Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package java-1_8_0-openjdk for openSUSE:Factory checked in at 2026-08-04 23:28:16 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/java-1_8_0-openjdk (Old) and /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.16738 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "java-1_8_0-openjdk" Tue Aug 4 23:28:16 2026 rev:116 rq:1369432 version:1.8.0.502 Changes: -------- --- /work/SRC/openSUSE:Factory/java-1_8_0-openjdk/java-1_8_0-openjdk.changes 2026-06-10 15:50:34.118291999 +0200 +++ /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.16738/java-1_8_0-openjdk.changes 2026-08-04 23:28:20.193616790 +0200 @@ -1,0 +2,103 @@ +Tue Aug 4 07:40:34 UTC 2026 - Andreas Schwab <[email protected]> + +- Modified patch: + * riscv64-zero.patch + + rebase and drop integrated hunks + +------------------------------------------------------------------- +Tue Aug 4 05:35:32 UTC 2026 - Fridrich Strba <[email protected]> + +- Update to version jdk8u502 (icedtea 3.40.0) + * CVEs + + CVE-2026-46968, bsc#1272224 + + CVE-2026-47010, bsc#1272225 + + CVE-2026-47021, bsc#1272227 + + CVE-2026-47027, bsc#1272228 + + CVE-2026-60147, bsc#1272237 + + CVE-2026-47059, bsc#1272235 + + CVE-2026-47063, bsc#1272236 + + CVE-2026-47057, bsc#1272233 + + CVE-2026-47058, bsc#1272234 + + CVE-2026-41254, bsc#1272459 + * Import of OpenJDK 8 u502 build 07 + + JDK-6815126: intermittent SimulResumerTest.java failure + + JDK-8199138: Add RISC-V support to Zero + + JDK-8209362: sun/security/ssl/SSLSocketImpl/ReuseAddr.java + failed due to "BindException: Address already in use (Bind + failed)" + + JDK-8246330: Add TLS Tests for Legacy ECDSA curves + + JDK-8249159: Downport test rework for SSLSocketTemplate from + JDK-8224650 + + JDK-8261235: C1 compilation fails with + assert(res->vreg_number() == index) failed: conversion check + + JDK-8273135: java/awt/color/ICC_ColorSpace/ + /MTTransformReplacedProfile.java crashes in liblcms.dylib with + NULLSeek+0x7 + + JDK-8274736: Concurrent read/close of SSLSockets causes + SSLSessions to be invalidated unnecessarily + + JDK-8280158: New test from JDK-8274736 failed with/without + patch in JDK11u + + JDK-8298873: Update IllegalRecordVersion.java for changes to + TLS implementation + + JDK-8301189: validate-source fails after JDK-8298873 + + JDK-8314730: GHA: Drop libfreetype6-dev transitional package + in favor of libfreetype-dev + + JDK-8321489: Update LCMS to 2.16 + + JDK-8336451: [11u] GHA macos-13 and macos-15 builders are + unable to resolve local hostname + + JDK-8348110: Update LCMS to 2.17 + + JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and + getProcessCpuLoad are stale after 24.8 days (Windows) + + JDK-8363966: GHA: Switch cross-compiling sysroots to Debian + trixie + + JDK-8368041: Enhance TLS certificate handling + + JDK-8369996: Testcase java/net/Socket/B8312065.java fails on + Mac, AIX and Solaris + + JDK-8372351: Add 2 WISeKey roots + + JDK-8374058: Enhance JPEG handling + + JDK-8374888: Implement internal test cache to help + UserIterCount test performance + + JDK-8375065: Update LCMS to 2.18 + + JDK-8377158: Enhance XBM image support + + JDK-8377498: Improve HttpServer handling + + JDK-8377833: Enhance Jar file processing + + JDK-8378631: Update Zlib Data Compression Library to Version + 1.3.2 + + JDK-8378687: Improve delegation of HttpURLConnection + + JDK-8379684: Bump update version of OpenJDK: 8u502 + + JDK-8380377: [8u] Problem list CAInterop.java#teliarootcav2 + + JDK-8380672: Improve certification checking + + JDK-8380689: distrust/Chunghwa.java test fails with a + compilation error + + JDK-8380947: Add pull request template + + JDK-8381039: Enhance AWT ImagingLib + + JDK-8381049: Enhance Jar handling + + JDK-8381185: Improve Nashorn index handling + + JDK-8381195: Enhance Dataview Implementation + + JDK-8381519: Enhance Der Value Handling + + JDK-8381796: Enhance Certificate parsing + + JDK-8383175: (tz) Update Timezone Data to 2026b + + JDK-8383354: Update LCMS to 2.19.1 + + JDK-8383473: Follow on from tzdata2026b time change to include + temporary hack BC time