diff --git a/.gitignore b/.gitignore index 7897d95..5bac72c 100644 --- a/.gitignore +++ b/.gitignore @@ -42,3 +42,37 @@ varnish-2.1.3.tar.gz /pkg-varnish-cache-ec7ad9e.tar.gz /varnish-6.3.2.tgz /varnish-6.4.0.tgz +/varnish-6.5.0.tgz +/varnish-6.5.1.tgz +/varnish-6.6.0.tgz +/varnish-6.6.1.tgz +/pkg-varnish-cache-d3e6a3f.tar.gz +/varnish-7.0.0.tgz +/varnish-7.0.1.tgz +/varnish-7.0.2.tgz +/pkg-varnish-cache-3ba24a8.tar.gz +/varnish-7.1.0.tgz +/varnish-7.1.1.tgz +/pkg-varnish-cache-ffc59a3.tar.gz +/varnish-7.2.0.tgz +/varnish-7.2.1.tgz +/pkg-varnish-cache-7126673.tar.gz +/varnish-7.3.0.tgz +/pkg-varnish-cache-cfa8cb3.tar.gz +/varnish-7.4.0.tgz +/varnish-7.4.1.tgz +/varnish-7.4.2.tgz +/varnish-7.5.0.tgz +/varnish-7.6.0.tgz +/pkg-varnish-cache-7d90347.tar.gz +/varnish-7.6.1.tgz +/varnish-7.7.0.tgz +/varnish-7.7.1.tgz +/jemalloc-5.3.0.tar.bz2 +/varnish-7.7.3.tgz +/varnish-8.0.0.tgz +/pkg-varnish-cache-1f0d212.tar.gz +/varnish-9.0.0.tar.gz +/varnish-9.0.1.tar.gz +/varnish-9.0.2.tar.gz +/varnish-9.0.3.tar.gz diff --git a/jemalloc-5.3.0-aarch64-ts-segfault.patch b/jemalloc-5.3.0-aarch64-ts-segfault.patch new file mode 100644 index 0000000..624f4ff --- /dev/null +++ b/jemalloc-5.3.0-aarch64-ts-segfault.patch @@ -0,0 +1,140 @@ +diff --git a/test/unit/psset.c b/test/unit/psset.c +index 6ff7201..58b4a88 100644 +--- a/test/unit/psset.c ++++ b/test/unit/psset.c +@@ -124,7 +124,7 @@ TEST_BEGIN(test_fill) { + hpdata_t pageslab; + hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE); + +- edata_t alloc[HUGEPAGE_PAGES]; ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + psset_t psset; + psset_init(&psset); +@@ -147,6 +147,8 @@ TEST_BEGIN(test_fill) { + edata_init_test(&extra_alloc); + err = test_psset_alloc_reuse(&psset, &extra_alloc, PAGE); + expect_true(err, "Alloc succeeded even though psset should be empty"); ++ ++ free(alloc); + } + TEST_END + +@@ -157,7 +159,7 @@ TEST_BEGIN(test_reuse) { + hpdata_t pageslab; + hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE); + +- edata_t alloc[HUGEPAGE_PAGES]; ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + psset_t psset; + psset_init(&psset); +@@ -239,6 +241,8 @@ TEST_BEGIN(test_reuse) { + err = test_psset_alloc_reuse(&psset, &alloc[index_of_4], 4 * PAGE); + expect_false(err, "Should have been able to find alloc."); + edata_expect(&alloc[index_of_4], index_of_4, 4); ++ ++ free(alloc); + } + TEST_END + +@@ -249,7 +253,7 @@ TEST_BEGIN(test_evict) { + hpdata_t pageslab; + hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE); + +- edata_t alloc[HUGEPAGE_PAGES]; ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + psset_t psset; + psset_init(&psset); +@@ -273,6 +277,8 @@ TEST_BEGIN(test_evict) { + + err = test_psset_alloc_reuse(&psset, &alloc[0], PAGE); + expect_true(err, "psset should be empty."); ++ ++ free(alloc); + } + TEST_END + +@@ -286,7 +292,9 @@ TEST_BEGIN(test_multi_pageslab) { + (void *)((uintptr_t)PAGESLAB_ADDR + HUGEPAGE), + PAGESLAB_AGE + 1); + +- edata_t alloc[2][HUGEPAGE_PAGES]; ++ edata_t* alloc[2]; ++ alloc[0] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); ++ alloc[1] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + psset_t psset; + psset_init(&psset); +@@ -336,6 +344,9 @@ TEST_BEGIN(test_multi_pageslab) { + */ + err = test_psset_alloc_reuse(&psset, &alloc[1][0], 2 * PAGE); + expect_false(err, "Allocation should have succeeded"); ++ ++ free(alloc[0]); ++ free(alloc[1]); + } + TEST_END + +@@ -385,7 +396,7 @@ TEST_BEGIN(test_stats) { + hpdata_t pageslab; + hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE); + +- edata_t alloc[HUGEPAGE_PAGES]; ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + psset_t psset; + psset_init(&psset); +@@ -415,6 +426,8 @@ TEST_BEGIN(test_stats) { + stats_expect(&psset, 0); + psset_update_end(&psset, &pageslab); + stats_expect(&psset, 1); ++ ++ free(alloc); + } + TEST_END + +@@ -475,8 +488,8 @@ init_test_pageslabs(psset_t *psset, hpdata_t *pageslab, + + TEST_BEGIN(test_oldest_fit) { + bool err; +- edata_t alloc[HUGEPAGE_PAGES]; +- edata_t worse_alloc[HUGEPAGE_PAGES]; ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); ++ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); + + hpdata_t pageslab; + hpdata_t worse_pageslab; +@@ -493,14 +506,19 @@ TEST_BEGIN(test_oldest_fit) { + expect_false(err, "Nonempty psset failed page allocation"); + expect_ptr_eq(&pageslab, edata_ps_get(&test_edata), + "Allocated from the wrong pageslab"); ++ ++ free(alloc); ++ free(worse_alloc); + } + TEST_END + + TEST_BEGIN(test_insert_remove) { + bool err; + hpdata_t *ps; +- edata_t alloc[HUGEPAGE_PAGES]; +- edata_t worse_alloc[HUGEPAGE_PAGES]; ++ ++ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); ++ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES); ++ + + hpdata_t pageslab; + hpdata_t worse_pageslab; +@@ -539,6 +557,9 @@ TEST_BEGIN(test_insert_remove) { + psset_update_begin(&psset, &worse_pageslab); + err = test_psset_alloc_reuse(&psset, &alloc[HUGEPAGE_PAGES - 1], PAGE); + expect_true(err, "psset should be empty, but an alloc succeeded"); ++ ++ free(alloc); ++ free(worse_alloc); + } + TEST_END + diff --git a/jemalloc-5.3.0_fno-builtin.patch b/jemalloc-5.3.0_fno-builtin.patch new file mode 100644 index 0000000..b938dff --- /dev/null +++ b/jemalloc-5.3.0_fno-builtin.patch @@ -0,0 +1,29 @@ +commit 3de0c24859f4413bf03448249078169bb50bda0f +Author: divanorama +Date: Thu Sep 29 23:35:59 2022 +0200 + + Disable builtin malloc in tests + + With `--with-jemalloc-prefix=` and without `-fno-builtin` or `-O1` both clang and gcc may optimize out `malloc` calls + whose result is unused. Comparing result to NULL also doesn't necessarily count as being used. + + This won't be a problem in most client programs as this only concerns really unused pointers, but in + tests it's important to actually execute allocations. + `-fno-builtin` should disable this optimization for both gcc and clang, and applying it only to tests code shouldn't hopefully be an issue. + Another alternative is to force "use" of result but that'd require more changes and may miss some other optimization-related issues. + + This should resolve https://github.com/jemalloc/jemalloc/issues/2091 + +diff --git a/Makefile.in b/Makefile.in +index 6809fb29..a964f07e 100644 +--- a/Makefile.in ++++ b/Makefile.in +@@ -458,6 +458,8 @@ $(TESTS_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.c + $(TESTS_CPP_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.cpp + $(TESTS_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include + $(TESTS_CPP_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include ++$(TESTS_OBJS): CFLAGS += -fno-builtin ++$(TESTS_CPP_OBJS): CPPFLAGS += -fno-builtin + ifneq ($(IMPORTLIB),$(SO)) + $(CPP_OBJS) $(C_SYM_OBJS) $(C_OBJS) $(C_JET_SYM_OBJS) $(C_JET_OBJS): CPPFLAGS += -DDLLEXPORT + endif diff --git a/sources b/sources index 1ec0db0..abfe64e 100644 --- a/sources +++ b/sources @@ -1,2 +1,3 @@ -SHA512 (pkg-varnish-cache-ec7ad9e.tar.gz) = 146aacec76b2ca641bb8bc9dda49e82d28740dbcba034e73a8d39387696f10fa3108ab124a078e900865388217352d112f63f6fe9ef7b23e20bc699441aab4f2 -SHA512 (varnish-6.4.0.tgz) = cda8f9e1d301a2b79db14685a23e25e36225f37065a1b7f37c5ae12fbb0483be51be9ffcc8ba72c1f65f5a022d1e408825694daed6780e206b9ba91feb2a07a1 +SHA512 (varnish-9.0.3.tar.gz) = 2789cff88632c2279062a109513cc00cab7690785f8f77e90b9968098c71ddcdc6403d6a9edc755b8f4055f0d32d9e330b0bc20fbab92ba80232955942dc912a +SHA512 (jemalloc-5.3.0.tar.bz2) = 22907bb052096e2caffb6e4e23548aecc5cc9283dce476896a2b1127eee64170e3562fa2e7db9571298814a7a2c7df6e8d1fbe152bd3f3b0c1abec22a2de34b1 +SHA512 (pkg-varnish-cache-1f0d212.tar.gz) = 9f05978c99f292e64e71ba24ef2de791a33640e40fbad66d47889837fb0d4ced203873f5a17716edf757b5ad48098289882c2df196ce1fb457f279bf7f35bec3 diff --git a/varnish-6.5.0_el6_fix_warning_from_old_gcc.patch b/varnish-6.5.0_el6_fix_warning_from_old_gcc.patch new file mode 100644 index 0000000..d72b238 --- /dev/null +++ b/varnish-6.5.0_el6_fix_warning_from_old_gcc.patch @@ -0,0 +1,78 @@ +diff -Naur ../varnish-6.5.0.orig/bin/varnishd/http1/cache_http1_deliver.c ./bin/varnishd/http1/cache_http1_deliver.c +--- ../varnish-6.5.0.orig/bin/varnishd/http1/cache_http1_deliver.c 2020-09-15 17:06:03.000000000 +0200 ++++ ./bin/varnishd/http1/cache_http1_deliver.c 2020-09-16 11:45:28.663086943 +0200 +@@ -76,7 +76,7 @@ + VSLb(req->vsl, SLT_RespReason, "Internal Server Error"); + + req->wrk->stats->client_resp_500++; +- (void)write(req->sp->fd, r_500, sizeof r_500 - 1); ++ if (write(req->sp->fd, r_500, sizeof r_500 - 1)) 0; + req->doclose = SC_TX_EOF; + } + +diff -Naur ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_main.c ./bin/varnishd/mgt/mgt_main.c +--- ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_main.c 2020-09-15 17:06:03.000000000 +0200 ++++ ./bin/varnishd/mgt/mgt_main.c 2020-09-16 11:46:21.323667133 +0200 +@@ -252,7 +252,7 @@ + return; + VJ_rmdir("vmod_cache"); + VJ_unlink("_.pid"); +- (void)chdir("/"); ++ if (chdir("/")) 0; + VJ_rmdir(workdir); + } + +diff -Naur ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_param.c ./bin/varnishd/mgt/mgt_param.c +--- ../varnish-6.5.0.orig/bin/varnishd/mgt/mgt_param.c 2020-09-15 17:06:03.000000000 +0200 ++++ ./bin/varnishd/mgt/mgt_param.c 2020-09-16 11:45:28.771086082 +0200 +@@ -829,11 +829,11 @@ + t2 = strchr(t1 + 1, '\t'); + AN(t2); + printf("\n\t*"); +- (void)fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout); ++ if (fwrite(t1 + 1, (t2 - 1) - t1, 1, stdout)) 1; + printf("*\n\t\t"); + p = t2 + 1; + } +- (void)fwrite(p, q - p, 1, stdout); ++ if(fwrite(p, q - p, 1, stdout)) 1; + p = q; + if (*p == '\n') { + printf("\n"); +diff -Naur ../varnish-6.5.0.orig/bin/varnishtest/vtc_main.c ./bin/varnishtest/vtc_main.c +--- ../varnish-6.5.0.orig/bin/varnishtest/vtc_main.c 2020-09-15 17:06:03.000000000 +0200 ++++ ./bin/varnishtest/vtc_main.c 2020-09-16 11:45:28.771086082 +0200 +@@ -233,7 +233,7 @@ + assert(cleaner_pid >= 0); + if (cleaner_pid == 0) { + closefd(&p[1]); +- (void)nice(1); /* Not important */ ++ if (nice(1)) 1; + setbuf(stdin, NULL); + AZ(dup2(p[0], STDIN_FILENO)); + while (fgets(buf, sizeof buf, stdin)) { +diff -Naur ../varnish-6.5.0.orig/lib/libvarnishapi/vsm.c ./lib/libvarnishapi/vsm.c +--- ../varnish-6.5.0.orig/lib/libvarnishapi/vsm.c 2020-09-15 17:06:03.000000000 +0200 ++++ ./lib/libvarnishapi/vsm.c 2020-09-16 11:45:28.772086074 +0200 +@@ -764,18 +764,18 @@ + VSM_ResetError(vd); + if (u & VSM_MGT_RUNNING) { + if (progress >= 0 && n > 4) +- (void)write(progress, "\n", 1); ++ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress")); + vd->attached = 1; + return (0); + } + if (t0 < VTIM_mono()) { + if (progress >= 0 && n > 4) +- (void)write(progress, "\n", 1); ++ if (!write(progress, "\n", 1)) return (vsm_diag(vd, "Unable to write progress")); + return (vsm_diag(vd, + "Could not get hold of varnishd, is it running?")); + } + if (progress >= 0 && !