Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package libtcnative-2-0 for openSUSE:Factory
checked in at 2026-09-28 10:43:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libtcnative-2-0 (Old)
and /work/SRC/openSUSE:Factory/.libtcnative-2-0.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libtcnative-2-0"
Mon Sep 28 10:43:23 2026 rev:4 rq:1380682 version:2.0.16
Changes:
--------
--- /work/SRC/openSUSE:Factory/libtcnative-2-0/libtcnative-2-0.changes
2026-06-16 18:30:29.728287075 +0200
+++
/work/SRC/openSUSE:Factory/.libtcnative-2-0.new.383539/libtcnative-2-0.changes
2026-09-28 10:43:25.072324324 +0200
@@ -1,0 +2,51 @@
+Fri Sep 25 05:28:40 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to version 2.0.16
+ * Security fixes
+ + Client certificate requirements can be down-graded
+ (bsc#1282621, CVE-2026-86247)
+ A race condition allowed client certificate verification
+ requirements to be down-graded for some configurations.
+ + Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
+ Apache Tomcat Native enabled insecure options by default
+ including ALLOW_CLIENT_RENEGOTIATION,
+ NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
+ ALLOW_NO_DHE_KEX.
+ + DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
+ A buffer over-read vulnerability in Apache Tomcat Native
+ during the TLS handshaking permits a malicious user to trigger
+ a DoS via a JVM crash.
+ * Changes
+ + Code: Remove call to ERR_remove_thread_state() from Windows
+ specific code to allow building with OpenSSL 4.0.x
+ ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
+ removed in OpenSSL 4
+ + Update: Remove support for Windows build on IA64 architecture
+ (Itanium)
+ + Update: Make x64 the default architecture for Windows build
+ + Update: Make Windows 10 / 11 the default target version for
+ Windows builds
+ + Fix: Fix a potential crash when negotiating ALPN
+ + Fix: If ALPN negotiation fails and failure is configured to
+ use the last server protocol in the list, use it rather than
+ the last protocol offered by the client
+ + Fix: Add support for the extended range of options available
+ from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
+ int (represented by a Java long) rather than a 32-bit unsigned
+ int (represented by a Java int)
+ + Code: Remove unused code
+ + Fix: Ensure that per connection changes to certificate
+ verification settings, e.g. to support client certificate
+ authentication, do not modify the certificate verification
+ settings for other connections
+ + Fix: Fix a potential crash when configuring raw certificates
+ + Fix: Avoid a potential crash with very long ALPN protocol
+ names
+ + Fix: Make the call to a CertificateVerifier more robust
+ + Fix: Avoid a potential crash when processing OCSP URLs
+ + Fix: Make the processing of OCSP responses more robust
+ + Fix: Stricter OCSP handling when soft-fail is disabled
+ + Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+ + Fix: Harden against the mis-use of Pool.destroy(long)
+
+-------------------------------------------------------------------
Old:
----
tomcat-native-2.0.15-src.tar.gz
tomcat-native-2.0.15-src.tar.gz.asc
New:
----
tomcat-native-2.0.16-src.tar.gz
tomcat-native-2.0.16-src.tar.gz.asc
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ libtcnative-2-0.spec ++++++
--- /var/tmp/diff_new_pack.WEietk/_old 2026-09-28 10:43:26.432381279 +0200
+++ /var/tmp/diff_new_pack.WEietk/_new 2026-09-28 10:43:26.434381363 +0200
@@ -18,7 +18,7 @@
%{!?make_build:%global make_build make %{?_smp_mflags}}
Name: libtcnative-2-0
-Version: 2.0.15
+Version: 2.0.16
Release: 0
Summary: Tomcat resources for performance, compatibility, etc
License: Apache-2.0
@@ -26,7 +26,7 @@
URL: https://tomcat.apache.org/native-doc/index.html
Source0:
https://archive.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz
Source1:
https://archive.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz.asc
-# https://www.apache.org/dist/tomcat/tomcat-connectors/KEYS
+# https://downloads.apache.org/tomcat/tomcat-connectors/KEYS
Source2: %{name}.keyring
Patch0: apr163.patch
BuildRequires: fdupes
++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.WEietk/_old 2026-09-28 10:43:26.521385006 +0200
+++ /var/tmp/diff_new_pack.WEietk/_new 2026-09-28 10:43:26.525385174 +0200
@@ -1,6 +1,6 @@
-mtime: 1781587474
-commit: 1c36dbaf56f358f38dc738d280279f0215398405db2b45bc84177daff9f79c05
+mtime: 1790314819
+commit: fc0eb220e2d5e00e3562e54cea619df33e00a924c2a0e211563b2a330e679f78
url: https://src.opensuse.org/java-packages/libtcnative-2-0
-revision: 1c36dbaf56f358f38dc738d280279f0215398405db2b45bc84177daff9f79c05
+revision: fc0eb220e2d5e00e3562e54cea619df33e00a924c2a0e211563b2a330e679f78
projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
++++++ build.specials.obscpio ++++++
++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore 1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore 2026-09-25 07:40:19.000000000 +0200
@@ -0,0 +1 @@
+.osc
++++++ tomcat-native-2.0.15-src.tar.gz -> tomcat-native-2.0.16-src.tar.gz ++++++
++++ 3397 lines of diff (skipped)