changing the variable name from `thread_local` to `threadlocal`.
---
common/library.c | 36 ++++++++++++++++++------------------
1 file changed, 18 insertions(+), 18 deletions(-)
diff --git a/common/library.c b/common/library.c
index 1581702b62db..723b05f33699 100644
--- a/common/library.c
+++ b/common/library.c
@@ -124,7 +124,7 @@ _p11_library_get_thread_local (void)
return &local;
}
#else
-static pthread_key_t thread_local = 0;
+static pthread_key_t threadlocal = 0;
static p11_local *
_p11_library_get_thread_local (void)
@@ -133,10 +133,10 @@ _p11_library_get_thread_local (void)
p11_library_init_once ();
- local = pthread_getspecific (thread_local);
+ local = pthread_getspecific (threadlocal);
if (local == NULL) {
local = calloc (1, sizeof (p11_local));
- pthread_setspecific (thread_local, local);
+ pthread_setspecific (threadlocal, local);
}
return local;
@@ -158,7 +158,7 @@ p11_library_init_impl (void)
P11_RECURSIVE_MUTEX_INIT (p11_library_mutex);
P11_RECURSIVE_MUTEX_INIT (p11_virtual_mutex);
#ifndef P11_TLS_KEYWORD
- pthread_key_create (&thread_local, free);
+ pthread_key_create (&threadlocal, free);
#endif
p11_message_storage = thread_local_message;
#ifdef HAVE_STRERROR_L
@@ -181,8 +181,8 @@ p11_library_uninit (void)
#ifndef P11_TLS_KEYWORD
/* Some cleanup to pacify valgrind */
- free (pthread_getspecific (thread_local));
- pthread_setspecific (thread_local, NULL);
+ free (pthread_getspecific (threadlocal));
+ pthread_setspecific (threadlocal, NULL);
#endif
#ifdef HAVE_STRERROR_L
@@ -191,7 +191,7 @@ p11_library_uninit (void)
#endif
p11_message_storage = dont_store_message;
#ifndef P11_TLS_KEYWORD
- pthread_key_delete (thread_local);
+ pthread_key_delete (threadlocal);
#endif
p11_mutex_uninit (&p11_virtual_mutex);
p11_mutex_uninit (&p11_library_mutex);
@@ -205,7 +205,7 @@ p11_library_uninit (void)
#ifdef OS_WIN32
-static DWORD thread_local = TLS_OUT_OF_INDEXES;
+static DWORD threadlocal = TLS_OUT_OF_INDEXES;
BOOL WINAPI DllMain (HINSTANCE, DWORD, LPVOID);
@@ -214,13 +214,13 @@ _p11_library_get_thread_local (void)
{
LPVOID data;
- if (thread_local == TLS_OUT_OF_INDEXES)
+ if (threadlocal == TLS_OUT_OF_INDEXES)
return NULL;
- data = TlsGetValue (thread_local);
+ data = TlsGetValue (threadlocal);
if (data == NULL) {
data = LocalAlloc (LPTR, sizeof (p11_local));
- TlsSetValue (thread_local, data);
+ TlsSetValue (threadlocal, data);
}
return (p11_local *)data;
@@ -233,8 +233,8 @@ p11_library_init (void)
p11_debug ("initializing library");
P11_RECURSIVE_MUTEX_INIT (p11_library_mutex);
P11_RECURSIVE_MUTEX_INIT (p11_virtual_mutex);
- thread_local = TlsAlloc ();
- if (thread_local == TLS_OUT_OF_INDEXES)
+ threadlocal = TlsAlloc ();
+ if (threadlocal == TLS_OUT_OF_INDEXES)
p11_debug ("couldn't setup tls");
else
p11_message_storage = thread_local_message;
@@ -244,9 +244,9 @@ void
p11_library_thread_cleanup (void)
{
p11_local *local;
- if (thread_local != TLS_OUT_OF_INDEXES) {
+ if (threadlocal != TLS_OUT_OF_INDEXES) {
p11_debug ("thread stopped, freeing tls");
- local = TlsGetValue (thread_local);
+ local = TlsGetValue (threadlocal);
LocalFree (local);
}
}
@@ -258,11 +258,11 @@ p11_library_uninit (void)
uninit_common ();
- if (thread_local != TLS_OUT_OF_INDEXES) {
+ if (threadlocal != TLS_OUT_OF_INDEXES) {
p11_message_storage = dont_store_message;
- data = TlsGetValue (thread_local);
+ data = TlsGetValue (threadlocal);
LocalFree (data);
- TlsFree (thread_local);
+ TlsFree (threadlocal);
}
p11_mutex_uninit (&p11_virtual_mutex);
p11_mutex_uninit (&p11_library_mutex);
--
2.49.0

View file

@ -1,35 +0,0 @@
Port meson build script to C99. The _Thread_local check used
an implicit int. Future compilers are likely to reject missing
int types by default.
