Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package libtcnative-1-0 for openSUSE:Factory
checked in at 2026-09-28 10:42:35
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libtcnative-1-0 (Old)
and /work/SRC/openSUSE:Factory/.libtcnative-1-0.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libtcnative-1-0"
Mon Sep 28 10:42:35 2026 rev:46 rq:1380680 version:1.3.9
Changes:
--------
--- /work/SRC/openSUSE:Factory/libtcnative-1-0/libtcnative-1-0.changes
2026-06-16 18:30:24.736077806 +0200
+++
/work/SRC/openSUSE:Factory/.libtcnative-1-0.new.383539/libtcnative-1-0.changes
2026-09-28 10:42:43.586587028 +0200
@@ -1,0 +2,66 @@
+Fri Sep 25 05:08:32 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Update to 1.3.9
+ * Security fixes
+ + Client certificate requirements can be down-graded
+ (bsc#1282621, CVE-2026-86247)
+ A race condition allowed client certificate verification
+ requirements to be down-graded for some configurations.
+ + Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
+ Apache Tomcat Native enabled insecure options by default
+ including ALLOW_CLIENT_RENEGOTIATION,
+ NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
+ ALLOW_NO_DHE_KEX.
+ + DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
+ A buffer over-read vulnerability in Apache Tomcat Native
+ during the TLS handshaking permits a malicious user to trigger
+ a DoS via a JVM crash.
+ * Changes
+ + Code: Remove call to ERR_remove_thread_state() from Windows
+ specific code to allow building with OpenSSL 4.0.x.
+ ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
+ removed in OpenSSL 4
+ + Fix: Fix a potential crash when negotiating ALPN
+ + If ALPN negotiation fails and failure is configured to use
+ the last server protocol in the list, use it rather than the
+ last protocol offered by the client
+ + Fix: Add support for the extended range of options available
+ from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
+ int (represented by a Java long) rather than a 32-bit unsigned
+ int (represented by a Java int)
+ + Code: Remove unused code
+ + Ensure that per connection changes to certificate verification
+ settings, e.g. to support client certificate authentication,
+ do not modify the certificate verification settings for other
+ connections
+ + Fix: Fix a potential crash when configuring raw certificates
+ + Fix: Avoid a potential crash with very long ALPN protocol
+ names
+ + Fix: Make the call to a CertificateVerifier more robust
+ + Fix: Avoid a potential crash when processing OCSP URLs
+ + Fix: Make the processing of OCSP responses more robust
+ + Fix: Stricter OCSP handling when soft-fail is disabled
+ + Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+ + Fix: Harden against the mis-use of Pool.destroy(long)
+ + Code: The minimum supported OpenSSL version is now 3.0.x.
+ OpenSSL 1.1.1 support was accidentally broken in 1.3.8. As no
+ bug reports were receive for that failure and since both
+ Debian and Ubuntu versions that used OpenSSL 1.1.1 have
+ reached end of support, OpenSSL 1.1.1 is no longer supported
+ + Update: OpenSSL 3.0.x is approaching end of support so the
+ recommended version of OpenSSL (and the version that windows
+ binaries will be built with) now follows the 3.5.x LTS branch
+ + Fix: Switch to automatic configuration of DH parameters.
