Compare commits

..

2 commits

Author SHA1 Message Date
Ingvar Hagelund
8cd5ade963 fixed filename for fix_h00004.vtc.patch 2025-03-26 16:46:59 +01:00
Ingvar Hagelund
9b6c565f88 Security: Added patch for VSV00015 aka CVE-2025-30346, BZ#2354008 2025-03-26 16:44:37 +01:00
11 changed files with 160 additions and 666 deletions

14
.gitignore vendored
View file

@ -62,17 +62,3 @@ varnish-2.1.3.tar.gz
/varnish-7.4.0.tgz
/varnish-7.4.1.tgz
/varnish-7.4.2.tgz
/varnish-7.5.0.tgz
/varnish-7.6.0.tgz
/pkg-varnish-cache-7d90347.tar.gz
/varnish-7.6.1.tgz
/varnish-7.7.0.tgz
/varnish-7.7.1.tgz
/jemalloc-5.3.0.tar.bz2
/varnish-7.7.3.tgz
/varnish-8.0.0.tgz
/pkg-varnish-cache-1f0d212.tar.gz
/varnish-9.0.0.tar.gz
/varnish-9.0.1.tar.gz
/varnish-9.0.2.tar.gz
/varnish-9.0.3.tar.gz

46
VSV00015.patch Normal file
View file

@ -0,0 +1,46 @@
commit 8ef69a03b36aeac5f364c01eb20f821860e47f14
Author: Dag Haavi Finstad <daghf@varnish-software.com>
Date: Fri Jan 10 13:07:54 2025 +0100
req_fsm: Close the connection on a malformed request
diff --git a/bin/varnishd/cache/cache_req_fsm.c b/bin/varnishd/cache/cache_req_fsm.c
index 1004cbc5f..803810210 100644
--- a/bin/varnishd/cache/cache_req_fsm.c
+++ b/bin/varnishd/cache/cache_req_fsm.c
@@ -962,6 +962,7 @@ cnt_recv(struct worker *wrk, struct req *req)
if (http_CountHdr(req->http0, H_Host) > 1) {
VSLb(req->vsl, SLT_BogoHeader, "Multiple Host: headers");
wrk->stats->client_req_400++;
+ req->doclose = SC_RX_BAD;
(void)req->transport->minimal_response(req, 400);
return (REQ_FSM_DONE);
}
@@ -969,6 +970,7 @@ cnt_recv(struct worker *wrk, struct req *req)
if (http_CountHdr(req->http0, H_Content_Length) > 1) {
VSLb(req->vsl, SLT_BogoHeader, "Multiple Content-Length: headers");
wrk->stats->client_req_400++;
+ req->doclose = SC_RX_BAD;
(void)req->transport->minimal_response(req, 400);
return (REQ_FSM_DONE);
}
diff --git a/bin/varnishtest/tests/b00037.vtc b/bin/varnishtest/tests/b00037.vtc
index ce0e84112..e6185bd07 100644
--- a/bin/varnishtest/tests/b00037.vtc
+++ b/bin/varnishtest/tests/b00037.vtc
@@ -11,6 +11,7 @@ client c1 {
varnish v1 -vsl_catchup
varnish v1 -expect client_req_400 == 1
+varnish v1 -expect sc_rx_bad == 1
client c1 {
txreq -method POST -hdr "Content-Length: 12" -hdr "Content-Length: 12" -bodylen 12
@@ -20,6 +21,7 @@ client c1 {
varnish v1 -vsl_catchup
varnish v1 -expect client_req_400 == 2
+varnish v1 -expect sc_rx_bad == 2
varnish v1 -cliok "param.set feature +http2"

