Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libtcnative-1-0 for openSUSE:Factory 
checked in at 2026-09-28 10:42:35
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libtcnative-1-0 (Old)
 and      /work/SRC/openSUSE:Factory/.libtcnative-1-0.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libtcnative-1-0"

Mon Sep 28 10:42:35 2026 rev:46 rq:1380680 version:1.3.9

Changes:
--------
--- /work/SRC/openSUSE:Factory/libtcnative-1-0/libtcnative-1-0.changes  
2026-06-16 18:30:24.736077806 +0200
+++ 
/work/SRC/openSUSE:Factory/.libtcnative-1-0.new.383539/libtcnative-1-0.changes  
    2026-09-28 10:42:43.586587028 +0200
@@ -1,0 +2,66 @@
+Fri Sep 25 05:08:32 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 1.3.9
+  * Security fixes
+    + Client certificate requirements can be down-graded
+      (bsc#1282621, CVE-2026-86247)
+      A race condition allowed client certificate verification
+      requirements to be down-graded for some configurations.
+    + Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
+      Apache Tomcat Native enabled insecure options by default
+      including ALLOW_CLIENT_RENEGOTIATION,
+      NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
+      ALLOW_NO_DHE_KEX.
+    + DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
+      A buffer over-read vulnerability in Apache Tomcat Native
+      during the TLS handshaking permits a malicious user to trigger
+      a DoS via a JVM crash.
+  * Changes
+    + Code: Remove call to ERR_remove_thread_state() from Windows
+      specific code to allow building with OpenSSL 4.0.x.
+      ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
+      removed in OpenSSL 4
+    + Fix: Fix a potential crash when negotiating ALPN
+    + If ALPN negotiation fails and failure is configured to use
+      the last server protocol in the list, use it rather than the
+      last protocol offered by the client
+    + Fix: Add support for the extended range of options available
+      from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
+      int (represented by a Java long) rather than a 32-bit unsigned
+      int (represented by a Java int)
+    + Code: Remove unused code
+    + Ensure that per connection changes to certificate verification
+      settings, e.g. to support client certificate authentication,
+      do not modify the certificate verification settings for other
+      connections
+    + Fix: Fix a potential crash when configuring raw certificates
+    + Fix: Avoid a potential crash with very long ALPN protocol
+      names
+    + Fix: Make the call to a CertificateVerifier more robust
+    + Fix: Avoid a potential crash when processing OCSP URLs
+    + Fix: Make the processing of OCSP responses more robust
+    + Fix: Stricter OCSP handling when soft-fail is disabled
+    + Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+    + Fix: Harden against the mis-use of Pool.destroy(long)
+    + Code: The minimum supported OpenSSL version is now 3.0.x.
+      OpenSSL 1.1.1 support was accidentally broken in 1.3.8. As no
+      bug reports were receive for that failure and since both
+      Debian and Ubuntu versions that used OpenSSL 1.1.1 have
+      reached end of support, OpenSSL 1.1.1 is no longer supported
+    + Update: OpenSSL 3.0.x is approaching end of support so the
+      recommended version of OpenSSL (and the version that windows
+      binaries will be built with) now follows the 3.5.x LTS branch
+    + Fix: Switch to automatic configuration of DH parameters.
+      Manual configuration attempts will be ignored
+    + Code: Make setTmpECDHByCurveName() a NO-OP
+    + Fix: Refactor extraction of ECDH curve name from the
+      Certificate to avoid deprecated OpenSSL methods
+    + Fix: Refactor the native implementation of SSL.getTime() to
+      avoid the Y2038 problem in SSL_SESSION_get_time() when running
+      on a verion of OpenSSL that includes the new
+      SSL_SESSION_get_time_ex() method
+- Added patch:
+  * 0001-Bring-back-OpenSSL-1.1.1-support.patch
+    + restore openssl 1.1.1 support
+
+-------------------------------------------------------------------
@@ -26 +91,0 @@
-      