(++n % 4)) +- (void)write(progress, ".", 1); ++ if (!write(progress, ".", 1)) return (vsm_diag(vd, "Unable to write progress")); + VTIM_sleep(.25); + } + return (vsm_diag(vd, "Attach interrupted")); diff --git a/varnish-7.7.0_fix_4298.patch b/varnish-7.7.0_fix_4298.patch new file mode 100644 index 0000000..f37f52c --- /dev/null +++ b/varnish-7.7.0_fix_4298.patch @@ -0,0 +1,178 @@ +commit 95e41dfa584d108e444949534c7ce5801cffeacc +Author: Poul-Henning Kamp +Date: Wed Mar 26 09:25:43 2025 +0000 + + If the client sends NO_RFC7540_PRIORITIES, "rxprio" verbs become no-ops. + + Fixes: #4298 + Tested by: @ingvarha + + + +commit 3a1eb57d8bd57205db7d2c766aed39cf73c4f578 +Author: Poul-Henning Kamp +Date: Wed Mar 26 09:24:17 2025 +0000 + + Add more HTTP2 Settings to the table + + +diff --git a/bin/varnishtest/vtc.h b/bin/varnishtest/vtc.h +index 2e5d4161a..b765fe60a 100644 +--- a/bin/varnishtest/vtc.h ++++ b/bin/varnishtest/vtc.h +@@ -148,7 +148,7 @@ struct http; + void cmd_stream(CMD_ARGS); + void start_h2(struct http *hp); + void stop_h2(struct http *hp); +-void b64_settings(const struct http *hp, const char *s); ++void b64_settings(struct http *hp, const char *s); + + /* vtc_gzip.c */ + void vtc_gunzip(struct http *, char *, long *); +diff --git a/bin/varnishtest/vtc_http.h b/bin/varnishtest/vtc_http.h +index 7a86de8da..62c598a55 100644 +--- a/bin/varnishtest/vtc_http.h ++++ b/bin/varnishtest/vtc_http.h +@@ -83,6 +83,7 @@ struct http { + /* H/2 */ + unsigned h2; + int wf; ++ int no_rfc7540_priorities; + + pthread_t tp; + VTAILQ_HEAD(, stream) streams; +diff --git a/bin/varnishtest/vtc_http2.c b/bin/varnishtest/vtc_http2.c +index 822abbae1..7feeb42b0 100644 +--- a/bin/varnishtest/vtc_http2.c ++++ b/bin/varnishtest/vtc_http2.c +@@ -629,7 +629,7 @@ parse_settings(const struct stream *s, struct frame *f) + buf = "unknown"; + u += 4; + +- if (t == 1) { ++ if (t == SETTINGS_HEADER_TABLE_SIZE) { + r = HPK_ResizeTbl(s->hp->encctx, v); + assert(r == hpk_done); + } +@@ -2460,28 +2460,47 @@ cmd_rxsettings(CMD_ARGS) + hp->h2_win_peer->init = val; + } + } ++/* SECTION: stream.spec.prio_rxprio rxprio ++ * ++ * Receive a PRIORITY frame. ++ */ ++static void ++cmd_rxprio (CMD_ARGS) ++{ ++ struct stream *s; ++ (void)av; ++ CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC); ++ if (s->hp->no_rfc7540_priorities) { ++ vtc_log(vl, 4, "skipping rxprio: no_rfc7540_priorities is set"); ++ return; ++ } ++ s->frame = rxstuff(s); ++ if (s->frame != NULL && s->frame->type != TYPE_PRIORITY) { ++ vtc_fatal(vl, ++ "Wrong frame type %s (%d) wanted %s", ++ s->frame->type < TYPE_MAX ? ++ h2_types[s->frame->type] : "?", ++ s->frame->type, "PRIORITY"); ++ } ++} + + #define RXFUNC(lctype, upctype) \ + static void \ +- cmd_rx ## lctype(CMD_ARGS) { \ ++ cmd_rx ## lctype(CMD_ARGS) \ ++ { \ + struct stream *s; \ + (void)av; \ + CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC); \ + s->frame = rxstuff(s); \ +- if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) \ ++ if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) { \ + vtc_fatal(vl, \ + "Wrong frame type %s (%d) wanted %s", \ + s->frame->type < TYPE_MAX ? \ + h2_types[s->frame->type] : "?", \ + s->frame->type, #upctype); \ ++ } \ + } + +-/* SECTION: stream.spec.prio_rxprio rxprio +- * +- * Receive a PRIORITY frame. +- */ +-RXFUNC(prio, PRIORITY) +- + /* SECTION: stream.spec.reset_rxrst rxrst + * + * Receive a RST_STREAM frame. +@@ -2857,7 +2876,7 @@ cmd_stream(CMD_ARGS) + } + + void +-b64_settings(const struct http *hp, const char *s) ++b64_settings(struct http *hp, const char *s) + { + uint16_t i; + uint64_t v, vv; +@@ -2891,7 +2910,10 @@ b64_settings(const struct http *hp, const char *s) + else + buf = "unknown"; + +- if (v == 1) { ++ if (i == SETTINGS_NO_RFC7540_PRIORITIES) { ++ hp->no_rfc7540_priorities = v; ++ } ++ if (i == SETTINGS_HEADER_TABLE_SIZE) { + enum hpk_result hrs; + if (hp->sfd) { + AN(hp->encctx); +diff --git a/include/tbl/h2_settings.h b/include/tbl/h2_settings.h +index 2dbac671f..273f157fe 100644 +--- a/include/tbl/h2_settings.h ++++ b/include/tbl/h2_settings.h +@@ -102,7 +102,39 @@ H2_SETTING( // rfc7540,l,2159,2167 + 0xffffffff, + 0 + ) +-#endif ++ ++H2_SETTING( // rfc8441 ++ ENABLE_CONNECT_PROTOCOL, ++ enable_connect_protocol, ++ 0x8, ++ 0, ++ 0, ++ 1, ++ H2CE_PROTOCOL_ERROR ++) ++ ++H2_SETTING( // rfc9218 ++ NO_RFC7540_PRIORITIES, ++ no_rfc7540_priorities, ++ 0x9, ++ 0, ++ 0, ++ 1, ++ H2CE_PROTOCOL_ERROR ++) ++ ++H2_SETTING( // [MS-HTTP2E] ++ // [Gabriel_Montenegro] ++ TLS_RENEG_PERMITTED, ++ tls_reneg_permitted, ++ 0x10, ++ 0, ++ 0, ++ 3, ++ H2CE_PROTOCOL_ERROR ++) ++#endif /* !H2_SETTINGS_PARAM_ONLY */ ++ + #undef H2_SETTING + + /*lint -restore */ diff --git a/varnish-9.0.1_openssl_4.0_asn1.patch b/varnish-9.0.1_openssl_4.0_asn1.patch new file mode 100644 index 0000000..3bd33f1 --- /dev/null +++ b/varnish-9.0.1_openssl_4.0_asn1.patch @@ -0,0 +1,38 @@ +Author: Ingvar Hagelund +Date: Wed Apr 15 00:17:59 2026 +0200 + + Use ASN1_STRING functions for openssl-4.0.0 + +diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c +--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-08 