Patch configure.ac as well, although it is not used by the current
Fedora build.
Submitted upstream: <https://github.com/p11-glue/p11-kit/pull/451>
diff --git a/configure.ac b/configure.ac
index be3af55093874750..fc719c78c99c2ac3 100644
--- a/configure.ac
+++ b/configure.ac
@@ -148,7 +148,7 @@ if test "$os_unix" = "yes"; then
[ac_cv_tls_keyword=
for keyword in _Thread_local __thread; do
AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include <stdlib.h>]],
- [[static ]$keyword[ foo;]])],
+ [[static ]$keyword[ int foo;]])],
[ac_cv_tls_keyword=$keyword])
done])
if test -n "$ac_cv_tls_keyword"; then
diff --git a/meson.build b/meson.build
index 64bb3429aef1bb79..aaa3c1f50b5b943f 100644
--- a/meson.build
+++ b/meson.build
@@ -200,7 +200,7 @@ if host_system != 'windows'
tls_test_code_template = '''
#include <stdlib.h>
int main (void) {
-static @0@ foo;
+static @0@ int foo;
return 0;
}
'''

View file

@ -1,17 +1,23 @@
# This spec file has been automatically updated
Version: 0.24.1
Release: %{?autorelease}%{!?autorelease:1%{?dist}}
%if 0%{?fedora}
%bcond_without mingw
%else
%bcond_with mingw
%endif
Version: 0.25.8
Release: %{?autorelease}%{!?autorelease:1%{?dist}}
Name: p11-kit
Summary: Library for loading and sharing PKCS#11 modules
License: BSD
License: BSD-3-Clause
URL: http://p11-glue.freedesktop.org/p11-kit.html
Source0: https://github.com/p11-glue/p11-kit/releases/download/%{version}/p11-kit-%{version}.tar.xz
Source1: https://github.com/p11-glue/p11-kit/releases/download/%{version}/p11-kit-%{version}.tar.xz.sig
Source2: gpgkey-462225C3B46F34879FC8496CD605848ED7E69871.gpg
Source2: https://p11-glue.github.io/p11-glue/p11-kit/p11-kit-release-keyring.gpg
Source3: trust-extract-compat
Source4: p11-kit-client.service
Patch0: p11-kit-meson-c99.patch
BuildRequires: gcc
BuildRequires: libtasn1-devel >= 2.3
@ -20,7 +26,7 @@ BuildRequires: gettext
BuildRequires: gtk-doc
BuildRequires: meson
BuildRequires: systemd-devel
BuildRequires: bash-completion
BuildRequires: pkgconfig(bash-completion)
# Work around for https://bugzilla.redhat.com/show_bug.cgi?id=1497147
# Remove this once it is fixed
BuildRequires: pkgconfig(glib-2.0)
@ -28,12 +34,40 @@ BuildRequires: pkgconfig(systemd)
BuildRequires: gnupg2
BuildRequires: /usr/bin/xsltproc
%if %{with mingw}
BuildRequires: ninja-build
BuildRequires: mingw32-filesystem >= 95
BuildRequires: mingw32-gcc
BuildRequires: mingw32-binutils
BuildRequires: mingw32-libffi
BuildRequires: mingw32-libtasn1
BuildRequires: mingw64-filesystem >= 95
BuildRequires: mingw64-gcc
BuildRequires: mingw64-binutils
BuildRequires: mingw64-libffi
BuildRequires: mingw64-libtasn1
%endif
%description
p11-kit provides a way to load and enumerate PKCS#11 modules, as well
as a standard configuration setup for installing PKCS#11 modules in
such a way that they're discoverable.