Old:
----
  tomcat-native-1.3.8-src.tar.gz
  tomcat-native-1.3.8-src.tar.gz.asc

New:
----
  0001-Bring-back-OpenSSL-1.1.1-support.patch
  tomcat-native-1.3.9-src.tar.gz
  tomcat-native-1.3.9-src.tar.gz.asc

----------(New B)----------
  New:- Added patch:
  * 0001-Bring-back-OpenSSL-1.1.1-support.patch
    + restore openssl 1.1.1 support
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libtcnative-1-0.spec ++++++
--- /var/tmp/diff_new_pack.H81pab/_old  2026-09-28 10:42:44.587628949 +0200
+++ /var/tmp/diff_new_pack.H81pab/_new  2026-09-28 10:42:44.588628991 +0200
@@ -18,7 +18,7 @@
 
 %{!?make_build:%global make_build make %{?_smp_mflags}}
 Name:           libtcnative-1-0
-Version:        1.3.8
+Version:        1.3.9
 Release:        0
 Summary:        Tomcat resources for performance, compatibility, etc
 License:        Apache-2.0
@@ -26,8 +26,9 @@
 URL:            https://tomcat.apache.org/native-1.2-doc/index.html
 Source0:        
https://www.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz
 Source1:        
https://www.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz.asc
-# https://www.apache.org/dist/tomcat/tomcat-connectors/KEYS
+# https://downloads.apache.org/tomcat/tomcat-connectors/KEYS
 Source2:        %{name}.keyring
+Patch0:         0001-Bring-back-OpenSSL-1.1.1-support.patch
 BuildRequires:  fdupes
 BuildRequires:  java-devel
 BuildRequires:  javapackages-tools
@@ -93,6 +94,7 @@
 
 %prep
 %setup -q -n tomcat-native-%{version}-src
+%patch -P 0 -p1
 
 %build
 cd native

++++++ 0001-Bring-back-OpenSSL-1.1.1-support.patch ++++++
>From c5f8684b6a556116ddfed4219f59cf41f166f68e Mon Sep 17 00:00:00 2001
From: Fridrich Strba <[email protected]>
Date: Fri, 25 Sep 2026 08:39:56 +0200
Subject: [PATCH] Bring back OpenSSL 1.1.1 support

---
 native/include/ssl_private.h      | 10 +++++++-
 native/src/sslcontext.c           | 40 ++++++++++++++++++++++++++++---
 native/src/sslutils.c             | 28 ++++++++++++++++++++++
 native/srclib/VERSIONS            |  5 +++-
 4 files changed, 78 insertions(+), 5 deletions(-)

diff --git a/native/include/ssl_private.h b/native/include/ssl_private.h
index f56916754..93181fa50 100644
--- a/native/include/ssl_private.h
+++ b/native/include/ssl_private.h
@@ -48,8 +48,8 @@
 #include <openssl/bn.h>
 #if OPENSSL_VERSION_NUMBER > 0x2FFFFFFFL && !defined(LIBRESSL_VERSION_NUMBER)
 #include <openssl/provider.h>
-#endif
 #include <openssl/core_names.h>
+#endif
 
 #ifndef RAND_MAX
 #include <limits.h>
@@ -345,10 +345,18 @@ int         SSL_password_callback(char *, int, int, void 
*);
 void        SSL_BIO_close(BIO *);
 void        SSL_BIO_doref(BIO *);
 DH         *SSL_get_dh_params(unsigned keylen);
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+DH         *SSL_dh_GetParamFromFile(const char *);
+#else
 EVP_PKEY   *SSL_dh_GetParamFromFile(const char *);
+#endif
 #ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+EC_GROUP   *SSL_ec_GetParamFromFile(const char *);
+#else
 int         SSL_ec_GetParamFromFile(const char *);
 #endif
+#endif
 DH         *SSL_callback_tmp_DH(SSL *, int, int);
 void        SSL_callback_handshake(const SSL *, int, int);
 int         SSL_CTX_use_certificate_chain(SSL_CTX *, const char *, int);
diff --git a/native/src/sslcontext.c b/native/src/sslcontext.c
index 5f0f608da..5b51bf6b2 100644
--- a/native/src/sslcontext.c
+++ b/native/src/sslcontext.c
@@ -985,9 +985,19 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext, 
setCertificate)(TCN_STDARGS, jlong ctx,
     const char *p;
     char err[TCN_OPENSSL_ERROR_STRING_LENGTH];
 #ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+    EC_GROUP *ecparams = NULL;
     int nid;
+    EC_KEY *eckey = NULL;
+#else
+    int nid;
+#endif
 #endif
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+    DH *dhparams;
+#else
     EVP_PKEY *evp;
+#endif
 