+ Manual configuration attempts will be ignored
+ + Code: Make setTmpECDHByCurveName() a NO-OP
+ + Fix: Refactor extraction of ECDH curve name from the
+ Certificate to avoid deprecated OpenSSL methods
+ + Fix: Refactor the native implementation of SSL.getTime() to
+ avoid the Y2038 problem in SSL_SESSION_get_time() when running
+ on a verion of OpenSSL that includes the new
+ SSL_SESSION_get_time_ex() method
+- Added patch:
+ * 0001-Bring-back-OpenSSL-1.1.1-support.patch
+ + restore openssl 1.1.1 support
+
+-------------------------------------------------------------------
@@ -26 +91,0 @@
-
Old:
----
tomcat-native-1.3.8-src.tar.gz
tomcat-native-1.3.8-src.tar.gz.asc
New:
----
0001-Bring-back-OpenSSL-1.1.1-support.patch
tomcat-native-1.3.9-src.tar.gz
tomcat-native-1.3.9-src.tar.gz.asc
----------(New B)----------
New:- Added patch:
* 0001-Bring-back-OpenSSL-1.1.1-support.patch
+ restore openssl 1.1.1 support
----------(New E)----------
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ libtcnative-1-0.spec ++++++
--- /var/tmp/diff_new_pack.H81pab/_old 2026-09-28 10:42:44.587628949 +0200
+++ /var/tmp/diff_new_pack.H81pab/_new 2026-09-28 10:42:44.588628991 +0200
@@ -18,7 +18,7 @@
%{!?make_build:%global make_build make %{?_smp_mflags}}
Name: libtcnative-1-0
-Version: 1.3.8
+Version: 1.3.9
Release: 0
Summary: Tomcat resources for performance, compatibility, etc
License: Apache-2.0
@@ -26,8 +26,9 @@
URL: https://tomcat.apache.org/native-1.2-doc/index.html
Source0:
https://www.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz
Source1:
https://www.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz.asc
-# https://www.apache.org/dist/tomcat/tomcat-connectors/KEYS
+# https://downloads.apache.org/tomcat/tomcat-connectors/KEYS
Source2: %{name}.keyring
+Patch0: 0001-Bring-back-OpenSSL-1.1.1-support.patch
BuildRequires: fdupes
BuildRequires: java-devel
BuildRequires: javapackages-tools
@@ -93,6 +94,7 @@
%prep
%setup -q -n tomcat-native-%{version}-src
+%patch -P 0 -p1
%build
cd native
++++++ 0001-Bring-back-OpenSSL-1.1.1-support.patch ++++++
>From c5f8684b6a556116ddfed4219f59cf41f166f68e Mon Sep 17 00:00:00 2001
From: Fridrich Strba <[email protected]>
Date: Fri, 25 Sep 2026 08:39:56 +0200
Subject: [PATCH] Bring back OpenSSL 1.1.1 support
---
native/include/ssl_private.h | 10 +++++++-
native/src/sslcontext.c | 40 ++++++++++++++++++++++++++++---
native/src/sslutils.c | 28 ++++++++++++++++++++++
native/srclib/VERSIONS | 5 +++-
4 files changed, 78 insertions(+), 5 deletions(-)
diff --git a/native/include/ssl_private.h b/native/include/ssl_private.h
index f56916754..93181fa50 100644
--- a/native/include/ssl_private.h
+++ b/native/include/ssl_private.h
@@ -48,8 +48,8 @@
#include <openssl/bn.h>
#if OPENSSL_VERSION_NUMBER > 0x2FFFFFFFL && !defined(LIBRESSL_VERSION_NUMBER)
#include <openssl/provider.h>
-#endif
#include <openssl/core_names.h>
+#endif
#ifndef RAND_MAX
#include <limits.h>
@@ -345,10 +345,18 @@ int SSL_password_callback(char *, int, int, void
*);
void SSL_BIO_close(BIO *);
void SSL_BIO_doref(BIO *);
DH *SSL_get_dh_params(unsigned keylen);
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+DH *SSL_dh_GetParamFromFile(const char *);
+#else
EVP_PKEY *SSL_dh_GetParamFromFile(const char *);
+#endif
#ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+EC_GROUP *SSL_ec_GetParamFromFile(const char *);
+#else
int SSL_ec_GetParamFromFile(const char *);
#endif
+#endif
DH *SSL_callback_tmp_DH(SSL *, int, int);
void SSL_callback_handshake(const SSL *, int, int);
int SSL_CTX_use_certificate_chain(SSL_CTX *, const char *, int);
diff --git a/native/src/sslcontext.c b/native/src/sslcontext.c
index 5f0f608da..5b51bf6b2 100644
--- a/native/src/sslcontext.c
+++ b/native/src/sslcontext.c
@@ -985,9 +985,19 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext,
setCertificate)(TCN_STDARGS, jlong ctx,
const char *p;
char err[TCN_OPENSSL_ERROR_STRING_LENGTH];
#ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+ EC_GROUP *ecparams = NULL;
int nid;
+ EC_KEY *eckey = NULL;
+#else
+ int nid;
+#endif
#endif
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+ DH *dhparams;
+#else
EVP_PKEY *evp;
+#endif
UNREFERENCED(o);
TCN_ASSERT(ctx != 0);
@@ -1062,10 +1072,17 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext,
setCertificate)(TCN_STDARGS, jlong ctx,
*/
/* XXX Does this also work for pkcs12 or only for PEM files?