%package client
Summary: Client module from %{name}
Requires: %{name}%{?_isa} = %{version}-%{release}
Obsoletes: %{name}-server < 0.25.5-8
%description client
The %{name}-client package contains a PKCS#11 module that enables
accessing other PKCS#11 modules over a Unix domain socket. Note that
this feature is still experimental.
%package devel
Summary: Development files for %{name}
Requires: %{name}%{?_isa} = %{version}-%{release}
@ -46,18 +80,19 @@ developing applications that use %{name}.
%package trust
Summary: System trust module from %{name}
Requires: %{name}%{?_isa} = %{version}-%{release}
Requires(post): %{_sbindir}/update-alternatives
Requires(postun): %{_sbindir}/update-alternatives
Requires(post): %{_sbindir}/alternatives
Requires(postun): %{_sbindir}/alternatives
Conflicts: nss < 3.14.3-9
%description trust
The %{name}-trust package contains a system trust PKCS#11 module which
contains certificate anchors and black lists.
contains certificate anchors and blocklists.
%package server
Summary: Server and client commands for %{name}
Summary: Server command for %{name}
Requires: %{name}%{?_isa} = %{version}-%{release}
Obsoletes: %{name}-server < 0.25.5-8
%description server
The %{name}-server package contains command line tools that enable to
@ -65,6 +100,33 @@ export PKCS#11 modules through a Unix domain socket. Note that this
feature is still experimental.
%if %{with mingw}
%package -n mingw32-%{name}
Summary: MinGW Library for loading and sharing PKCS#11 modules
Requires: pkgconfig
BuildArch: noarch
%description -n mingw32-%{name}
p11-kit provides a way to load and enumerate PKCS#11 modules, as well as
a standard configuration setup for installing PKCS#11 modules in such a
way that they're discoverable. This library is cross-compiled for MinGW.
%package -n mingw64-%{name}
Summary: MinGW Library for loading and sharing PKCS#11 modules
Requires: pkgconfig
BuildArch: noarch
%description -n mingw64-%{name}
p11-kit provides a way to load and enumerate PKCS#11 modules, as well as
a standard configuration setup for installing PKCS#11 modules in such a
way that they're discoverable. This library is cross-compiled for MinGW.
%{?mingw_debug_package}
%endif
# solution taken from icedtea-web.spec
%define multilib_arches ppc64 sparc64 x86_64 ppc64le
%ifarch %{multilib_arches}
@ -80,11 +142,16 @@ gpgv2 --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0}
%autosetup -p1
%build
# These paths are the source paths that come from the plan here:
# These paths are the source paths that come from the plan here:
# https://fedoraproject.org/wiki/Features/SharedSystemCertificates:SubTasks
%meson -Dgtk_doc=true -Dman=true -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source
%meson_build
%if %{with mingw}
%mingw_meson -Dgtk_doc=false -Dman=false -Dnls=false -Dtrust_paths=%{_sysconfdir}/pki/ca-trust/source:%{_datadir}/pki/ca-trust-source -Dzsh_completion=disabled
%mingw_ninja
%endif
%install
%meson_install
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pkcs11/modules
@ -96,18 +163,23 @@ mkdir -p $RPM_BUILD_ROOT%{_userunitdir}
install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_userunitdir}
%find_lang %{name}
%if %{with mingw}
%mingw_ninja_install
%{?mingw_debug_install_post}
%endif
%check
%meson_test
%post trust
%{_sbindir}/update-alternatives --install %{_libdir}/libnssckbi.so \