     UNREFERENCED(o);
     TCN_ASSERT(ctx != 0);
@@ -1062,10 +1072,17 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext, 
setCertificate)(TCN_STDARGS, jlong ctx,
      */
     /* XXX Does this also work for pkcs12 or only for PEM files?
      * If only for PEM files move above to the PEM handling */
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+    if ((idx == 0) && (dhparams = SSL_dh_GetParamFromFile(cert_file))) {
+        SSL_CTX_set_tmp_dh(c->ctx, dhparams);
+        DH_free(dhparams);
+    }
+#else
     if ((idx == 0) && (evp = SSL_dh_GetParamFromFile(cert_file))) {
         SSL_CTX_set0_tmp_dh_pkey(c->ctx, evp);
         EVP_PKEY_free(evp);
     }
+#endif
 
 #ifdef HAVE_ECC
     /*
@@ -1073,10 +1090,21 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext, 
setCertificate)(TCN_STDARGS, jlong ctx,
      */
     /* XXX Does this also work for pkcs12 or only for PEM files?
      * If only for PEM files move above to the PEM handling */
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+    if ((ecparams = SSL_ec_GetParamFromFile(cert_file)) &&
+        (nid = EC_GROUP_get_curve_name(ecparams)) &&
+        (eckey = EC_KEY_new_by_curve_name(nid))) {
+        SSL_CTX_set_tmp_ecdh(c->ctx, eckey);
+    }
+    /* OpenSSL assures us that _free() is NULL-safe */
+    EC_KEY_free(eckey);
+    EC_GROUP_free(ecparams);
+#else
     nid = SSL_ec_GetParamFromFile(cert_file);
     if (nid != NID_undef) {
         SSL_CTX_set1_groups(c->ctx, &nid, 1);
     }
+#endif
 #endif
     SSL_CTX_set_dh_auto(c->ctx, 1);
 
@@ -1667,13 +1695,19 @@ TCN_IMPLEMENT_CALL(jlong, SSLContext, 
sessionCacheFull)(TCN_STDARGS, jlong ctx)
     return rv;
 }
 
-#define TICKET_KEYS_SIZE 80
+#define TICKET_KEYS_SIZE_1_1 48
+#define TICKET_KEYS_SIZE_3_0 80
 TCN_IMPLEMENT_CALL(void, SSLContext, setSessionTicketKeys)(TCN_STDARGS, jlong 
ctx, jbyteArray keys)
 {
     tcn_ssl_ctxt_t *c = J2P(ctx, tcn_ssl_ctxt_t *);
     jbyte* b;
+    int len = (*e)->GetArrayLength(e, keys);
 
-    if ((*e)->GetArrayLength(e, keys) != TICKET_KEYS_SIZE) {
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+    if (len != TICKET_KEYS_SIZE_1_1) {
+#else
+    if (len != TICKET_KEYS_SIZE_1_1 && len != TICKET_KEYS_SIZE_3_0) {
+#endif
         if (c->bio_os) {
             BIO_printf(c->bio_os, "[ERROR] Session ticket keys provided were 
wrong size.\n");
         }
@@ -1684,7 +1718,7 @@ TCN_IMPLEMENT_CALL(void, SSLContext, 
setSessionTicketKeys)(TCN_STDARGS, jlong ct
     }
 