18:57:33.000000000 +0200 ++++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-15 00:34:44.788211992 +0200 +@@ -142,10 +142,10 @@ + char *a; + int n, i, l, o; + +- if (d->type != V_ASN1_GENERALIZEDTIME) ++ if (ASN1_STRING_type(d) != V_ASN1_GENERALIZEDTIME) + return (0); +- l = d->length; +- a = (char *)d->data; ++ l = ASN1_STRING_length(d); ++ a = (char *)ASN1_STRING_get0_data(d); + o = 0; + /* + * GENERALIZEDTIME is similar to UTCTIME except the year is represented +diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c +--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-08 18:57:33.000000000 +0200 ++++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-15 00:35:53.447792774 +0200 +@@ -1060,10 +1060,10 @@ + + break; + case GEN_IPADD: +- p = n->d.ip->data; ++ p = ASN1_STRING_get0_data(n->d.ip); + AN(p); + +- if (inet_ntop(n->d.ip->length == 16 ? AF_INET6 : AF_INET, ++ if (inet_ntop(ASN1_STRING_length(n->d.ip) == 16 ? AF_INET6 : AF_INET, + p, b, INET6_ADDRSTRLEN) == 0) + continue; + diff --git a/varnish.spec b/varnish.spec index 6e387da..74a5c3b 100644 --- a/varnish.spec +++ b/varnish.spec @@ -1,135 +1,125 @@ -%global _hardened_build 1 - +%global _hardened_build 0 # https://github.com/varnishcache/varnish-cache/issues/2269 %global debug_package %{nil} -%if 0%{?rhel} == 6 || 0%{?rhel} == 7 -%global _use_internal_dependency_generator 0 -%global __find_provides %{_builddir}/%{name}-%{version}/find-provides %__find_provides -%global __python /usr/bin/python3.4 -%else -%global __python %{__python3} -%endif - %global __provides_exclude_from ^%{_libdir}/varnish/vmods -%global abi 13f137934ec1cf14af66baf7896311115ee35598 -%global vrt 11.0 +%global abi 0a625649cd40af4b6c10be5e58a2e89a5e275baa +%global vrt 23.1 # Package scripts are now external # https://github.com/varnishcache/pkg-varnish-cache -%global commit1 ec7ad9e6c6dd7c9b4f4ba60c5b223376908c3ca6 +%global commit1 1f0d212dc45065f38bd80ac57fe22773a20a0595 %global shortcommit1 %(c=%{commit1}; echo ${c:0:7}) +# Default: Use jemalloc, as adviced by upstream project +# Change to 1 to use system allocator (ie. glibc) +# +# for rhel >= 10, use bundled jemalloc +# for rhel < 10, use system allocator +%bcond system_allocator %[0%{?rhel} && 0%{?rhel} < 10] +%bcond bundled_jemalloc %[0%{?rhel} >= 10] + +%define jemalloc_version 5.3.0 +%define jemalloc_prefix varnish_ + +%if %{with system_allocator} +# use _lto_cflags if present +%else +%global _lto_cflags %{nil} +%endif + Summary: High-performance HTTP accelerator Name: varnish -Version: 6.4.0 -Release: 4%{?dist} -License: BSD +Version: 9.0.3 +Release: 3%{?dist} +License: BSD-2-Clause AND (BSD-2-Clause-FreeBSD AND BSD-3-Clause AND LicenseRef-Fedora-Public-Domain AND Zlib) URL: https://www.varnish-cache.org/ -Source0: http://varnish-cache.org/_downloads/%{name}-%{version}%{?vd_rc}.tgz +Source0: https://github.com/varnish/varnish/releases/download/%{name}-%{version}/%{name}-%{version}.tar.gz Source1: https://github.com/varnishcache/pkg-varnish-cache/archive/%{commit1}.tar.gz#/pkg-varnish-cache-%{shortcommit1}.tar.gz +Source2: varnish.sysusers +Source3: https://github.com/jemalloc/jemalloc/releases/download/%{jemalloc_version}/jemalloc-%{jemalloc_version}.tar.bz2 +Source4: varnish.tmpfiles -# Patches: -# Patch 001: Because of Fedora's libtool no-rpath requirement, it is still -# necessary to add LD_LIBRARY_PATH when building the documentation -# (Fixed by using LT_SYS_LIBRARY_PATH) -#Patch1: varnish-6.1.1_fix_ld_library_path_in_doc_build.patch +# Compatibility with openssl-4.0.0 +# https://github.com/varnish/varnish/issues/32 +Patch1: varnish-9.0.1_openssl_4.0_asn1.patch -# Patch 004: varnish selinux support for el6 -Patch4: varnish-4.0.3_fix_varnish4_selinux.el6.patch +%if %{with bundled_jemalloc} +# bundled jemalloc patch +Patch100: jemalloc-5.3.0_fno-builtin.patch +Patch101: jemalloc-5.3.0-aarch64-ts-segfault.patch +%endif -# Patch 009: Hard code older python support in configure for older el releases -#Patch9: varnish-5.1.1.fix_python_version.patch - -# Patch 012: Fix test for variants of ncurses, based on upstream commit 9bdc5f75, upstream issue #2668 -#Patch12: varnish-6.0.1_fix_bug2668.patch - -# Patch 013: Just a simple format error -#Patch13: varnish-6.1.0_fix_testu00008.patch - -# Patch 014: Another formatting error fixed upstream, issue 2879 -#Patch14: varnish-6.1.1_fix_upstrbug_2879.patch - -# Patch 015: pcre-jit fixed upstream, issue #2912 -#Patch15: varnish-6.1.1_fix_issue_2912.patch - -# Patch 016: Fix some warnings that prohibited clean -Werror compilation -# on el6. Will not be fixed upstream. Patch grows more stupid -# for each iteration :-( -Patch16: varnish-6.4.0_el6_fix_warning_from_old_gcc.patch - -# Patch 017: Fix stack size on ppc64 in test c_00057, upstream commit 88948d9 -#Patch17: varnish-6.2.0_fix_ppc64_for_test_c00057.patch - -# Patch 018: gcc-10.0.1/s390x compilation fix, upstream commit b0af060 -#Patch18: varnish-6.3.2_fix_s390x.patch - -%if 0%{?fedora} > 29 Provides: varnish%{_isa} = %{version}-%{release} Provides: varnishd(abi)%{_isa} = %{abi} Provides: varnishd(vrt)%{_isa} = %{vrt} Provides: vmod(blob)%{_isa} = %{version}-%{release} +Provides: vmod(cookie)%{_isa} = %{version}-%{release} +Provides: vmod(debug)%{_isa} = %{version}-%{release} Provides: vmod(directors)%{_isa} = %{version}-%{release} +Provides: vmod(h2)%{_isa} = %{version}-%{release} Provides: vmod(proxy)%{_isa} = %{version}-%{release} Provides: vmod(purge)%{_isa} = %{version}-%{release} Provides: vmod(std)%{_isa} = %{version}-%{release} Provides: vmod(unix)%{_isa} = %{version}-%{release} Provides: vmod(vtc)%{_isa} = %{version}-%{release} + +%if %{with bundled_jemalloc} +Provides: bundled(jemalloc) %endif -Obsoletes: varnish-libs < %{version}-%{release} +BuildRequires: systemd-rpm-macros +%{?systemd_requires} +%{?sysusers_requires_compat} -%if 0%{?rhel} == 6 || 0%{?rhel} == 7 -BuildRequires: python34 python-sphinx python34-docutils -%else BuildRequires: python3, python3-sphinx, python3-docutils -%endif -BuildRequires: jemalloc-devel -BuildRequires: libedit-devel -BuildRequires: ncurses-devel -BuildRequires: pcre-devel -BuildRequires: pkgconfig BuildRequires: gcc +%if %{without bundled_jemalloc} +%if %{with system_allocator} +# use glibc +%else +%ifnarch aarch64 +BuildRequires: jemalloc-devel +%endif +%endif +%endif + +BuildRequires: libedit-devel BuildRequires: make +BuildRequires: ncurses-devel +BuildRequires: pcre2-devel +BuildRequires: pkgconfig +BuildRequires: openssl-devel + +%if %{with bundled_jemalloc} +BuildRequires: /usr/bin/xsltproc +BuildRequires: perl-generators +%endif # Extra requirements for the build suite +# needs haproxy2 +%if 0%{?fedora} > 30 +BuildRequires: haproxy +%endif BuildRequires: nghttp2 -# haproxy is broken in rawhide now -#if 0#{?fedora} || 0#{?rhel} >= 8 -#BuildRequires: haproxy -#endif - -%if 0%{?rhel} == 6 -BuildRequires: selinux-policy -%endif -Requires: logrotate -Requires: ncurses -Requires: pcre -Requires: jemalloc -Requires: redhat-rpm-config -Requires(pre): shadow-utils -Requires(post): /usr/bin/uuidgen -# Varnish actually needs gcc installed to work. It uses the C compiler +# Varnish actually needs gcc installed to work. It uses the C compiler # at runtime to compile the VCL configuration files. This is by design. Requires: gcc -%if 0%{?fedora} >= 17 || 0%{?rhel} >= 7 -Requires(post): systemd-units -Requires(post): systemd-sysv -Requires(preun): systemd-units -Requires(postun): systemd-units -BuildRequires: systemd-units +Requires: logrotate +Requires: ncurses +Requires: pcre2 +Requires: redhat-rpm-config +Requires(post): /usr/bin/uuidgen + +%if %{with system_allocator} +# use glibc +%else +%if %{without bundled_jemalloc} +Requires: jemalloc %endif -%if 0%{?rhel} == 6 -Requires: %{name}-selinux -Requires(post): policycoreutils, -Requires(preun): policycoreutils -Requires(postun): policycoreutils -Requires(post): /sbin/chkconfig -Requires(preun): /sbin/chkconfig -Requires(preun): /sbin/service %endif %description @@ -149,17 +139,12 @@ Summary: Development files for %{name} Provides: varnish-libs-devel%{?isa} = %{version}-%{release} Provides: varnish-libs-devel = %{version}-%{release} Obsoletes: varnish-libs-devel < %{version}-%{release} +Requires: %{name} = %{version}-%{release} +Requires: python3 %description devel Development files for %{name} Varnish Cache is a high-performance HTTP accelerator -Requires: %{name} = %{version}-%{release} - -%if 0%{?rhel} == 6 -Requires: python34 -%else -Requires: python3 -%endif %package docs Summary: Documentation files for %name @@ -167,50 +152,95 @@ Summary: Documentation files for %name %description docs Documentation files for %name -%if 0%{?rhel} == 6 -%package selinux -Summary: Minimal selinux policy for running varnish - -%description selinux -Minimal selinux policy for running varnish4 -%endif - %prep -%setup -q -n varnish-%{version}%{?vd_rc} +%setup -q +%if 0%{?fedora} > 44 || 0%{?rhel} > 10 +%patch 1 -p1 +%endif tar xzf %SOURCE1 ln -s pkg-varnish-cache-%{commit1}/redhat redhat ln -s pkg-varnish-cache-%{commit1}/debian debian cp redhat/find-provides . -%if 0%{?rhel} == 6 -cp pkg-varnish-cache-%{commit1}/sysv/redhat/* redhat/ -sed -i '8 i\RPM_BUILD_ROOT=%{buildroot}' find-provides +sed -i 's,rst2man-3.6,rst2man-3.4,g; s,rst2html-3.6,rst2html-3.4,g; s,phinx-build-3.6,phinx-build-3.4,g' configure + +# jemalloc +%if %{with bundled_jemalloc} +tar xjf %SOURCE3 +sed -i '/^LIBPREFIX/s/@libprefix@/@libprefix@%{jemalloc_prefix}/' jemalloc*/Makefile.in +pushd jemalloc* +%patch 100 -p1 -b .jemalloc +%patch 101 -p1 -b .ts-segfault +popd + +# Override PAGESIZE, bz #1545539 +%ifarch %ix86 %arm x86_64 s390x riscv64 +%define lg_page --with-lg-page=12 %endif -%if 0%{?rhel} == 6 -%patch4 -p0 -%patch16 -p1 +%ifarch ppc64 ppc64le aarch64 +%define lg_page --with-lg-page=16 +%endif + +# Disable thp on systems not supporting this for now +%ifarch %ix86 %arm aarch64 s390x +%define disable_thp --disable-thp +%endif %endif %build -%if 0%{?rhel} == 6 -export CFLAGS="%{optflags} -fPIC" -export LDFLAGS=" -pie" +%if %{with bundled_jemalloc} +# build bundled jemalloc first +pushd jemalloc* + +echo "For debugging package builders" +echo "What is the pagesize?" +getconf PAGESIZE + +echo "What mm features are available?" +ls /sys/kernel/mm +ls /sys/kernel/mm/transparent_hugepage || true +cat /sys/kernel/mm/transparent_hugepage/enabled || true + +echo "What kernel version and config is this?" +uname -a + +%configure %{?disable_thp} %{?lg_page} --enable-prof +make %{?