* If only for PEM files move above to the PEM handling */
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+ if ((idx == 0) && (dhparams = SSL_dh_GetParamFromFile(cert_file))) {
+ SSL_CTX_set_tmp_dh(c->ctx, dhparams);
+ DH_free(dhparams);
+ }
+#else
if ((idx == 0) && (evp = SSL_dh_GetParamFromFile(cert_file))) {
SSL_CTX_set0_tmp_dh_pkey(c->ctx, evp);
EVP_PKEY_free(evp);
}
+#endif
#ifdef HAVE_ECC
/*
@@ -1073,10 +1090,21 @@ TCN_IMPLEMENT_CALL(jboolean, SSLContext,
setCertificate)(TCN_STDARGS, jlong ctx,
*/
/* XXX Does this also work for pkcs12 or only for PEM files?
* If only for PEM files move above to the PEM handling */
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+ if ((ecparams = SSL_ec_GetParamFromFile(cert_file)) &&
+ (nid = EC_GROUP_get_curve_name(ecparams)) &&
+ (eckey = EC_KEY_new_by_curve_name(nid))) {
+ SSL_CTX_set_tmp_ecdh(c->ctx, eckey);
+ }
+ /* OpenSSL assures us that _free() is NULL-safe */
+ EC_KEY_free(eckey);
+ EC_GROUP_free(ecparams);
+#else
nid = SSL_ec_GetParamFromFile(cert_file);
if (nid != NID_undef) {
SSL_CTX_set1_groups(c->ctx, &nid, 1);
}
+#endif
#endif
SSL_CTX_set_dh_auto(c->ctx, 1);
@@ -1667,13 +1695,19 @@ TCN_IMPLEMENT_CALL(jlong, SSLContext,
sessionCacheFull)(TCN_STDARGS, jlong ctx)
return rv;
}
-#define TICKET_KEYS_SIZE 80
+#define TICKET_KEYS_SIZE_1_1 48
+#define TICKET_KEYS_SIZE_3_0 80
TCN_IMPLEMENT_CALL(void, SSLContext, setSessionTicketKeys)(TCN_STDARGS, jlong
ctx, jbyteArray keys)
{
tcn_ssl_ctxt_t *c = J2P(ctx, tcn_ssl_ctxt_t *);
jbyte* b;
+ int len = (*e)->GetArrayLength(e, keys);
- if ((*e)->GetArrayLength(e, keys) != TICKET_KEYS_SIZE) {
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+ if (len != TICKET_KEYS_SIZE_1_1) {
+#else
+ if (len != TICKET_KEYS_SIZE_1_1 && len != TICKET_KEYS_SIZE_3_0) {
+#endif
if (c->bio_os) {
BIO_printf(c->bio_os, "[ERROR] Session ticket keys provided were
wrong size.\n");
}
@@ -1684,7 +1718,7 @@ TCN_IMPLEMENT_CALL(void, SSLContext,
setSessionTicketKeys)(TCN_STDARGS, jlong ct
}
b = (*e)->GetByteArrayElements(e, keys, NULL);
- SSL_CTX_set_tlsext_ticket_keys(c->ctx, b, TICKET_KEYS_SIZE);
+ SSL_CTX_set_tlsext_ticket_keys(c->ctx, b, len);
(*e)->ReleaseByteArrayElements(e, keys, b, 0);
}
diff --git a/native/src/sslutils.c b/native/src/sslutils.c
index 638584a8b..8e98568ec 100644
--- a/native/src/sslutils.c
+++ b/native/src/sslutils.c
@@ -202,6 +202,19 @@ int SSL_password_callback(char *buf, int bufsiz, int
verify,
** Custom (EC)DH parameter support
** _________________________________________________________________
*/