     b = (*e)->GetByteArrayElements(e, keys, NULL);
-    SSL_CTX_set_tlsext_ticket_keys(c->ctx, b, TICKET_KEYS_SIZE);
+    SSL_CTX_set_tlsext_ticket_keys(c->ctx, b, len);
     (*e)->ReleaseByteArrayElements(e, keys, b, 0);
 }
 
diff --git a/native/src/sslutils.c b/native/src/sslutils.c
index 638584a8b..8e98568ec 100644
--- a/native/src/sslutils.c
+++ b/native/src/sslutils.c
@@ -202,6 +202,19 @@ int SSL_password_callback(char *buf, int bufsiz, int 
verify,
 **  Custom (EC)DH parameter support
 **  _________________________________________________________________
 */
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+DH *SSL_dh_GetParamFromFile(const char *file)
+{
+    DH *dh = NULL;
+    BIO *bio;
+
+    if ((bio = BIO_new_file(file, "r")) == NULL)
+        return NULL;
+    dh = PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
+    BIO_free(bio);
+    return dh;
+}
+#else
 EVP_PKEY *SSL_dh_GetParamFromFile(const char *file)
 {
     EVP_PKEY *evp = NULL;
@@ -217,8 +230,22 @@ EVP_PKEY *SSL_dh_GetParamFromFile(const char *file)
     }
     return evp;
 }
+#endif
 
 #ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+EC_GROUP *SSL_ec_GetParamFromFile(const char *file)
+{
+    EC_GROUP *group = NULL;
+    BIO *bio;
+
+    if ((bio = BIO_new_file(file, "r")) == NULL)
+        return NULL;
+    group = PEM_read_bio_ECPKParameters(bio, NULL, NULL, NULL);
+    BIO_free(bio);
+    return (group);
+}
+#else
 int SSL_ec_GetParamFromFile(const char *file)
 {
     EVP_PKEY *evp = NULL;
@@ -256,6 +283,7 @@ int SSL_ec_GetParamFromFile(const char *file)
     return nid; /* Returns the curve's NID, or NID_undef on failure */
 }
 #endif
+#endif
 
 /*
  * Read a file that optionally contains the server certificate in PEM
diff --git a/native/srclib/VERSIONS b/native/srclib/VERSIONS
index e5e1896fd..d4de288c2 100644
--- a/native/srclib/VERSIONS
+++ b/native/srclib/VERSIONS
@@ -1,5 +1,5 @@
 The current minimum versions are:
-- OpenSSL 3.0.0 
+- OpenSSL 1.1.1
 - APR 1.6.3
 
 The following version of the libraries are recommended:
@@ -23,6 +23,9 @@ And in Ubuntu:
 - OpenSSL 3.0.13 in Ubuntu 24.04 LTS (EOL in April 2029)
 - OpenSSL 3.5.5  in Ubuntu 26.04 LTS (EOL in April 2031)
 
+And in SUSE:
+- OpenSSL 1.1.1  in SUSE Linux Enterprise 15 (LTSS through 2031)
+
 The minimum version of APR is driven by the version of APR used by
 downstream distributions.
 
-- 
2.55.0


++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.H81pab/_old  2026-09-28 10:42:44.631630791 +0200
+++ /var/tmp/diff_new_pack.H81pab/_new  2026-09-28 10:42:44.636631001 +0200
@@ -1,6 +1,6 @@
-mtime: 1781588023
-commit: b2a09b5da6fe5e7c5df4a3a8be9b01dce96c4af0d40f8086d75ca4b9cfce4103
+mtime: 1790319634
+commit: 52c7a530c9636393e568451177e0bda574f83614674200a1020ed56d28077baa
 url: https://src.opensuse.org/java-packages/libtcnative-1-0
-revision: b2a09b5da6fe5e7c5df4a3a8be9b01dce96c4af0d40f8086d75ca4b9cfce4103
+revision: 52c7a530c9636393e568451177e0bda574f83614674200a1020ed56d28077baa
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-25 09:00:34.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ tomcat-native-1.3.8-src.tar.gz -> tomcat-native-1.3.9-src.tar.gz ++++++
++++ 3160 lines of diff (skipped)

Reply via email to