_smp_mflags} +popd +%endif + + +# varnish +%if %{with system_allocator} +export CFLAGS="%{optflags}" +%else +# nilled _lto_cflags above because they remove the deps on jemalloc. +# On the fedoras, _lto_cflags is -flto=auto and -ffat-lto-objects. The latter is OK. +export CFLAGS="%{optflags} -ffat-lto-objects" %endif # https://gcc.gnu.org/wiki/FAQ#PR323 %ifarch %ix86 %if 0%{?fedora} > 21 -export CFLAGS="%{optflags} -ffloat-store -fexcess-precision=standard" -%endif -%if 0%{?rhel} >= 6 -export CFLAGS="%{optflags} -fno-exceptions -fPIC -ffloat-store" +export CFLAGS="$CFLAGS -ffloat-store -fexcess-precision=standard" %endif %endif -%ifarch s390x -export CFLAGS="%{optflags} -Wno-error=free-nonheap-object" +%if 0%{?fedora} > 41 || 0%{?rhel} > 10 +export CFLAGS="$CFLAGS -std=gnu17" %endif +%if 0%{?fedora} > 42 || 0%{?rhel} > 10 +export CFLAGS="$CFLAGS -Wno-error=discarded-qualifiers" +%endif + +%ifarch s390x +export CFLAGS="$CFLAGS -Wno-error=free-nonheap-object" +%endif + +# What platform is this +uname -a + # What gcc version is this? gcc --version @@ -220,23 +250,35 @@ getconf PAGESIZE # Man pages are prebuilt. No need to regenerate them. export RST2MAN=/bin/true # Explicit python, please -export PYTHON=%{__python} +export PYTHON=python3 + +for f in configure configure.ac; do + sed -i 's|ljemalloc|l%{jemalloc_prefix}jemalloc|g' $f +done + +%if %{with bundled_jemalloc} +export LDFLAGS="$LDFLAGS -L%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib" +%endif %configure LT_SYS_LIBRARY_PATH=%_libdir \ --disable-static \ -%ifarch aarch64 -%if 0%{?rhel} > 0 + --localstatedir=/var/lib \ + --with-contrib \ + --docdir=%{?_pkgdocdir}%{!?_pkgdocdir:%{_docdir}/%{name}-%{version}} \ +%ifarch %ix86 +%if 0%{?fedora} <= 37 + --enable-pcre2-jit=no \ +%endif +%endif +%if %{with system_allocator} || %{without bundled_jemalloc} --with-jemalloc=no \ %endif -%endif -%if 0%{?rhel} != 6 - --with-sphinx-build=sphinx-build-3.4 \ -%endif - --localstatedir=/var/lib \ - --docdir=%{?_pkgdocdir}%{!?_pkgdocdir:%{_docdir}/%{name}-%{version}} \ -# --disable-pcre-jit \ -make %{?_smp_mflags} V=1 +%if %{with bundled_jemalloc} +export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib +%endif + +%make_build # One varnish user is enough sed -i 's,User=varnishlog,User=varnish,g;' redhat/varnishncsa.service @@ -245,28 +287,55 @@ sed -i 's,User=varnishlog,User=varnish,g;' redhat/varnishncsa.service rm -rf doc/html/_sources %check - -# rhbz #1690796 -%if 0%{?rhel} == 6 -%ifarch ppc64 ppc64le aarch64 -rm bin/varnishtest/tests/c00057.vtc -%endif +# check jemalloc first +%if %{with bundled_jemalloc} +pushd jemalloc* +make %{?_smp_mflags} check +popd %endif -# Remove this for now. Hard to get the size and timing right -%ifarch s390 s390x -rm bin/varnishtest/tests/o00005.vtc +# Up the stack size in tests, necessary on secondary arches +sed -i 's/thread_pool_stack 80k/thread_pool_stack 128k/g;' bin/vinyltest/tests/*.vtc +sed -i 's/file,2M/file,8M/' bin/vinyltest/tests/r04036.vtc +%ifarch %ix86 +sed -i 's/param.set workspace_thread 0.55k/param.set workspace_thread 0.5k/' bin/vinyltest/tests/b00081.vtc %endif -make %{?_smp_mflags} check VERBOSE=1 +# This is a bug in varnishtest making it incompatible with nghttp2 >= 1.65 +#if 0#{?fedora} > 41 || 0#{?rhel} > 10 +#rm bin/varnishtest/tests/a02022.vtc +#endif +%if %{with bundled_jemalloc} +export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib +%endif + +# This runs fine in the emulator, but not on Red Hat's builders +# Upstream is looking at it, upstream issue #36 +%ifarch s390x +rm bin/vinyltest/tests/t02033.vtc +%endif + +# Just a hack to avoid too high load on secondary arch builders +%ifarch s390x ppc64le %ix86 +make check +%else +%make_build check +%endif %install rm -rf %{buildroot} -# mock el6 and el7 defaults to LANG=C, which makes python3 fail when parsing utf8 text -%if 0%{?rhel} == 6 || 0%{?rhel} == 7 -export LANG=en_US.UTF-8 +# jemalloc +%if %{with bundled_jemalloc} +pushd jemalloc* +make DESTDIR=%{buildroot} install_lib %{?_smp_mflags} + +find %{buildroot}%{_libdir}/ -name '*.a' -exec rm -vf {} ';' + +# we don't need .pc file +rm %{buildroot}%{_libdir}/pkgconfig/jemalloc.pc +popd %endif %{make_install} @@ -283,67 +352,55 @@ install -D -m 0644 redhat/varnish.logrotate %{buildroot}%{_sysconfdir}/logrotate install -D -m 0644 include/vcs_version.h %{buildroot}%{_includedir}/varnish install -D -m 0644 include/vrt.h %{buildroot}%{_includedir}/varnish -# systemd support -%if 0%{?fedora} >= 17 || 0%{?rhel} >= 7 mkdir -p %{buildroot}%{_unitdir} install -D -m 0644 redhat/varnish.service %{buildroot}%{_unitdir}/varnish.service install -D -m 0644 redhat/varnishncsa.service %{buildroot}%{_unitdir}/varnishncsa.service - -# default is standard sysvinit -%else -install -D -m 0644 redhat/varnish.sysconfig %{buildroot}%{_sysconfdir}/sysconfig/varnish -install -D -m 0755 redhat/varnish.initrc %{buildroot}%{_initrddir}/varnish -install -D -m 0755 redhat/varnishncsa.initrc %{buildroot}%{_initrddir}/varnishncsa -%endif install -D -m 0755 redhat/varnishreload %{buildroot}%{_sbindir}/varnishreload +install -p -D -m 0644 %{SOURCE2} %{buildroot}%{_sysusersdir}/varnish.conf -echo %{_libdir}/varnish > %{buildroot}%{_sysconfdir}/ld.so.conf.d/varnish-%{_arch}.conf +# tmpfiles.d configuration +mkdir -p %{buildroot}%{_tmpfilesdir} +install -m 644 -p %{SOURCE4} %{buildroot}%{_tmpfilesdir}/varnish.conf + +echo %{_libdir}/varnish > %{buildroot}%{_sysconfdir}/ld.so.conf.d/%{name}-%{_arch}.conf # No idea why these ends up with mode 600 in the debug package +%if 0%{debug_package} chmod 644 lib/libvmod_*/*.c chmod 644 lib/libvmod_*/*.h - -# selinux module for el6 -%if 0%{?rhel} == 6 -cd selinux -make -f %{_datadir}/selinux/devel/Makefile -install -p -m 644 -D varnish4.pp %{buildroot}%{_datadir}/selinux/packages/%{name}/varnish4.pp %endif +%pre +%sysusers_create_compat %{SOURCE2} + %files +%if "%{_sbindir}" != "%{_bindir}" %{_sbindir}/* +%endif %{_bindir}/* %{_libdir}/*.so.