Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libtcnative-2-0 for openSUSE:Factory 
checked in at 2026-09-28 10:43:23
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libtcnative-2-0 (Old)
 and      /work/SRC/openSUSE:Factory/.libtcnative-2-0.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libtcnative-2-0"

Mon Sep 28 10:43:23 2026 rev:4 rq:1380682 version:2.0.16

Changes:
--------
--- /work/SRC/openSUSE:Factory/libtcnative-2-0/libtcnative-2-0.changes  
2026-06-16 18:30:29.728287075 +0200
+++ 
/work/SRC/openSUSE:Factory/.libtcnative-2-0.new.383539/libtcnative-2-0.changes  
    2026-09-28 10:43:25.072324324 +0200
@@ -1,0 +2,51 @@
+Fri Sep 25 05:28:40 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to version 2.0.16
+  * Security fixes
+    + Client certificate requirements can be down-graded
+      (bsc#1282621, CVE-2026-86247)
+      A race condition allowed client certificate verification
+      requirements to be down-graded for some configurations.
+    + Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
+      Apache Tomcat Native enabled insecure options by default
+      including ALLOW_CLIENT_RENEGOTIATION,
+      NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
+      ALLOW_NO_DHE_KEX.
+    + DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
+      A buffer over-read vulnerability in Apache Tomcat Native
+      during the TLS handshaking permits a malicious user to trigger
+      a DoS via a JVM crash.
+  * Changes
+    + Code: Remove call to ERR_remove_thread_state() from Windows
+      specific code to allow building with OpenSSL 4.0.x
+      ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
+      removed in OpenSSL 4
+    + Update: Remove support for Windows build on IA64 architecture
+      (Itanium)
+    + Update: Make x64 the default architecture for Windows build
+    + Update: Make Windows 10 / 11 the default target version for
+      Windows builds
+    + Fix: Fix a potential crash when negotiating ALPN
+    + Fix: If ALPN negotiation fails and failure is configured to
+      use the last server protocol in the list, use it rather than
+      the last protocol offered by the client
+    + Fix: Add support for the extended range of options available
+      from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
+      int (represented by a Java long) rather than a 32-bit unsigned
+      int (represented by a Java int)
+    + Code: Remove unused code
+    + Fix: Ensure that per connection changes to certificate
+      verification settings, e.g. to support client certificate
+      authentication, do not modify the certificate verification
+      settings for other connections
+    + Fix: Fix a potential crash when configuring raw certificates
+    + Fix: Avoid a potential crash with very long ALPN protocol
+      names
+    + Fix: Make the call to a CertificateVerifier more robust
+    + Fix: Avoid a potential crash when processing OCSP URLs
+    + Fix: Make the processing of OCSP responses more robust
+    + Fix: Stricter OCSP handling when soft-fail is disabled
+    + Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+    + Fix: Harden against the mis-use of Pool.destroy(long)
+
+-------------------------------------------------------------------

Old:
----
  tomcat-native-2.0.15-src.tar.gz
  tomcat-native-2.0.15-src.tar.gz.asc

New:
----
  tomcat-native-2.0.16-src.tar.gz
  tomcat-native-2.0.16-src.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libtcnative-2-0.spec ++++++
--- /var/tmp/diff_new_pack.WEietk/_old  2026-09-28 10:43:26.432381279 +0200
+++ /var/tmp/diff_new_pack.WEietk/_new  2026-09-28 10:43:26.434381363 +0200
@@ -18,7 +18,7 @@
 
 %{!?make_build:%global make_build make %{?_smp_mflags}}
 Name:           libtcnative-2-0
-Version:        2.0.15
+Version:        2.0.16
 Release:        0
 Summary:        Tomcat resources for performance, compatibility, etc
 License:        Apache-2.0
@@ -26,7 +26,7 @@
 URL:            https://tomcat.apache.org/native-doc/index.html
 Source0:        
https://archive.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz
 Source1:        
https://archive.apache.org/dist/tomcat/tomcat-connectors/native/%{version}/source/tomcat-native-%{version}-src.tar.gz.asc
-# https://www.apache.org/dist/tomcat/tomcat-connectors/KEYS
+# https://downloads.apache.org/tomcat/tomcat-connectors/KEYS
 Source2:        %{name}.keyring
 Patch0:         apr163.patch
 BuildRequires:  fdupes

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.WEietk/_old  2026-09-28 10:43:26.521385006 +0200
+++ /var/tmp/diff_new_pack.WEietk/_new  2026-09-28 10:43:26.525385174 +0200
@@ -1,6 +1,6 @@
-mtime: 1781587474
-commit: 1c36dbaf56f358f38dc738d280279f0215398405db2b45bc84177daff9f79c05
+mtime: 1790314819
+commit: fc0eb220e2d5e00e3562e54cea619df33e00a924c2a0e211563b2a330e679f78
 url: https://src.opensuse.org/java-packages/libtcnative-2-0
-revision: 1c36dbaf56f358f38dc738d280279f0215398405db2b45bc84177daff9f79c05
+revision: fc0eb220e2d5e00e3562e54cea619df33e00a924c2a0e211563b2a330e679f78
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-25 07:40:19.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ tomcat-native-2.0.15-src.tar.gz -> tomcat-native-2.0.16-src.tar.gz ++++++
++++ 3397 lines of diff (skipped)

Reply via email to