View file

@ -1,140 +0,0 @@
diff --git a/test/unit/psset.c b/test/unit/psset.c
index 6ff7201..58b4a88 100644
--- a/test/unit/psset.c
+++ b/test/unit/psset.c
@@ -124,7 +124,7 @@ TEST_BEGIN(test_fill) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -147,6 +147,8 @@ TEST_BEGIN(test_fill) {
edata_init_test(&extra_alloc);
err = test_psset_alloc_reuse(&psset, &extra_alloc, PAGE);
expect_true(err, "Alloc succeeded even though psset should be empty");
+
+ free(alloc);
}
TEST_END
@@ -157,7 +159,7 @@ TEST_BEGIN(test_reuse) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -239,6 +241,8 @@ TEST_BEGIN(test_reuse) {
err = test_psset_alloc_reuse(&psset, &alloc[index_of_4], 4 * PAGE);
expect_false(err, "Should have been able to find alloc.");
edata_expect(&alloc[index_of_4], index_of_4, 4);
+
+ free(alloc);
}
TEST_END
@@ -249,7 +253,7 @@ TEST_BEGIN(test_evict) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -273,6 +277,8 @@ TEST_BEGIN(test_evict) {
err = test_psset_alloc_reuse(&psset, &alloc[0], PAGE);
expect_true(err, "psset should be empty.");
+
+ free(alloc);
}
TEST_END
@@ -286,7 +292,9 @@ TEST_BEGIN(test_multi_pageslab) {
(void *)((uintptr_t)PAGESLAB_ADDR + HUGEPAGE),
PAGESLAB_AGE + 1);
- edata_t alloc[2][HUGEPAGE_PAGES];
+ edata_t* alloc[2];
+ alloc[0] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ alloc[1] = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -336,6 +344,9 @@ TEST_BEGIN(test_multi_pageslab) {
*/
err = test_psset_alloc_reuse(&psset, &alloc[1][0], 2 * PAGE);
expect_false(err, "Allocation should have succeeded");
+
+ free(alloc[0]);
+ free(alloc[1]);
}
TEST_END
@@ -385,7 +396,7 @@ TEST_BEGIN(test_stats) {
hpdata_t pageslab;
hpdata_init(&pageslab, PAGESLAB_ADDR, PAGESLAB_AGE);
- edata_t alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
psset_t psset;
psset_init(&psset);
@@ -415,6 +426,8 @@ TEST_BEGIN(test_stats) {
stats_expect(&psset, 0);
psset_update_end(&psset, &pageslab);
stats_expect(&psset, 1);
+
+ free(alloc);
}
TEST_END
@@ -475,8 +488,8 @@ init_test_pageslabs(psset_t *psset, hpdata_t *pageslab,
TEST_BEGIN(test_oldest_fit) {
bool err;
- edata_t alloc[HUGEPAGE_PAGES];
- edata_t worse_alloc[HUGEPAGE_PAGES];
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
hpdata_t pageslab;
hpdata_t worse_pageslab;
@@ -493,14 +506,19 @@ TEST_BEGIN(test_oldest_fit) {
expect_false(err, "Nonempty psset failed page allocation");
expect_ptr_eq(&pageslab, edata_ps_get(&test_edata),
"Allocated from the wrong pageslab");
+
+ free(alloc);
+ free(worse_alloc);
}
TEST_END
TEST_BEGIN(test_insert_remove) {
bool err;
hpdata_t *ps;
- edata_t alloc[HUGEPAGE_PAGES];
- edata_t worse_alloc[HUGEPAGE_PAGES];
+
+ edata_t *alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+ edata_t *worse_alloc = (edata_t *)malloc(sizeof(edata_t) * HUGEPAGE_PAGES);
+
hpdata_t pageslab;
hpdata_t worse_pageslab;
@@ -539,6 +557,9 @@ TEST_BEGIN(test_insert_remove) {
psset_update_begin(&psset, &worse_pageslab);
err = test_psset_alloc_reuse(&psset, &alloc[HUGEPAGE_PAGES - 1], PAGE);
expect_true(err, "psset should be empty, but an alloc succeeded");
+
+ free(alloc);
+ free(worse_alloc);
}
TEST_END

View file

@ -1,29 +0,0 @@
commit 3de0c24859f4413bf03448249078169bb50bda0f
Author: divanorama <divanorama@gmail.com>
Date: Thu Sep 29 23:35:59 2022 +0200
Disable builtin malloc in tests
With `--with-jemalloc-prefix=` and without `-fno-builtin` or `-O1` both clang and gcc may optimize out `malloc` calls
whose result is unused. Comparing result to NULL also doesn't necessarily count as being used.
This won't be a problem in most client programs as this only concerns really unused pointers, but in
tests it's important to actually execute allocations.
`-fno-builtin` should disable this optimization for both gcc and clang, and applying it only to tests code shouldn't hopefully be an issue.
Another alternative is to force "use" of result but that'd require more changes and may miss some other optimization-related issues.
This should resolve https://github.com/jemalloc/jemalloc/issues/2091
diff --git a/Makefile.in b/Makefile.in
index 6809fb29..a964f07e 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -458,6 +458,8 @@ $(TESTS_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.c
$(TESTS_CPP_OBJS): $(objroot)test/%.$(O): $(srcroot)test/%.cpp
$(TESTS_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include
$(TESTS_CPP_OBJS): CPPFLAGS += -I$(srcroot)test/include -I$(objroot)test/include
+$(TESTS_OBJS): CFLAGS += -fno-builtin
+$(TESTS_CPP_OBJS): CPPFLAGS += -fno-builtin
ifneq ($(IMPORTLIB),$(SO))
$(CPP_OBJS) $(C_SYM_OBJS) $(C_OBJS) $(C_JET_SYM_OBJS) $(C_JET_OBJS): CPPFLAGS += -DDLLEXPORT
endif