* -%{_libdir}/varnish +%{_libdir}/%{name} %{_var}/lib/varnish %attr(0700,varnish,varnish) %dir %{_var}/log/varnish %{_mandir}/man1/*.1* %{_mandir}/man3/*.3* %{_mandir}/man7/*.7* %license LICENSE -%doc README.rst ChangeLog +%doc README.md ChangeLog %doc etc/builtin.vcl etc/example.vcl %dir %{_sysconfdir}/varnish/ %config(noreplace) %{_sysconfdir}/varnish/default.vcl %config(noreplace) %{_sysconfdir}/logrotate.d/varnish -%config %{_sysconfdir}/ld.so.conf.d/varnish-%{_arch}.conf +%config %{_sysconfdir}/ld.so.conf.d/%{name}-%{_arch}.conf - -# systemd from fedora 17 and rhel 7 -%if 0%{?fedora} >= 17 || 0%{?rhel} >= 7 %{_unitdir}/varnish.service %{_unitdir}/varnishncsa.service - -# default is standard sysvinit -%else -%config(noreplace) %{_sysconfdir}/sysconfig/varnish -%{_initrddir}/varnish -%{_initrddir}/varnishncsa -%endif +%{_sysusersdir}/varnish.conf +%{_tmpfilesdir}/varnish.conf %files devel %license LICENSE -%doc README.rst +%doc README.md %{_libdir}/lib*.so %{_includedir}/%{name} %{_libdir}/pkgconfig/varnishapi.pc @@ -355,84 +412,218 @@ install -p -m 644 -D varnish4.pp %{buildroot}%{_datadir}/selinux/packages/%{name %doc doc/html %doc doc/changes*.html -%if 0%{?rhel} == 6 -%files selinux -%{_datadir}/selinux/packages/%{name}/varnish4.pp -%endif - -%pre -getent group varnish >/dev/null || groupadd -r varnish -getent passwd varnish >/dev/null || \ - useradd -r -g varnish -d /var/lib/varnish -s /sbin/nologin \ - -c "Varnish Cache" varnish -exit 0 - %post -%if 0%{?fedora} >= 17 || 0%{?rhel} >= 7 %systemd_post varnish varnishncsa - -# Other distros: Use chkconfig -%else -/sbin/chkconfig --add varnish -/sbin/chkconfig --add varnishncsa -%endif - /sbin/ldconfig - -# Previous versions had varnishlog and varnishncsa running as root -chown varnish:varnish /var/log/varnish/varnishncsa.log 2>/dev/null || true - test -f /etc/varnish/secret || (uuidgen > /etc/varnish/secret && chmod 0600 /etc/varnish/secret) -# selinux module for el6 -%if 0%{?rhel} == 6 -%post selinux -if [ "$1" -le "1" ] ; then # First install -semodule -i %{_datadir}/selinux/packages/%{name}/varnish4.pp 2>/dev/null || : -fi - -%preun selinux -if [ "$1" -lt "1" ] ; then # Final removal -semodule -r varnish4 2>/dev/null || : -fi - %postun -%if 0%{?fedora} >= 18 || 0%{?rhel} >= 7 %systemd_postun_with_restart varnish varnishncsa -%endif /sbin/ldconfig -%postun selinux -if [ "$1" -ge "1" ] ; then # Upgrade -semodule -i %{_datadir}/selinux/packages/%{name}/varnish4.pp 2>/dev/null || : -fi - -%endif - %preun - -%if 0%{?fedora} >= 18 || 0%{?rhel} >= 7 %systemd_preun varnish varnishncsa -%else - -if [ $1 -lt 1 ]; then - # Package removal, not upgrade - %if 0%{?fedora} >= 17 || 0%{?rhel} >= 7 - /bin/systemctl --no-reload disable varnish.service > /dev/null 2>&1 || : - /bin/systemctl stop varnish.service > /dev/null 2>&1 || : - /bin/systemctl stop varnishncsa.service > /dev/null 2>&1 || : - %else - /sbin/service varnish stop > /dev/null 2>&1 - /sbin/service varnishncsa stop > /dev/null 2>%1 - /sbin/chkconfig --del varnish - /sbin/chkconfig --del varnishncsa - %endif -fi -%endif %changelog +* Fri Jul 17 2026 Fedora Release Engineering - 9.0.3-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + +* Sat Jun 13 2026 Yaakov Selkowitz - 9.0.3-2 +- Rebuilt for openssl 4.0 + +* Thu May 21 2026 Ingvar Hagelund - 9.0.3-1 +- New upstream release: A security relase +- Includes fix for VSV00019 aka CVE-2026-50052 + +* Fri May 15 2026 Ingvar Hagelund - 9.0.2-1 +- New upstream release: A bugfix release + +* Fri Apr 10 2026 Ingvar Hagelund - 9.0.1-1 +- New upstream release +- Add patch for openssl-4.0.0 in rawhide +- Includes fix for VEV00002 + +* Fri Mar 27 2026 Ingvar Hagelund - 9.0.0-1 +- New upstream release +- Includes fix for VSV00018 + +* Sat Jan 17 2026 Fedora Release Engineering - 8.0.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + +* Thu Dec 11 2025 Ingvar Hagelund - 8.0.0-1 +- New upstream release +- New pkg-varnish-cache checkout +- Added cflag -Wno-error=discarded-qualifiers to build on fedora while waiting for upstream + +* Wed Oct 29 2025 Luboš Uhliarik - 7.7.3-2 +- Add tmpfiles.d rules for /var directories (bootc compatibility) + +* Mon Sep 15 2025 Ingvar Hagelund - 7.7.3-1 +- New upstream release: A security release +- Includes fix for VSV00017 aka CVE-2025-8671, rhbz#2388222 + +* Thu Jul 31 2025 Luboš Uhliarik - 7.7.1-4 +- bundle jemalloc in RHEL + +* Fri Jul 25 2025 Fedora Release Engineering - 7.7.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Thu May 22 2025 Ingvar Hagelund - 7.7.1-2 +- Correct ABI and VRT versions +- Pulled el7 support +- Use systemd setup for users + +* Tue May 20 2025 Luboš Uhliarik - 7.7.1-1 +- new version 7.7.1 + +* Thu Mar 27 2025 Ingvar Hagelund - 7.7.0-2 +- Fix for eln build (merged from yselkowitz) +- Fix for failing h2 switch check. Enabling full test suite again + +* Mon Mar 24 2025 Ingvar Hagelund - 7.7.0-1 +- New upstream release +- fedora now has completed the bin/sbin merge + +* Sun Jan 19 2025 Fedora Release Engineering - 7.6.