change + + JDK-8384158: GHA: Downgrade Windows GHA runners to + windows-2022 temporarily + * AArch32 port + + JDK-8385332: aarch32 started to crash after 8261235 + +------------------------------------------------------------------- +Wed Jul 29 17:32:30 UTC 2026 - Bernhard Wiedemann <[email protected]> + +- Add patches for reproducible builds + * reproducible-copyright-year.patch + * java-40y.patch + * reproducible-zip-extra-fields.patch + * reproducible-dist-id.patch + * reproducible-generated-source-dates.patch + * reproducible-jvm-cfg-order.patch + * reproducible-generated-timestamps.patch + * reproducible-classuse-order.patch +- Drop broken classes.jsa (embedded build path failed java -Xshare:on -version) +- Unset CFLAGS/CXXFLAGS after configure to avoid warnings + +------------------------------------------------------------------- Old: ---- icedtea-3.39.0.tar.xz New: ---- icedtea-3.40.0.tar.xz java-40y.patch reproducible-classuse-order.patch reproducible-copyright-year.patch reproducible-dist-id.patch reproducible-generated-source-dates.patch reproducible-generated-timestamps.patch reproducible-jvm-cfg-order.patch reproducible-zip-extra-fields.patch ----------(New B)---------- New: * reproducible-copyright-year.patch * java-40y.patch * reproducible-zip-extra-fields.patch New: * reproducible-generated-timestamps.patch * reproducible-classuse-order.patch - Drop broken classes.jsa (embedded build path failed java -Xshare:on -version) New:- Add patches for reproducible builds * reproducible-copyright-year.patch * java-40y.patch New: * reproducible-zip-extra-fields.patch * reproducible-dist-id.patch * reproducible-generated-source-dates.patch New: * reproducible-dist-id.patch * reproducible-generated-source-dates.patch * reproducible-jvm-cfg-order.patch New: * reproducible-jvm-cfg-order.patch * reproducible-generated-timestamps.patch * reproducible-classuse-order.patch New: * reproducible-generated-source-dates.patch * reproducible-jvm-cfg-order.patch * reproducible-generated-timestamps.patch New: * java-40y.patch * reproducible-zip-extra-fields.patch * reproducible-dist-id.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ java-1_8_0-openjdk.spec ++++++ --- /var/tmp/diff_new_pack.Sl7SRA/_old 2026-08-04 23:28:26.653845235 +0200 +++ /var/tmp/diff_new_pack.Sl7SRA/_new 2026-08-04 23:28:26.657845377 +0200 @@ -20,7 +20,7 @@ %global make make %{!?aarch64:%global aarch64 aarch64 arm64 armv8} %global jit_arches %{ix86} x86_64 ppc64 ppc64le %{aarch64} %{arm} -%global icedtea_version 3.39.0 +%global icedtea_version 3.40.0 %global buildoutputdir openjdk.build/ %global headless_binaries java keytool orbd policytool rmid rmiregistry servertool tnameserv %global headless_binaries_comma %(echo %{headless_binaries} | sed 's#\ #,#g') @@ -41,10 +41,10 @@ # Standard JPackage naming and versioning defines. # priority must be 6 digits in total %global priority 1805 -%global javaver 1.8.0 -%global updatever 492 -%global buildver 09 %global featurever 8 +%global javaver 1.%{featurever}.0 +%global updatever 502 +%global buildver 07 # Standard JPackage directories and symbolic links. %global sdklnk java-%{javaver}-openjdk %global archname %{sdklnk} @@ -146,6 +146,11 @@ %global with_shenandoah 0 #endif %global NSS_LIBDIR %(pkg-config --variable=libdir nss) +%ifarch %{aarch64} +%if 0%{?gcc_version} < 7 || 0%{?suse_version} < 1500 +%define with_gcc 7 +%endif +%endif %bcond_without bootstrap %bcond_with zero # Turn on/off some features depending on openSUSE version @@ -170,11 +175,6 @@ %global tapsetroot %{_datadir}/systemtap %global tapsetdir %{tapsetroot}/tapset/%{_build_cpu} %endif -%ifarch %{aarch64} -%if 0%{?gcc_version} < 7 || 0%{?suse_version} < 1500 -%define with_gcc 7 -%endif -%endif Name: java-1_8_0-openjdk Version: %{javaver}.