View file

@ -1,3 +1,2 @@
SHA512 (varnish-9.0.3.tar.gz) = 2789cff88632c2279062a109513cc00cab7690785f8f77e90b9968098c71ddcdc6403d6a9edc755b8f4055f0d32d9e330b0bc20fbab92ba80232955942dc912a
SHA512 (jemalloc-5.3.0.tar.bz2) = 22907bb052096e2caffb6e4e23548aecc5cc9283dce476896a2b1127eee64170e3562fa2e7db9571298814a7a2c7df6e8d1fbe152bd3f3b0c1abec22a2de34b1
SHA512 (pkg-varnish-cache-1f0d212.tar.gz) = 9f05978c99f292e64e71ba24ef2de791a33640e40fbad66d47889837fb0d4ced203873f5a17716edf757b5ad48098289882c2df196ce1fb457f279bf7f35bec3
SHA512 (varnish-7.4.2.tgz) = acd61a852ac7d66b268ab831d3a771d7a063a6a257b5e7c25c5a2ec9bccefa845279b9bd5fc85dd0b4f1d56da59164a13149355d1e6187e71ad76463687f7971
SHA512 (pkg-varnish-cache-cfa8cb3.tar.gz) = 058e689186d1b01bb4a256ff3a5a373337e380a0a87128d4b2adbcff41210189e7f4b3d56e8451f06120449c04aaa4ddc61f934a1fda9c5336dfe2020c66a569

View file

@ -0,0 +1,48 @@
--- bin/varnishtest/vtc_haproxy.c.orig 2023-11-13 09:41:21.000000000 +0100
+++ bin/varnishtest/vtc_haproxy.c 2025-03-26 16:27:52.525931293 +0100
@@ -55,7 +55,6 @@
#define HAPROXY_OPT_DAEMON "-D"
#define HAPROXY_SIGNAL SIGINT
#define HAPROXY_EXPECT_EXIT (128 + HAPROXY_SIGNAL)
-#define HAPROXY_GOOD_CONF "Configuration file is valid"
struct envar {
VTAILQ_ENTRY(envar) list;
@@ -268,7 +267,7 @@
}
/* Connection closed. */
if (ret == 0) {
- if (hc->rxbuf[rdz - 1] != '\n')
+ if (rdz > 0 && hc->rxbuf[rdz - 1] != '\n')
vtc_fatal(hc->vl,
"CLI rx timeout (fd: %d %.3fs ret: %zd)",
hc->sock, hc->timeout, ret);
@@ -291,7 +290,7 @@
* SECTION: haproxy.cli.expect
* expect OP STRING
* Regex match the CLI reception buffer with STRING
- * if OP is ~ or, on the contraty, if OP is !~ check that there is
+ * if OP is ~ or, on the contrary, if OP is !~ check that there is
* no regex match.
*/
static void v_matchproto_(cmd_f)
@@ -825,7 +824,7 @@
vtc_log(h->vl, 4,
"Kill(%d)=%d: %s", sig, i, strerror(errno));
}
- usleep(100000);
+ VTIM_sleep(0.1);
if (++n == 20) {
switch (sig) {
case SIGINT: sig = SIGTERM ; break;
@@ -1077,8 +1076,9 @@
if (!strcmp(*av, "-conf-OK")) {
AN(av[1]);
haproxy_store_conf(h, av[1], 0);
+ h->expect_exit = 0;
+ haproxy_check_conf(h, "");
av++;
- haproxy_check_conf(h, HAPROXY_GOOD_CONF);
continue;
}
if (!strcmp(*av, "-conf-BAD")) {