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Mon Dec 02 2024 Ingvar Hagelund - 7.6.1-1 +- New upstream release + +* Mon Sep 16 2024 Ingvar Hagelund - 7.6.0-1 +- New upstream release +- Updated checkout of pkg-varnish + +* Sat Jul 20 2024 Fedora Release Engineering - 7.5.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Tue Mar 19 2024 Ingvar Hagelund - 7.5.0-1 +- New upstream release +- Moved somethings around to make the diff from the upstream spec less +- Upped some memory requirements in some of the tests. Necessary on aarch64 and ppc64le (and ppc32) +- Reduced number of parallel jobs on s390x builders as builds tend to fail when stressed +- Retired armv7hl + +* Sat Jan 27 2024 Fedora Release Engineering - 7.4.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Wed Nov 08 2023 Ingvar Hagelund - 7.4.2-1 +- New upstream release. A security release +- Includes fix for CVE-2023-44487 aka VSV00013, rhbz#2243328, HTTP/2 Rapid Reset Attack + +* Thu Oct 12 2023 Ingvar Hagelund - 7.4.1-1 +- New upstream release. A bugfix release + +* Wed Oct 11 2023 Ingvar Hagelund - 7.4.0-0 +- New upstream release + +* Thu Sep 14 2023 Luboš Uhliarik - 7.3.0-5 +- SPDX migration + +* Sat Jul 22 2023 Fedora Release Engineering - 7.3.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Fri Jun 23 2023 Yaakov Selkowitz - 7.3.0-3 +- Enable system_allocator in RHEL/ELN builds + +* Mon Mar 20 2023 Ingvar Hagelund - 7.3.0-2 +- Switched from bcond to bcond_with for compatibility with el8 and el9 +- haproxy builddep on systems with haproxy2 +- Disable pcre2-jit only for fedora <= 37 on 32bit x86 + +* Thu Mar 16 2023 Ingvar Hagelund - 7.3.0-1 +- New upstream release +- Added a bcond system_allocator for skipping jemalloc, bz#1917697 +- nil _lto_cflags macro to link to jemalloc again +- disable pcre2-jit on 32bit x86 for now + +* Sat Jan 21 2023 Fedora Release Engineering - 7.2.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Wed Nov 09 2022 Ingvar Hagelund - 7.2.1-1 +- New upstream release: A security release +- Includes fix for VSV00011 + +* Fri Sep 16 2022 Ingvar Hagelund - 7.2.0-1 +- New upstream release. The regular bi-annual "fresh" release +- Removed list of patches from comments +- Cosmetical changes to specfile from upstream +- Now build with --with-contrib + +* Fri Aug 12 2022 Ingvar Hagelund - 7.1.1-1 +- New upstream release. A security release +- Includes fix for VSV00009 aka CVE-2022-38150 + +* Sat Jul 23 2022 Fedora Release Engineering - 7.1.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Tue Mar 29 2022 Ingvar Hagelund - 7.1.0-1 +- New upstream release +- Includes updated snapshot of pkg-varnish + +* Mon Feb 21 2022 Luboš Uhliarik - 7.0.2-2 +- Fix Provides directive for varnish-devel package + +* Wed Jan 26 2022 Ingvar Hagelund - 7.0.2-1 +- New upstream release. A security release +- Includes fix for CVE-2022-23959 aka VSV00008, rhbz#2045033 + +* Sat Jan 22 2022 Fedora Release Engineering - 7.0.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Thu Jan 13 2022 Ingvar Hagelund - 7.0.1-2 +- Update ABI string + +* Thu Jan 13 2022 Ingvar Hagelund - 7.0.1-1 +- New upstream release. A maintenance and stability release + +* Tue Nov 02 2021 Ingvar Hagelund - 7.0.0-2 +- upstream switched to pcre2 a while ago + +* Thu Sep 16 2021 Ingvar Hagelund - 7.0.0-1 +- New upstream release +- Updated pkg-varnish checkout from the 7.0 branch + +* Fri Jul 23 2021 Fedora Release Engineering - 6.6.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Sat Jul 17 2021 Ingvar Hagelund 6.6.1-2 +- Bumped abi and vrt versions + +* Sat Jul 17 2021 Ingvar Hagelund 6.6.1-1 +- New upstream release +- Includes fix for CVE-2021-36740 aka VSV00007, bz#1982413 + +* Tue May 18 2021 Timm Bäder - 6.6.0-2 +- Use make macros + +* Mon Mar 15 2021 Ingvar Hagelund - 6.6.0-1 +- New upstream release +- Now provides vmod_purge +- Uses haproxy in the test suite on el8 +- Skipped obsoleting varnish-libs. That was many years ago now. + +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 6.5.1-4 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + +* Wed Jan 27 2021 Fedora Release Engineering - 6.5.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Thu Jan 21 2021 Ingvar Hagelund 6.5.1-2 +- Pulled support for el6 +- Pulled support for sysvinit +- aarch64 builds now with jemalloc again on el7 + +* Fri Sep 25 2020 Ingvar Hagelund 6.5.1-1 +- New upstream release varnish-6.5.1 + +* Wed Sep 16 2020 Ingvar Hagelund 6.5.0-1 +- New upstream release varnish-6.5.0 +- Respun silly patch to get rid of compiler warnings on el6 + * Tue Aug 04 2020 Ingvar Hagelund 6.4.0-4 - Added -Wno-error=free-nonheap-object to CFLAGS to build on s390x diff --git a/varnish.sysusers b/varnish.sysusers new file mode 100644 index 0000000..58b740e --- /dev/null +++ b/varnish.sysusers @@ -0,0 +1,3 @@ +#Type Name ID GECOS Home directory Shell +g varnish - +u varnish - "Varnish Cache" /var/lib/varnish /sbin/nologin diff --git a/varnish.tmpfiles b/varnish.tmpfiles new file mode 100644 index 0000000..2717356 --- /dev/null +++ b/varnish.tmpfiles @@ -0,0 +1,2 @@ +d /var/lib/varnish 755 root root - +d /var/log/varnish 700 varnish varnish -