%{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so 30
alternatives --install %{_libdir}/libnssckbi.so %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so 30
%postun trust
if [ $1 -eq 0 ] ; then
# package removal
%{_sbindir}/update-alternatives --remove %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so
alternatives --remove %{alt_ckbi} %{_libdir}/pkcs11/p11-kit-trust.so
fi
@ -120,6 +192,7 @@ fi
%dir %{_sysconfdir}/pkcs11/modules
%dir %{_datadir}/p11-kit
%dir %{_datadir}/p11-kit/modules
%dir %{_libdir}/pkcs11
%dir %{_libexecdir}/p11-kit
%{_bindir}/p11-kit
%{_libdir}/libp11-kit.so.*
@ -129,6 +202,11 @@ fi
%{_mandir}/man8/p11-kit.8.gz
%{_mandir}/man5/pkcs11.conf.5.gz
%{_datadir}/bash-completion/completions/p11-kit
%{_datadir}/zsh/site-functions/_p11-kit
%files client
%{_libdir}/pkcs11/p11-kit-client.so
%{_userunitdir}/p11-kit-client.service
%files devel
%{_includedir}/p11-kit-1/
@ -138,20 +216,56 @@ fi
%files trust
%{_bindir}/trust
%dir %{_libdir}/pkcs11
%ghost %{_libdir}/libnssckbi.so
%{_libdir}/pkcs11/p11-kit-trust.so
%{_datadir}/p11-kit/modules/p11-kit-trust.module
%{_libexecdir}/p11-kit/trust-extract-compat
%{_datadir}/bash-completion/completions/trust
%{_datadir}/zsh/site-functions/_trust
%files server
%{_libdir}/pkcs11/p11-kit-client.so
%{_userunitdir}/p11-kit-client.service
%{_libexecdir}/p11-kit/p11-kit-server
%{_userunitdir}/p11-kit-server.service
%{_userunitdir}/p11-kit-server.socket
%if %{with mingw}
%files -n mingw32-%{name}
%{!?_licensedir:%global license %%doc}
%license COPYING
%{mingw32_bindir}/libp11-kit-0.dll
%{mingw32_bindir}/p11-kit.exe
%{mingw32_bindir}/trust.exe
%{mingw32_libdir}/libp11-kit.dll.a
%dir %{mingw32_libdir}/pkcs11/
%{mingw32_libdir}/pkcs11/p11-kit-trust.dll
%{mingw32_libdir}/pkcs11/p11-kit-trust.dll.a
%{mingw32_libdir}/pkgconfig/p11-kit-1.pc
%dir %{mingw32_libexecdir}/p11-kit/
%{mingw32_libexecdir}/p11-kit/*.exe
%{mingw32_libexecdir}/p11-kit/trust-extract-compat
%{mingw32_includedir}/p11-kit-1/
%{mingw32_datadir}/p11-kit/
%{mingw32_sysconfdir}/pkcs11/
%files -n mingw64-%{name}
%{!?_licensedir:%global license %%doc}
%license COPYING
%{mingw64_bindir}/libp11-kit-0.dll
%{mingw64_bindir}/p11-kit.exe
%{mingw64_bindir}/trust.exe
%{mingw64_libdir}/libp11-kit.dll.a
%dir %{mingw64_libdir}/pkcs11/
%{mingw64_libdir}/pkcs11/p11-kit-trust.dll
%{mingw64_libdir}/pkcs11/p11-kit-trust.dll.a
%{mingw64_libdir}/pkgconfig/p11-kit-1.pc
%dir %{mingw64_libexecdir}/p11-kit/
%{mingw64_libexecdir}/p11-kit/*.exe
%{mingw64_libexecdir}/p11-kit/trust-extract-compat
%{mingw64_includedir}/p11-kit-1/
%{mingw64_datadir}/p11-kit/
%{mingw64_sysconfdir}/pkcs11/
%endif
%changelog
%autochangelog

View file

@ -1 +1,3 @@
SHA512 (p11-kit-0.24.1.tar.xz) = 8cf170c714bb9e0cf3df93e8ec55b8e3c55cabf2c6a27f177ac6de8b8028985df2ca0216d3215d6828dc2ae3095c4e1a4febe8cb26b88ec321defc66bb011e81
SHA512 (p11-kit-0.25.8.tar.xz) = 4a3852459a4a5e4ea71eea5d23ef74deeb51c66b28d095be30a263f10d1f47853341f8628eb0c43c88247503059a4c1f67017965a70cd3c7df31d86e458a8162
SHA512 (p11-kit-0.25.8.tar.xz.sig) = 97f47324cd7578833b751ab1fee55a9a538ba94b52ec4729249a9e5494c60cceef6c60999b495299f2b9ae0d0cda60d5db713d82e0b7991112b7b4b46ad46d1d
SHA512 (p11-kit-release-keyring.gpg) = 9a832a8ac3a139cbbf1ecb66573f0709847ebfef4975777cf82b4dca09af1ad8e6400f0af0bcdb92860e7ed4fc05082ba1edda0238a21fe24d49555a1069e881