View file

@ -1,178 +0,0 @@
commit 95e41dfa584d108e444949534c7ce5801cffeacc
Author: Poul-Henning Kamp <phk@FreeBSD.org>
Date: Wed Mar 26 09:25:43 2025 +0000
If the client sends NO_RFC7540_PRIORITIES, "rxprio" verbs become no-ops.
Fixes: #4298
Tested by: @ingvarha
commit 3a1eb57d8bd57205db7d2c766aed39cf73c4f578
Author: Poul-Henning Kamp <phk@FreeBSD.org>
Date: Wed Mar 26 09:24:17 2025 +0000
Add more HTTP2 Settings to the table
diff --git a/bin/varnishtest/vtc.h b/bin/varnishtest/vtc.h
index 2e5d4161a..b765fe60a 100644
--- a/bin/varnishtest/vtc.h
+++ b/bin/varnishtest/vtc.h
@@ -148,7 +148,7 @@ struct http;
void cmd_stream(CMD_ARGS);
void start_h2(struct http *hp);
void stop_h2(struct http *hp);
-void b64_settings(const struct http *hp, const char *s);
+void b64_settings(struct http *hp, const char *s);
/* vtc_gzip.c */
void vtc_gunzip(struct http *, char *, long *);
diff --git a/bin/varnishtest/vtc_http.h b/bin/varnishtest/vtc_http.h
index 7a86de8da..62c598a55 100644
--- a/bin/varnishtest/vtc_http.h
+++ b/bin/varnishtest/vtc_http.h
@@ -83,6 +83,7 @@ struct http {
/* H/2 */
unsigned h2;
int wf;
+ int no_rfc7540_priorities;
pthread_t tp;
VTAILQ_HEAD(, stream) streams;
diff --git a/bin/varnishtest/vtc_http2.c b/bin/varnishtest/vtc_http2.c
index 822abbae1..7feeb42b0 100644
--- a/bin/varnishtest/vtc_http2.c
+++ b/bin/varnishtest/vtc_http2.c
@@ -629,7 +629,7 @@ parse_settings(const struct stream *s, struct frame *f)
buf = "unknown";
u += 4;
- if (t == 1) {
+ if (t == SETTINGS_HEADER_TABLE_SIZE) {
r = HPK_ResizeTbl(s->hp->encctx, v);
assert(r == hpk_done);
}
@@ -2460,28 +2460,47 @@ cmd_rxsettings(CMD_ARGS)
hp->h2_win_peer->init = val;
}
}
+/* SECTION: stream.spec.prio_rxprio rxprio
+ *
+ * Receive a PRIORITY frame.
+ */
+static void
+cmd_rxprio (CMD_ARGS)
+{
+ struct stream *s;
+ (void)av;
+ CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC);
+ if (s->hp->no_rfc7540_priorities) {
+ vtc_log(vl, 4, "skipping rxprio: no_rfc7540_priorities is set");
+ return;
+ }
+ s->frame = rxstuff(s);
+ if (s->frame != NULL && s->frame->type != TYPE_PRIORITY) {
+ vtc_fatal(vl,
+ "Wrong frame type %s (%d) wanted %s",
+ s->frame->type < TYPE_MAX ?
+ h2_types[s->frame->type] : "?",
+ s->frame->type, "PRIORITY");
+ }
+}
#define RXFUNC(lctype, upctype) \
static void \
- cmd_rx ## lctype(CMD_ARGS) { \
+ cmd_rx ## lctype(CMD_ARGS) \
+ { \
struct stream *s; \
(void)av; \
CAST_OBJ_NOTNULL(s, priv, STREAM_MAGIC); \
s->frame = rxstuff(s); \
- if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) \
+ if (s->frame != NULL && s->frame->type != TYPE_ ## upctype) { \
vtc_fatal(vl, \
"Wrong frame type %s (%d) wanted %s", \
s->frame->type < TYPE_MAX ? \
h2_types[s->frame->type] : "?", \
s->frame->type, #upctype); \
+ } \
}
-/* SECTION: stream.spec.prio_rxprio rxprio
- *
- * Receive a PRIORITY frame.
- */
-RXFUNC(prio, PRIORITY)
-
/* SECTION: stream.spec.reset_rxrst rxrst
*
* Receive a RST_STREAM frame.
@@ -2857,7 +2876,7 @@ cmd_stream(CMD_ARGS)
}
void
-b64_settings(const struct http *hp, const char *s)
+b64_settings(struct http *hp, const char *s)
{
uint16_t i;
uint64_t v, vv;
@@ -2891,7 +2910,10 @@ b64_settings(const struct http *hp, const char *s)
else
buf = "unknown";
- if (v == 1) {
+ if (i == SETTINGS_NO_RFC7540_PRIORITIES) {
+ hp->no_rfc7540_priorities = v;
+ }
+ if (i == SETTINGS_HEADER_TABLE_SIZE) {
enum hpk_result hrs;
if (hp->sfd) {
AN(hp->encctx);
diff --git a/include/tbl/h2_settings.h b/include/tbl/h2_settings.h
index 2dbac671f..273f157fe 100644
--- a/include/tbl/h2_settings.h
+++ b/include/tbl/h2_settings.h
@@ -102,7 +102,39 @@ H2_SETTING( // rfc7540,l,2159,2167
0xffffffff,
0
)
-#endif
+
+H2_SETTING( // rfc8441
+ ENABLE_CONNECT_PROTOCOL,
+ enable_connect_protocol,
+ 0x8,
+ 0,
+ 0,
+ 1,
+ H2CE_PROTOCOL_ERROR
+)
+
+H2_SETTING( // rfc9218
+ NO_RFC7540_PRIORITIES,
+ no_rfc7540_priorities,
+ 0x9,
+ 0,
+ 0,
+ 1,
+ H2CE_PROTOCOL_ERROR
+)
+
+H2_SETTING( // [MS-HTTP2E]
+ // [Gabriel_Montenegro]
+ TLS_RENEG_PERMITTED,
+ tls_reneg_permitted,
+ 0x10,
+ 0,
+ 0,
+ 3,
+ H2CE_PROTOCOL_ERROR
+)
+#endif /* !H2_SETTINGS_PARAM_ONLY */
+
#undef H2_SETTING
/*lint -restore */