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+DH *SSL_dh_GetParamFromFile(const char *file)
+{
+ DH *dh = NULL;
+ BIO *bio;
+
+ if ((bio = BIO_new_file(file, "r")) == NULL)
+ return NULL;
+ dh = PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
+ BIO_free(bio);
+ return dh;
+}
+#else
EVP_PKEY *SSL_dh_GetParamFromFile(const char *file)
{
EVP_PKEY *evp = NULL;
@@ -217,8 +230,22 @@ EVP_PKEY *SSL_dh_GetParamFromFile(const char *file)
}
return evp;
}
+#endif
#ifdef HAVE_ECC
+#if (OPENSSL_VERSION_NUMBER < 0x30000000L)
+EC_GROUP *SSL_ec_GetParamFromFile(const char *file)
+{
+ EC_GROUP *group = NULL;
+ BIO *bio;
+
+ if ((bio = BIO_new_file(file, "r")) == NULL)
+ return NULL;
+ group = PEM_read_bio_ECPKParameters(bio, NULL, NULL, NULL);
+ BIO_free(bio);
+ return (group);
+}
+#else
int SSL_ec_GetParamFromFile(const char *file)
{
EVP_PKEY *evp = NULL;
@@ -256,6 +283,7 @@ int SSL_ec_GetParamFromFile(const char *file)
return nid; /* Returns the curve's NID, or NID_undef on failure */
}
#endif
+#endif
/*
* Read a file that optionally contains the server certificate in PEM
diff --git a/native/srclib/VERSIONS b/native/srclib/VERSIONS
index e5e1896fd..d4de288c2 100644
--- a/native/srclib/VERSIONS
+++ b/native/srclib/VERSIONS
@@ -1,5 +1,5 @@
The current minimum versions are:
-- OpenSSL 3.0.0
+- OpenSSL 1.1.1
- APR 1.6.3
The following version of the libraries are recommended:
@@ -23,6 +23,9 @@ And in Ubuntu:
- OpenSSL 3.0.13 in Ubuntu 24.04 LTS (EOL in April 2029)
- OpenSSL 3.5.5 in Ubuntu 26.04 LTS (EOL in April 2031)
+And in SUSE:
+- OpenSSL 1.1.1 in SUSE Linux Enterprise 15 (LTSS through 2031)
+
The minimum version of APR is driven by the version of APR used by
downstream distributions.
--
2.55.0
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.H81pab/_old 2026-09-28 10:42:44.631630791 +0200
+++ /var/tmp/diff_new_pack.H81pab/_new 2026-09-28 10:42:44.636631001 +0200
@@ -1,6 +1,6 @@
-mtime: 1781588023
-commit: b2a09b5da6fe5e7c5df4a3a8be9b01dce96c4af0d40f8086d75ca4b9cfce4103
+mtime: 1790319634
+commit: 52c7a530c9636393e568451177e0bda574f83614674200a1020ed56d28077baa
url: https://src.opensuse.org/java-packages/libtcnative-1-0
-revision: b2a09b5da6fe5e7c5df4a3a8be9b01dce96c4af0d40f8086d75ca4b9cfce4103
+revision: 52c7a530c9636393e568451177e0bda574f83614674200a1020ed56d28077baa
projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-09-25 09:00:34.000000000 +0200
@@ -0,0 +1 @@
+.osc
++++++ tomcat-native-1.3.8-src.tar.gz -> tomcat-native-1.3.9-src.tar.gz ++++++
++++ 3160 lines of diff (skipped)