%{updatever} Release: 0 @@ -209,11 +209,29 @@ Patch20: reproducible-directory-mtime.patch Patch21: reproducible-javadoc-timestamp.patch Patch22: reproducible-properties.patch +# Derive the copyright year in the javadoc footer from SOURCE_DATE_EPOCH +Patch23: reproducible-copyright-year.patch +# Use SOURCE_DATE_EPOCH for the dates the CLDR converter and GenerateCharacter +# write into the sources they generate +Patch24: reproducible-generated-source-dates.patch +# Do not fail the build when the clock is far from the currency data's epoch +Patch25: java-40y.patch +# Drop build timestamps from generated javadoc and CORBA sources +Patch26: reproducible-generated-timestamps.patch +# Build zip archives without the UT extra field, which carries access times +Patch27: reproducible-zip-extra-fields.patch +# Sort the javadoc class-use tables on a key that distinguishes same-named +# members of different classes +Patch28: reproducible-classuse-order.patch # # Patch for PPC Patch103: ppc-zero-hotspot.patch Patch1001: java-1_8_0-openjdk-suse-desktop-files.patch Patch1002: icedtea-3.8.0-s390.patch +# IcedTea-level reproducibility fixes - these patch the icedtea build itself, +# so unlike the openjdk ones above they are applied in %%prep +Patch1003: reproducible-jvm-cfg-order.patch +Patch1004: reproducible-dist-id.patch Patch2001: disable-doclint-by-default.patch Patch2002: JDK_1_8_0-8208602.patch Patch3000: tls13extensions.patch @@ -239,6 +257,9 @@ BuildRequires: libxslt BuildRequires: mozilla-nss-devel >= 3.53 BuildRequires: pkgconfig +%if 0%{?suse_version} >= 1500 +BuildRequires: strip-nondeterminism +%endif BuildRequires: unzip BuildRequires: xorg-x11-proto-devel BuildRequires: xz @@ -439,6 +460,11 @@ %patch -P 1002 -p1 %endif +# Reproducibility fixes to the icedtea build itself. These must be applied +# before %%build runs autogen.sh, which regenerates configure and Makefile.in. +%patch -P 1003 -p1 +%patch -P 1004 -p1 + # Setup nss.fips.cfg sed -e "s:@NSS_LIBDIR@:%{NSS_LIBDIR}:g" %{SOURCE17} > nss.fips.cfg sed -i -e "s:@NSS_SECMOD@:sql\:%{_sysconfdir}/pki/nssdb:g" nss.fips.cfg @@ -481,7 +507,7 @@ %configure \ --disable-downloading \ --with-tzdata-dir=%{_datadir}/javazi \ - --with-pkgversion="build %{javaver}_%{updatever}-b%{buildver} suse-%{suse_version}-%{_arch}" \ + --with-pkgversion="build %{javaver}_%{updatever}-b%{buildver} suse-0%{?suse_version}-%{_arch}" \ --disable-nss \ --enable-sysconf-nss \ --enable-non-nss-curves \ @@ -539,6 +565,13 @@ %endif --with-openjdk-src-zip=%{SOURCE1} +# configure has captured CFLAGS/CXXFLAGS and passes them on as +# --with-extra-cflags/--with-extra-cxxflags, so they must not stay in the +# environment: hotspot's makefiles only ever do "CFLAGS +=" and compile C++ +# with "$(CXX) $(CXXFLAGS) $(CFLAGS)", so an inherited CFLAGS puts -std=gnu99 +# on every g++ command line ("valid for C/ObjC but not for C++"). +unset CFLAGS CXXFLAGS + %make patch %{?_smp_mflags} patch -p0 -i %{PATCH1} @@ -555,6 +588,12 @@ patch -p0 -i %{PATCH20} patch -p0 -i %{PATCH21} patch -p0 -i %{PATCH22} +patch -p1 -i %{PATCH23} +patch -p1 -i %{PATCH24} +patch -p1 -i %{PATCH25} +patch -p1 -i %{PATCH26} +patch -p1 -i %{PATCH27} +patch -p1 -i %{PATCH28} %ifarch ppc ppc64 ppc64le # PPC fixes @@ -574,7 +613,7 @@ bash ./autogen.sh ) -%make %{?_smp_mflags} +%{make} %{?_smp_mflags} export JAVA_HOME=$(pwd)/%{buildoutputdir}images/j2sdk-image @@ -721,6 +760,8 @@ install -m 0644 $d.desktop %{buildroot}/%{_jvmdir}/%{jredir}/lib/desktop/ done +rm -f %{buildroot}%{_jvmdir}/%{jredir}/lib/*/server/classes.jsa # broken and builds vary + # Find JRE directories. find %{buildroot}%{_jvmdir}/%{jredir} -type d \ | grep -v jre/lib/security \ @@ -793,6 +834,13 @@ echo "" >> accessibility.properties popd +%if 0%?have_strip_nondeterminism > 0 +strip-all-nondeterminism %{buildroot}/%{_jvmdir} +# ct.sym is a jar, but strip-all-nondeterminism only looks at *.jar, *.zip and +# a few other suffixes, so it has to be normalised by name. +strip-nondeterminism --type zip --timestamp=${SOURCE_DATE_EPOCH:-1494270000} \ + --clamp-timestamp %{buildroot}%{_jvmdir}/%{sdkdir}/lib/ct.sym +%endif # fdupes links the files from JDK to JRE, so it breaks a JRE # use it carefully :)) %fdupes -s %{buildroot}/%{_jvmdir}/%{jredir}/ ++++++ aarch32-git.tar.xz ++++++ /work/SRC/openSUSE:Factory/java-1_8_0-openjdk/aarch32-git.tar.xz /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.16738/aarch32-git.tar.xz differ: char 15, line 1 ++++++ icedtea-3.39.0.tar.xz -> icedtea-3.40.0.tar.xz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/ChangeLog new/icedtea-3.40.0/ChangeLog --- old/icedtea-3.39.0/ChangeLog 2026-04-28 23:59:50.396989469 +0200 +++ new/icedtea-3.40.0/ChangeLog 2026-08-01 18:11:38.310537506 +0200 @@ -1,5 +1,47 @@ 2026-04-27 Andrew John Hughes <[email protected]> + Bump aarch32 to jdk8u502-ga-aarch32-20260731 + * patches/hotspot/aarch32/8364465-cpu-2026-04.patch: + * patches/hotspot/aarch32/8370986-cpu-2026-04.patch: + Removed. + * Makefile.am: + (ICEDTEA_PATCHES): Remove HotSpot security patches + added for AArch32 from 8u492-b09. + * NEWS: Updated. + * hotspot.map.in: Bump aarch32 to + jdk8u502-ga-aarch32-20260731 + +2026-08-01 Andrew John Hughes <[email protected]> + + Bump shenandoah to shenandoah8u502-b07 + * hotspot.map.in: Bump shenandoah to + shenandoah8u502-b07 + +2026-08-01 Andrew John Hughes <[email protected]> + + Support passing toolchain binaries + to the OpenJDK configure. + * Makefile.am: + (ICEDTEA_CONFIGURE): Pass values of + $(CC), $(CXX), $(LD), $(AR), $(AR), + $(AS), $(NM), $(OBJCOPY), $(OBJDUMP), + $(READELF) and $(STRIP) (if any) + down to OpenJDK build. + +2026-08-01 Andrew John Hughes <[email protected]> + + Bump to icedtea-3.40.0. + * Makefile.am: + (OPENJDK_CHANGESET): Update to icedtea-3.40.0 tag. + (OPENJDK_SHA256SUM): Likewise. + * NEWS: Updated. + * acinclude.m4: + (IT_DETERMINE_VERSION): Set JDK_UPDATE_VERSION + to 502 and BUILD_VERSION to b07. + * configure.ac: Bump to 3.40.0. + +2026-04-27 Andrew John Hughes <[email protected]> + Prepare for release. * NEWS: Set release date to tomorrow post testing (2025-04-28). diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/Makefile.am new/icedtea-3.40.0/Makefile.am --- old/icedtea-3.39.0/Makefile.am 2026-04-28 23:59:50.409989500 +0200 +++ new/icedtea-3.40.0/Makefile.am 2026-08-01 18:11:38.316537515 +0200 @@ -1,8 +1,8 @@ # Dependencies -OPENJDK_CHANGESET = de478b44737 +OPENJDK_CHANGESET = cc677591ffc -OPENJDK_SHA256SUM = 492cca1aa42f355fbfed3e9f28fdc731993ed637486495917e00fd0e094d4688 +OPENJDK_SHA256SUM = 5a7262110d9d4fd3ce8848d4864726cd60c888da1136a760921fa4b6d90a451a HS_TYPE = "`$(AWK) 'version==$$1 {print $$2}' version=$(HSBUILD) $(abs_top_builddir)/hotspot.map`" HS_URL = "`$(AWK) 'version==$$1 {print $$3}' version=$(HSBUILD) $(abs_top_builddir)/hotspot.map`" @@ -253,9 +253,7 @@ # Patches only for AArch32 if WITH_AARCH32_HSBUILD ICEDTEA_PATCHES += \ - patches/hotspot/$(HSBUILD)/8078628-pr3208.patch \ - patches/hotspot/$(HSBUILD)/8364465-cpu-2026-04.patch \ - patches/hotspot/$(HSBUILD)/8370986-cpu-2026-04.patch + patches/hotspot/$(HSBUILD)/8078628-pr3208.patch endif ICEDTEA_PATCHES += \ @@ -365,7 +363,11 @@ --with-extra-cflags="$(CFLAGS)" \ --with-extra-cxxflags="$(CXXFLAGS)" \ --with-extra-ldflags="$(LDFLAGS)" \ - --with-extra-asflags="$(CCASFLAGS)" + --with-extra-asflags="$(CCASFLAGS)" \ + CC="$(CC)" CXX="$(CXX)" LD="$(LD)" \ + AR="$(AR)" AS="$(AS)" NM="$(NM)" \ + OBJCOPY="$(OBJCOPY)" OBJDUMP="$(OBJDUMP)" \ + READELF="$(READELF)" STRIP="$(STRIP)" ICEDTEA_CONFIGURE_ENV = \ ${ICEDTEA_COMMON_ENV} \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/Makefile.in new/icedtea-3.40.0/Makefile.in --- old/icedtea-3.39.0/Makefile.in 2026-04-29 00:00:16.382051441 +0200 +++ new/icedtea-3.40.0/Makefile.in 2026-08-01 18:13:41.704728210 +0200 @@ -96,9 +96,7 @@ # Patches only for AArch32 @WITH_AARCH32_HSBUILD_TRUE@@WITH_ALT_HSBUILD_TRUE@am__append_2 = \ -@WITH_AARCH32_HSBUILD_TRUE@@WITH_ALT_HSBUILD_TRUE@ patches/hotspot/$(HSBUILD)/8078628-pr3208.patch \ -@WITH_AARCH32_HSBUILD_TRUE@@WITH_ALT_HSBUILD_TRUE@ patches/hotspot/$(HSBUILD)/8364465-cpu-2026-04.patch \ -@WITH_AARCH32_HSBUILD_TRUE@@WITH_ALT_HSBUILD_TRUE@ patches/hotspot/$(HSBUILD)/8370986-cpu-2026-04.patch +@WITH_AARCH32_HSBUILD_TRUE@@WITH_ALT_HSBUILD_TRUE@ patches/hotspot/$(HSBUILD)/8078628-pr3208.patch @WITH_ALT_HSBUILD_TRUE@am__append_3 = \ @WITH_ALT_HSBUILD_TRUE@ patches/hotspot/$(HSBUILD)/8041658.patch \ @@ -645,8 +643,8 @@ top_build_prefix = @top_build_prefix@ top_builddir = @top_builddir@ top_srcdir = @top_srcdir@ -OPENJDK_CHANGESET = de478b44737 -OPENJDK_SHA256SUM = 492cca1aa42f355fbfed3e9f28fdc731993ed637486495917e00fd0e094d4688 +OPENJDK_CHANGESET = cc677591ffc +OPENJDK_SHA256SUM = 5a7262110d9d4fd3ce8848d4864726cd60c888da1136a760921fa4b6d90a451a HS_TYPE = "`$(AWK) 'version==$$1 {print $$2}' version=$(HSBUILD) $(abs_top_builddir)/hotspot.map`" HS_URL = "`$(AWK) 'version==$$1 {print $$3}' version=$(HSBUILD) $(abs_top_builddir)/hotspot.map`" HS_CHANGESET = "`$(AWK) 'version==$$1 {print $$4}' version=$(HSBUILD) $(abs_top_builddir)/hotspot.map`" @@ -826,19 +824,22 @@ --with-extra-cflags="$(CFLAGS)" \ --with-extra-cxxflags="$(CXXFLAGS)" \ --with-extra-ldflags="$(LDFLAGS)" \ - --with-extra-asflags="$(CCASFLAGS)" $(am__append_11) \ - $(am__append_12) $(am__append_13) $(am__append_14) \ - $(am__append_15) $(am__append_17) $(am__append_18) \ - $(am__append_19) $(am__append_20) $(am__append_22) \ - $(am__append_23) $(am__append_24) $(am__append_26) \ - $(am__append_27) $(am__append_29) $(am__append_30) \ - $(am__append_32) $(am__append_33) $(am__append_34) \ - $(am__append_35) $(am__append_36) $(am__append_37) \ - $(am__append_38) $(am__append_39) $(am__append_41) \ - $(am__append_42) $(am__append_43) $(am__append_44) \ - $(am__append_45) $(am__append_46) $(am__append_47) \ - $(am__append_48) $(am__append_49) $(am__append_50) \ - $(am__append_51) $(am__append_52) + --with-extra-asflags="$(CCASFLAGS)" CC="$(CC)" CXX="$(CXX)" \ + LD="$(LD)" AR="$(AR)" AS="$(AS)" NM="$(NM)" \ + OBJCOPY="$(OBJCOPY)" OBJDUMP="$(OBJDUMP)" READELF="$(READELF)" \ + STRIP="$(STRIP)" $(am__append_11) $(am__append_12) \ + $(am__append_13) $(am__append_14) $(am__append_15) \ + $(am__append_17) $(am__append_18) $(am__append_19) \ + $(am__append_20) $(am__append_22) $(am__append_23) \ + $(am__append_24) $(am__append_26) $(am__append_27) \ + $(am__append_29) $(am__append_30) $(am__append_32) \ + $(am__append_33) $(am__append_34) $(am__append_35) \ + $(am__append_36) $(am__append_37) $(am__append_38) \ + $(am__append_39) $(am__append_41) $(am__append_42) \ + $(am__append_43) $(am__append_44) $(am__append_45) \ + $(am__append_46) $(am__append_47) $(am__append_48) \ + $(am__append_49) $(am__append_50) $(am__append_51) \ + $(am__append_52) ICEDTEA_CONFIGURE_ENV = ${ICEDTEA_COMMON_ENV} \ FREETYPE_CFLAGS="${FREETYPE2_CFLAGS}" \ FREETYPE_LIBS="${FREETYPE2_LIBS}" $(am__append_16) \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/NEWS new/icedtea-3.40.0/NEWS --- old/icedtea-3.39.0/NEWS 2026-04-28 23:59:50.412989508 +0200 +++ new/icedtea-3.40.0/NEWS 2026-08-01 18:11:38.320537521 +0200 @@ -12,6 +12,66 @@ CVE-XXXX-YYYY: https://cve.mitre.org/cgi-bin/cvename.cgi?name=XXXX-YYYY +New in release 3.40.0 (2026-08-01): + +* CVEs + - CVE-2026-46968 + - CVE-2026-47010 + - CVE-2026-47021 + - CVE-2026-47027 + - CVE-2026-60147 + - CVE-2026-47059 + - CVE-2026-47063 + - CVE-2026-47057 + - CVE-2026-47058 + - CVE-2026-41254 +* Import of OpenJDK 8 u502 build 07 + - JDK-6815126: intermittent SimulResumerTest.java failure + - JDK-8199138: Add RISC-V support to Zero + - JDK-8209362: sun/security/ssl/SSLSocketImpl/ReuseAddr.java failed due to "BindException: Address already in use (Bind failed)" + - JDK-8246330: Add TLS Tests for Legacy ECDSA curves + - JDK-8249159: Downport test rework for SSLSocketTemplate from 8224650 + - JDK-8261235: C1 compilation fails with assert(res->vreg_number() == index) failed: conversion check + - JDK-8273135: java/awt/color/ICC_ColorSpace/MTTransformReplacedProfile.java crashes in liblcms.dylib with NULLSeek+0x7 + - JDK-8274736: Concurrent read/close of SSLSockets causes SSLSessions to be invalidated unnecessarily + - JDK-8280158: New test from JDK-8274736 failed with/without patch in JDK11u + - JDK-8298873: Update IllegalRecordVersion.java for changes to TLS implementation + - JDK-8301189: validate-source fails after JDK-8298873 + - JDK-8314730: GHA: Drop libfreetype6-dev transitional package in favor of libfreetype-dev + - JDK-8321489: Update LCMS to 2.16 + - JDK-8336451: [11u] GHA macos-13 and macos-15 builders are unable to resolve local hostname + - JDK-8348110: Update LCMS to 2.17 + - JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and