View file

@ -1,38 +0,0 @@
Author: Ingvar Hagelund <ingvar@redpill-linpro.com>
Date: Wed Apr 15 00:17:59 2026 +0200
Use ASN1_STRING functions for openssl-4.0.0
diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c
--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-08 18:57:33.000000000 +0200
+++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_asn_gentm.c 2026-04-15 00:34:44.788211992 +0200
@@ -142,10 +142,10 @@
char *a;
int n, i, l, o;
- if (d->type != V_ASN1_GENERALIZEDTIME)
+ if (ASN1_STRING_type(d) != V_ASN1_GENERALIZEDTIME)
return (0);
- l = d->length;
- a = (char *)d->data;
+ l = ASN1_STRING_length(d);
+ a = (char *)ASN1_STRING_get0_data(d);
o = 0;
/*
* GENERALIZEDTIME is similar to UTCTIME except the year is represented
diff -Naur varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c
--- varnish-9.0.1.orig/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-08 18:57:33.000000000 +0200
+++ varnish-9.0.1/bin/vinyltest/vtest2/src/vtc_tls.c 2026-04-15 00:35:53.447792774 +0200
@@ -1060,10 +1060,10 @@
break;
case GEN_IPADD:
- p = n->d.ip->data;
+ p = ASN1_STRING_get0_data(n->d.ip);
AN(p);
- if (inet_ntop(n->d.ip->length == 16 ? AF_INET6 : AF_INET,
+ if (inet_ntop(ASN1_STRING_length(n->d.ip) == 16 ? AF_INET6 : AF_INET,
p, b, INET6_ADDRSTRLEN) == 0)
continue;

View file

@ -2,26 +2,31 @@
# https://github.com/varnishcache/varnish-cache/issues/2269
%global debug_package %{nil}
%if 0%{?rhel} == 7
%global _use_internal_dependency_generator 0
%global __find_provides %{_builddir}/%{name}-%{version}/find-provides %__find_provides
%global __python /usr/bin/python3.4
%else
%global __python %{__python3}
%endif
%global __provides_exclude_from ^%{_libdir}/varnish/vmods
%global abi 0a625649cd40af4b6c10be5e58a2e89a5e275baa
%global vrt 23.1
%global abi cd1d10ab53a6f6115b2b4f3b2a1da94c1f749f80
%global vrt 18.0
# Package scripts are now external
# https://github.com/varnishcache/pkg-varnish-cache
%global commit1 1f0d212dc45065f38bd80ac57fe22773a20a0595
%global commit1 cfa8cb3724e4ca6398f60b09157715bcb99d189d
%global shortcommit1 %(c=%{commit1}; echo ${c:0:7})
# Default: Use jemalloc, as adviced by upstream project
# Change to 1 to use system allocator (ie. glibc)
#
# for rhel >= 10, use bundled jemalloc
# for rhel < 10, use system allocator
%bcond system_allocator %[0%{?rhel} && 0%{?rhel} < 10]
%bcond bundled_jemalloc %[0%{?rhel} >= 10]
%define jemalloc_version 5.3.0
%define jemalloc_prefix varnish_
%if 0%{?rhel}
%bcond_without system_allocator
%else
%bcond_with system_allocator
%endif
%if %{with system_allocator}
# use _lto_cflags if present
@ -31,26 +36,16 @@
Summary: High-performance HTTP accelerator
Name: varnish
Version: 9.0.3
Version: 7.4.2
Release: 3%{?dist}
License: BSD-2-Clause AND (BSD-2-Clause-FreeBSD AND BSD-3-Clause AND LicenseRef-Fedora-Public-Domain AND Zlib)
URL: https://www.varnish-cache.org/
Source0: https://github.com/varnish/varnish/releases/download/%{name}-%{version}/%{name}-%{version}.tar.gz
Source0: http://varnish-cache.org/_downloads/%{name}-%{version}.tgz
Source1: https://github.com/varnishcache/pkg-varnish-cache/archive/%{commit1}.tar.gz#/pkg-varnish-cache-%{shortcommit1}.tar.gz
Source2: varnish.sysusers
Source3: https://github.com/jemalloc/jemalloc/releases/download/%{jemalloc_version}/jemalloc-%{jemalloc_version}.tar.bz2
Source4: varnish.tmpfiles
# Compatibility with openssl-4.0.0
# https://github.com/varnish/varnish/issues/32
Patch1: varnish-9.0.1_openssl_4.0_asn1.patch
%if %{with bundled_jemalloc}
# bundled jemalloc patch
Patch100: jemalloc-5.3.0_fno-builtin.patch
Patch101: jemalloc-5.3.0-aarch64-ts-segfault.patch
%endif
Patch1: VSV00015.patch
Patch2: varnish-7.4.2-fix_h00004.vtc.patch
%if 0%{?fedora} > 29 || 0%{?rhel} > 7
Provides: varnish%{_isa} = %{version}-%{release}
Provides: varnishd(abi)%{_isa} = %{abi}
Provides: varnishd(vrt)%{_isa} = %{vrt}
@ -65,62 +60,52 @@ Provides: vmod(purge)%{_isa} = %{version}-%{release}
Provides: vmod(std)%{_isa} = %{version}-%{release}
Provides: vmod(unix)%{_isa} = %{version}-%{release}
Provides: vmod(vtc)%{_isa} = %{version}-%{release}
%if %{with bundled_jemalloc}
Provides: bundled(jemalloc)
%endif
BuildRequires: systemd-rpm-macros
%{?systemd_requires}
%{?sysusers_requires_compat}
BuildRequires: python3, python3-sphinx, python3-docutils
BuildRequires: gcc
%if %{without bundled_jemalloc}
%if %{with system_allocator}
# use glibc
%if 0%{?rhel} == 7
BuildRequires: python34 python34-sphinx python34-docutils
%else
%ifnarch aarch64
BuildRequires: jemalloc-devel
BuildRequires: python3, python3-sphinx, python3-docutils
%endif
%endif
%endif
BuildRequires: gcc
BuildRequires: libedit-devel
BuildRequires: make
BuildRequires: ncurses-devel
BuildRequires: pcre2-devel
BuildRequires: pkgconfig
BuildRequires: openssl-devel
%if %{with bundled_jemalloc}
BuildRequires: /usr/bin/xsltproc
BuildRequires: perl-generators
BuildRequires: systemd-units
%if %{with system_allocator}
# use glibc
%else
BuildRequires: jemalloc-devel
%endif
# Extra requirements for the build suite
# needs haproxy2
%if 0%{?fedora} > 30
%if 0%{?fedora} > 30 || 0%{?rhel} > 8
BuildRequires: haproxy
%endif
BuildRequires: nghttp2
# Varnish actually needs gcc installed to work. It uses the C compiler
# at runtime to compile the VCL configuration files. This is by design.
Requires: gcc
Requires: logrotate
Requires: ncurses
Requires: pcre2
Requires: redhat-rpm-config
Requires(pre): shadow-utils
Requires(post): /usr/bin/uuidgen
# Varnish actually needs gcc installed to work. It uses the C compiler
# at runtime to compile the VCL configuration files. This is by design.
Requires: gcc
Requires(post): systemd-units
Requires(post): systemd-sysv
Requires(preun): systemd-units
Requires(postun): systemd-units
%if %{with system_allocator}
# use glibc
%else
%if %{without bundled_jemalloc}
Requires: jemalloc
%endif
%endif
%description
This is Varnish Cache, a high-performance HTTP accelerator.
@ -154,63 +139,15 @@ Documentation files for %name
%prep
%setup -q
%if 0%{?fedora} > 44 || 0%{?rhel} > 10
%patch 1 -p1
%endif
%patch 2 -p0
tar xzf %SOURCE1
ln -s pkg-varnish-cache-%{commit1}/redhat redhat
ln -s pkg-varnish-cache-%{commit1}/debian debian
cp redhat/find-provides .
sed -i 's,rst2man-3.6,rst2man-3.4,g; s,rst2html-3.6,rst2html-3.4,g; s,phinx-build-3.6,phinx-build-3.4,g' configure
# jemalloc
%if %{with bundled_jemalloc}
tar xjf %SOURCE3
sed -i '/^LIBPREFIX/s/@libprefix@/@libprefix@%{jemalloc_prefix}/' jemalloc*/Makefile.in
pushd jemalloc*
%patch 100 -p1 -b .jemalloc
%patch 101 -p1 -b .ts-segfault
popd
# Override PAGESIZE, bz #1545539
%ifarch %ix86 %arm x86_64 s390x riscv64
%define lg_page --with-lg-page=12
%endif
%ifarch ppc64 ppc64le aarch64
%define lg_page --with-lg-page=16
%endif
# Disable thp on systems not supporting this for now
%ifarch %ix86 %arm aarch64 s390x
%define disable_thp --disable-thp
%endif
%endif
%build
%if %{with bundled_jemalloc}
# build bundled jemalloc first
pushd jemalloc*
echo "For debugging package builders"
echo "What is the pagesize?"
getconf PAGESIZE
echo "What mm features are available?"
ls /sys/kernel/mm
ls /sys/kernel/mm/transparent_hugepage || true
cat /sys/kernel/mm/transparent_hugepage/enabled || true
echo "What kernel version and config is this?"
uname -a
%configure %{?disable_thp} %{?lg_page} --enable-prof
make %{?_smp_mflags}
popd
%endif
# varnish
%if %{with system_allocator}
export CFLAGS="%{optflags}"
%else
@ -226,20 +163,10 @@ export CFLAGS="$CFLAGS -ffloat-store -fexcess-precision=standard"
%endif
%endif
%if 0%{?fedora} > 41 || 0%{?rhel} > 10
export CFLAGS="$CFLAGS -std=gnu17"
%endif
%if 0%{?fedora} > 42 || 0%{?rhel} > 10
export CFLAGS="$CFLAGS -Wno-error=discarded-qualifiers"
%endif
%ifarch s390x
export CFLAGS="$CFLAGS -Wno-error=free-nonheap-object"
%endif
# What platform is this
uname -a
# What gcc version is this?
gcc --version
@ -250,15 +177,7 @@ getconf PAGESIZE
# Man pages are prebuilt. No need to regenerate them.
export RST2MAN=/bin/true
# Explicit python, please
export PYTHON=python3
for f in configure configure.ac; do
sed -i 's|ljemalloc|l%{jemalloc_prefix}jemalloc|g' $f
done
%if %{with bundled_jemalloc}
export LDFLAGS="$LDFLAGS -L%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib"
%endif
export PYTHON=%{__python}
%configure LT_SYS_LIBRARY_PATH=%_libdir \
--disable-static \
@ -270,14 +189,10 @@ export LDFLAGS="$LDFLAGS -L%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_v
--enable-pcre2-jit=no \
%endif
%endif
%if %{with system_allocator} || %{without bundled_jemalloc}
%if %{with system_allocator}
--with-jemalloc=no \
%endif
%if %{with bundled_jemalloc}
export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib
%endif
%make_build
# One varnish user is enough
@ -287,55 +202,23 @@ sed -i 's,User=varnishlog,User=varnish,g;' redhat/varnishncsa.service
rm -rf doc/html/_sources
%check
# check jemalloc first
%if %{with bundled_jemalloc}
pushd jemalloc*
make %{?_smp_mflags} check
popd
# Remove these for now. Hard to get the size and timing right
%ifarch s390 s390x aarch64
rm bin/varnishtest/tests/o00005.vtc
%endif
%ifarch armv7hl
rm bin/varnishtest/tests/b00046.vtc
%endif
# Up the stack size in tests, necessary on secondary arches
sed -i 's/thread_pool_stack 80k/thread_pool_stack 128k/g;' bin/vinyltest/tests/*.vtc
sed -i 's/file,2M/file,8M/' bin/vinyltest/tests/r04036.vtc
%ifarch %ix86
sed -i 's/param.set workspace_thread 0.55k/param.set workspace_thread 0.5k/' bin/vinyltest/tests/b00081.vtc
%endif
# This is a bug in varnishtest making it incompatible with nghttp2 >= 1.65
#if 0#{?fedora} > 41 || 0#{?rhel} > 10
#rm bin/varnishtest/tests/a02022.vtc
#endif
%if %{with bundled_jemalloc}
export LD_LIBRARY_PATH=%{_builddir}/%{name}-%{version}/jemalloc-%{jemalloc_version}/lib
%endif
# This runs fine in the emulator, but not on Red Hat's builders
# Upstream is looking at it, upstream issue #36
%ifarch s390x
rm bin/vinyltest/tests/t02033.vtc
%endif
# Just a hack to avoid too high load on secondary arch builders
%ifarch s390x ppc64le %ix86
make check
%else
%make_build check
%endif
%install
rm -rf %{buildroot}
# jemalloc
%if %{with bundled_jemalloc}
pushd jemalloc*
make DESTDIR=%{buildroot} install_lib %{?_smp_mflags}
find %{buildroot}%{_libdir}/ -name '*.a' -exec rm -vf {} ';'
# we don't need .pc file
rm %{buildroot}%{_libdir}/pkgconfig/jemalloc.pc
popd
# mock el7 defaults to LANG=C, which makes python3 fail when parsing utf8 text
%if 0%{?rhel} == 7
export LANG=en_US.UTF-8
%endif
%{make_install}
@ -356,11 +239,6 @@ mkdir -p %{buildroot}%{_unitdir}
install -D -m 0644 redhat/varnish.service %{buildroot}%{_unitdir}/varnish.service
install -D -m 0644 redhat/varnishncsa.service %{buildroot}%{_unitdir}/varnishncsa.service
install -D -m 0755 redhat/varnishreload %{buildroot}%{_sbindir}/varnishreload
install -p -D -m 0644 %{SOURCE2} %{buildroot}%{_sysusersdir}/varnish.conf
# tmpfiles.d configuration
mkdir -p %{buildroot}%{_tmpfilesdir}
install -m 644 -p %{SOURCE4} %{buildroot}%{_tmpfilesdir}/varnish.conf
echo %{_libdir}/varnish > %{buildroot}%{_sysconfdir}/ld.so.conf.d/%{name}-%{_arch}.conf
@ -370,13 +248,8 @@ chmod 644 lib/libvmod_*/*.c
chmod 644 lib/libvmod_*/*.h
%endif
%pre
%sysusers_create_compat %{SOURCE2}
%files
%if "%{_sbindir}" != "%{_bindir}"
%{_sbindir}/*
%endif
%{_bindir}/*
%{_libdir}/*.so.*
%{_libdir}/%{name}
@ -386,21 +259,20 @@ chmod 644 lib/libvmod_*/*.h
%{_mandir}/man3/*.3*
%{_mandir}/man7/*.7*
%license LICENSE
%doc README.md ChangeLog
%doc README.rst ChangeLog
%doc etc/builtin.vcl etc/example.vcl
%dir %{_sysconfdir}/varnish/
%config(noreplace) %{_sysconfdir}/varnish/default.vcl
%config(noreplace) %{_sysconfdir}/logrotate.d/varnish
%config %{_sysconfdir}/ld.so.conf.d/%{name}-%{_arch}.conf
%{_unitdir}/varnish.service
%{_unitdir}/varnishncsa.service
%{_sysusersdir}/varnish.conf
%{_tmpfilesdir}/varnish.conf
%files devel
%license LICENSE
%doc README.md
%doc README.rst
%{_libdir}/lib*.so
%{_includedir}/%{name}
%{_libdir}/pkgconfig/varnishapi.pc
@ -412,6 +284,15 @@ chmod 644 lib/libvmod_*/*.h
%doc doc/html
%doc doc/changes*.html
%pre
getent group varnish >/dev/null || groupadd -r varnish
getent passwd varnish >/dev/null || \
useradd -r -g varnish -d /var/lib/varnish -s /sbin/nologin \
-c "Varnish Cache" varnish
exit 0
%post
%systemd_post varnish varnishncsa
/sbin/ldconfig
@ -427,84 +308,8 @@ test -f /etc/varnish/secret || (uuidgen > /etc/varnish/secret && chmod 0600 /etc
%changelog
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 9.0.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Sat Jun 13 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 9.0.3-2
- Rebuilt for openssl 4.0
* Thu May 21 2026 Ingvar Hagelund <ingvar@redpill-linpro.com> - 9.0.3-1
- New upstream release: A security relase
- Includes fix for VSV00019 aka CVE-2026-50052
* Fri May 15 2026 Ingvar Hagelund <ingvar@redpill-linpro.com> - 9.0.2-1
- New upstream release: A bugfix release
* Fri Apr 10 2026 Ingvar Hagelund <ingvar@redpill-linpro.com> - 9.0.1-1
- New upstream release
- Add patch for openssl-4.0.0 in rawhide
- Includes fix for VEV00002
* Fri Mar 27 2026 Ingvar Hagelund <ingvar@redpill-linpro.com> - 9.0.0-1
- New upstream release
- Includes fix for VSV00018
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 8.0.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Thu Dec 11 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 8.0.0-1
- New upstream release
- New pkg-varnish-cache checkout
- Added cflag -Wno-error=discarded-qualifiers to build on fedora while waiting for upstream
* Wed Oct 29 2025 Luboš Uhliarik <luhliari@redhat.com> - 7.7.3-2
- Add tmpfiles.d rules for /var directories (bootc compatibility)
* Mon Sep 15 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.7.3-1
- New upstream release: A security release
- Includes fix for VSV00017 aka CVE-2025-8671, rhbz#2388222
* Thu Jul 31 2025 Luboš Uhliarik <luhliari@redhat.com> - 7.7.1-4
- bundle jemalloc in RHEL
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 7.7.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Thu May 22 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.7.1-2
- Correct ABI and VRT versions
- Pulled el7 support
- Use systemd setup for users
* Tue May 20 2025 Luboš Uhliarik <luhliari@redhat.com> - 7.7.1-1
- new version 7.7.1
* Thu Mar 27 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.7.0-2
- Fix for eln build (merged from yselkowitz)
- Fix for failing h2 switch check. Enabling full test suite again
* Mon Mar 24 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.7.0-1
- New upstream release
- fedora now has completed the bin/sbin merge
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 7.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Mon Dec 02 2024 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.6.1-1
- New upstream release
* Mon Sep 16 2024 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.6.0-1
- New upstream release
- Updated checkout of pkg-varnish
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 7.5.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Tue Mar 19 2024 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.5.0-1
- New upstream release
- Moved somethings around to make the diff from the upstream spec less
- Upped some memory requirements in some of the tests. Necessary on aarch64 and ppc64le (and ppc32)
- Reduced number of parallel jobs on s390x builders as builds tend to fail when stressed
- Retired armv7hl
* Wed Mar 26 2025 Ingvar Hagelund <ingvar@redpill-linpro.com> - 7.4.2-3
- Security: Added patch for VSV00015 aka CVE-2025-30346, BZ#2354008
* Sat Jan 27 2024 Fedora Release Engineering <releng@fedoraproject.org> - 7.4.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

View file

@ -1,3 +0,0 @@
#Type Name ID GECOS Home directory Shell
g varnish -
u varnish - "Varnish Cache" /var/lib/varnish /sbin/nologin

View file

@ -1,2 +0,0 @@
d /var/lib/varnish 755 root root -
d /var/log/varnish 700 varnish varnish -