getProcessCpuLoad are stale after 24.8 days (Windows) + - JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie + - JDK-8368041: Enhance TLS certificate handling + - JDK-8369996: Testcase java/net/Socket/B8312065.java fails on Mac, AIX and Solaris + - JDK-8372351: Add 2 WISeKey roots + - JDK-8374058: Enhance JPEG handling + - JDK-8374888: Implement internal test cache to help UserIterCount test performance + - JDK-8375065: Update LCMS to 2.18 + - JDK-8377158: Enhance XBM image support + - JDK-8377498: Improve HttpServer handling + - JDK-8377833: Enhance Jar file processing + - JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2 + - JDK-8378687: Improve delegation of HttpURLConnection + - JDK-8379684: Bump update version of OpenJDK: 8u502 + - JDK-8380377: [8u] Problem list CAInterop.java#teliarootcav2 + - JDK-8380672: Improve certification checking + - JDK-8380689: distrust/Chunghwa.java test fails with a compilation error + - JDK-8380947: Add pull request template + - JDK-8381039: Enhance AWT ImagingLib + - JDK-8381049: Enhance Jar handling + - JDK-8381185: Improve Nashorn index handling + - JDK-8381195: Enhance Dataview Implementation + - JDK-8381519: Enhance Der Value Handling + - JDK-8381796: Enhance Certificate parsing + - JDK-8383175: (tz) Update Timezone Data to 2026b + - JDK-8383354: Update LCMS to 2.19.1 + - JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change + - JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily +* AArch32 port + - JDK-8385332: aarch32 started to crash after 8261235 + New in release 3.39.0 (2026-04-28): * CVEs diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/acinclude.m4 new/icedtea-3.40.0/acinclude.m4 --- old/icedtea-3.39.0/acinclude.m4 2026-04-28 23:59:50.418989522 +0200 +++ new/icedtea-3.40.0/acinclude.m4 2026-08-01 18:11:38.322537524 +0200 @@ -1966,8 +1966,8 @@ dnl (e.g. 1.8.0 = 8, 1.7.0 = 7, etc.) JAVA_SPEC_VER=8 JAVA_VENDOR=openjdk - JDK_UPDATE_VERSION=492 - BUILD_VERSION=b09 + JDK_UPDATE_VERSION=502 + BUILD_VERSION=b07 MILESTONE=fcs if test "x${MILESTONE}" = "xfcs"; then COMBINED_VERSION=${JDK_UPDATE_VERSION}-${BUILD_VERSION} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/configure new/icedtea-3.40.0/configure --- old/icedtea-3.39.0/configure 2026-04-29 00:00:16.005050541 +0200 +++ new/icedtea-3.40.0/configure 2026-08-01 18:13:41.324727554 +0200 @@ -1,6 +1,6 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.69 for icedtea 3.39.0. +# Generated by GNU Autoconf 2.69 for icedtea 3.40.0. # # Report bugs to <[email protected]>. # @@ -580,8 +580,8 @@ # Identity of this package. PACKAGE_NAME='icedtea' PACKAGE_TARNAME='icedtea' -PACKAGE_VERSION='3.39.0' -PACKAGE_STRING='icedtea 3.39.0' +PACKAGE_VERSION='3.40.0' +PACKAGE_STRING='icedtea 3.40.0' PACKAGE_BUGREPORT='[email protected]' PACKAGE_URL='' @@ -1727,7 +1727,7 @@ # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -\`configure' configures icedtea 3.39.0 to adapt to many kinds of systems. +\`configure' configures icedtea 3.40.0 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1798,7 +1798,7 @@ if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of icedtea 3.39.0:";; + short | recursive ) echo "Configuration of icedtea 3.40.0:";; esac cat <<\_ACEOF @@ -2063,7 +2063,7 @@ test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -icedtea configure 3.39.0 +icedtea configure 3.40.0 generated by GNU Autoconf 2.69 Copyright (C) 2012 Free Software Foundation, Inc. @@ -2632,7 +2632,7 @@ This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by icedtea $as_me 3.39.0, which was +It was created by icedtea $as_me 3.40.0, which was generated by GNU Autoconf 2.69. Invocation command line was $ $0 $@ @@ -3605,7 +3605,7 @@ # Define the identity of the package. PACKAGE='icedtea' - VERSION='3.39.0' + VERSION='3.40.0' cat >>confdefs.h <<_ACEOF @@ -3824,8 +3824,8 @@ JAVA_VER=1.8.0 JAVA_SPEC_VER=8 JAVA_VENDOR=openjdk - JDK_UPDATE_VERSION=492 - BUILD_VERSION=b09 + JDK_UPDATE_VERSION=502 + BUILD_VERSION=b07 MILESTONE=fcs if test "x${MILESTONE}" = "xfcs"; then COMBINED_VERSION=${JDK_UPDATE_VERSION}-${BUILD_VERSION} @@ -15759,7 +15759,7 @@ # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by icedtea $as_me 3.39.0, which was +This file was extended by icedtea $as_me 3.40.0, which was generated by GNU Autoconf 2.69. Invocation command line was CONFIG_FILES = $CONFIG_FILES @@ -15816,7 +15816,7 @@ cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_config="`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`" ac_cs_version="\\ -icedtea config.status 3.39.0 +icedtea config.status 3.40.0 configured by $0, generated by GNU Autoconf 2.69, with options \\"\$ac_cs_config\\" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/configure.ac new/icedtea-3.40.0/configure.ac --- old/icedtea-3.39.0/configure.ac 2026-04-28 23:59:50.418989522 +0200 +++ new/icedtea-3.40.0/configure.ac 2026-08-01 18:11:38.323537526 +0200 @@ -1,4 +1,4 @@ -AC_INIT([icedtea], [3.39.0], [[email protected]]) +AC_INIT([icedtea], [3.40.0], [[email protected]]) AC_CANONICAL_HOST AC_CANONICAL_TARGET AM_INIT_AUTOMAKE([1.9 tar-pax foreign]) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/hotspot.map.in new/icedtea-3.40.0/hotspot.map.in --- old/icedtea-3.39.0/hotspot.map.in 2026-04-28 23:59:50.427989543 +0200 +++ new/icedtea-3.40.0/hotspot.map.in 2026-08-01 18:11:38.382537615 +0200 @@ -1,3 +1,3 @@ # version type(drop/hg) url changeset sha256sum -shenandoah drop https://icedtea.classpath.org/download/drops/icedtea8/@ICEDTEA_RELEASE@ d5052511616 48713b749d9e9acc8109085b9c0cc37897b33e169dec77513accd6fc017ee5c2 -aarch32 drop https://icedtea.classpath.org/download/drops/icedtea8/@ICEDTEA_RELEASE@ 953bc9695f7 7b32f287cd38af211aa960b135f6e1501d750ee22cc3bc49b2fc18a5a82b1dbf +shenandoah drop https://icedtea.classpath.org/download/drops/icedtea8/@ICEDTEA_RELEASE@ 1cc3cb10846 e55b875b748b1d5ff647b43e9d49445ef7ad03018d555c1c9e299686c6229f28 +aarch32 drop https://icedtea.classpath.org/download/drops/icedtea8/@ICEDTEA_RELEASE@ e9efeef446d 40cae6fa394bab98063de1e856322674fcc8ab109f3d3fd29854b9ea2f164e46 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/patches/hotspot/aarch32/8364465-cpu-2026-04.patch new/icedtea-3.40.0/patches/hotspot/aarch32/8364465-cpu-2026-04.patch --- old/icedtea-3.39.0/patches/hotspot/aarch32/8364465-cpu-2026-04.patch 2026-04-28 23:59:50.442989579 +0200 +++ new/icedtea-3.40.0/patches/hotspot/aarch32/8364465-cpu-2026-04.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,72 +0,0 @@ -commit 6b719f16d9ecd53e9ad34e77e683b10d896e0ea3 -Author: Andreas Chmielewski <[email protected]> -AuthorDate: Mon Apr 13 12:07:02 2026 +0200 -Commit: Andrew John Hughes <[email protected]> -CommitDate: Mon Apr 27 23:25:17 2026 +0100 - - 8364465: Enhance behavior of some intrinsics - - Reviewed-by: andrew - Backport-of: 304331b052c177359f09ba7d2710666fa6a4a7d1 - -diff --git openjdk.orig/hotspot/src/cpu/aarch64/vm/aarch64.ad openjdk/hotspot/src/cpu/aarch64/vm/aarch64.ad -index 7341ddf87f..705464f80f 100644 ---- openjdk.orig/hotspot/src/cpu/aarch64/vm/aarch64.ad -+++ openjdk/hotspot/src/cpu/aarch64/vm/aarch64.ad -@@ -7511,10 +7511,11 @@ instruct bytes_reverse_unsigned_short(iRegINoSp dst, iRegIorL2I src) %{ - match(Set dst (ReverseBytesUS src)); - - ins_cost(INSN_COST); -- format %{ "rev16w $dst, $src" %} -+ format %{ "rev16w $dst, $src\t# $dst -> unsigned short" %} - - ins_encode %{ - __ rev16w(as_Register($dst$$reg), as_Register($src$$reg)); -+ __ narrow_subword_type(as_Register($dst$$reg), T_CHAR); - %} - - ins_pipe(ialu_reg); -diff --git openjdk.orig/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.cpp openjdk/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.cpp -index 4725e16c49..93c99a8b56 100644 ---- openjdk.orig/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.cpp -+++ openjdk/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.cpp -@@ -1827,6 +1827,17 @@ void MacroAssembler::store_sized_value(Address dst, Register src, size_t size_in - } - } - -+void MacroAssembler::narrow_subword_type(Register reg, BasicType bt) { -+ assert(is_subword_type(bt), "required"); -+ switch (bt) { -+ case T_BOOLEAN: andw(reg, reg, 1); break; -+ case T_BYTE: sxtbw(reg, reg); break; -+ case T_CHAR: uxthw(reg, reg); break; -+ case T_SHORT: sxthw(reg, reg); break; -+ default: ShouldNotReachHere(); -+ } -+} -+ - void MacroAssembler::decrementw(Register reg, int value) - { - if (value < 0) { incrementw(reg, -value); return; } -diff --git openjdk.orig/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.hpp openjdk/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.hpp -index 593411634b..5135d0b10e 100644 ---- openjdk.orig/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.hpp -+++ openjdk/hotspot/src/cpu/aarch64/vm/macroAssembler_aarch64.hpp -@@ -28,6 +28,7 @@ - #define CPU_AARCH64_VM_MACROASSEMBLER_AARCH64_HPP - - #include "asm/assembler.inline.hpp" -+#include "utilities/globalDefinitions.hpp" - - // MacroAssembler extends Assembler by frequently used macros. - // -@@ -620,6 +621,9 @@ public: - // Support for sign-extension (hi:lo = extend_sign(lo)) - void extend_sign(Register hi, Register lo); - -+ // Clean up a subword typed value to the representation in compliance with JVMS ยง2.3 -+ void narrow_subword_type(Register reg, BasicType bt); -+ - // Load and store values by size and signed-ness - void load_sized_value(Register dst, Address src, size_t size_in_bytes, bool is_signed, Register dst2 = noreg); - void store_sized_value(Address dst, Register src, size_t size_in_bytes, Register src2 = noreg); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/icedtea-3.39.0/patches/hotspot/aarch32/8370986-cpu-2026-04.patch new/icedtea-3.40.0/patches/hotspot/aarch32/8370986-cpu-2026-04.patch --- old/icedtea-3.39.0/patches/hotspot/aarch32/8370986-cpu-2026-04.patch 2026-04-28 23:59:50.442989579 +0200 +++ new/icedtea-3.40.0/patches/hotspot/aarch32/8370986-cpu-2026-04.patch 1970-01-01 01:00:00.000000000 +0100 @@ -1,25 +0,0 @@ -commit da9eab31a692d83216cd224aa9de909261c17e2e -Author: Aleksei Voitylov <[email protected]> -AuthorDate: Wed Mar 11 09:28:30 2026 +0100 -Commit: Andrew John Hughes <[email protected]> -CommitDate: Mon Apr 27 23:26:24 2026 +0100 - - 8370986: Enhance Zip file reading - - Reviewed-by: abakhtin, andrew - Backport-of: 0e46b6b0c682a6a4dd09d74bad4e7283fae4f479 - -diff --git openjdk.orig/hotspot/src/share/vm/classfile/classLoader.cpp openjdk/hotspot/src/share/vm/classfile/classLoader.cpp -index adffbb6d29..77cceff502 100644 ---- openjdk.orig/hotspot/src/share/vm/classfile/classLoader.cpp -+++ openjdk/hotspot/src/share/vm/classfile/classLoader.cpp -@@ -746,6 +746,9 @@ ClassPathEntry* ClassLoader::create_class_path_entry(const char *path, const str - if (throw_exception) { - THROW_MSG_(vmSymbols::java_lang_ClassNotFoundException(), msg, NULL); - } else { -+ if (TraceClassLoading || TraceClassPaths) { -+ tty->print_cr("[Path failed: %s, err: %s]", path, error_msg); -+ } - return NULL; - } - } ++++++ java-40y.patch ++++++ # Widen the currency cut-over sanity check from 10 to 40 years # # GenerateCurrencyData rejects any special-case cut-over time that is more # than 10 years away from the current time. That guard is about catching # typos in CurrencyData.properties, but it also makes the build fail when it # is run with a clock far from the data's epoch - which is what happens when # testing reproducibility with a shifted clock, and will happen anyway as # the data ages. # # Same change as java-40y.patch carries for java-17-openjdk. # diff --git a/openjdk/jdk/make/src/classes/build/tools/generatecurrencydata/GenerateCurrencyData.java b/openjdk/jdk/make/src/classes/build/tools/generatecurrencydata/GenerateCurrencyData.java index d599d9744fd..b544701fe66 100644 --- a/openjdk/jdk/make/src/classes/build/tools/generatecurrencydata/GenerateCurrencyData.java +++ b/openjdk/jdk/make/src/classes/build/tools/generatecurrencydata/GenerateCurrencyData.java @@ -283,8 +283,8 @@ public class GenerateCurrencyData { checkCurrencyCode(newCurrency); String timeString = currencyInfo.substring(4, length - 4); long time = format.parse(timeString).getTime(); - if (Math.abs(time - System.currentTimeMillis()) > ((long) 10) * 365 * 24 * 60 * 60 * 1000) { - throw new RuntimeException("time is more than 10 years from present: " + time); + if (Math.abs(time - System.currentTimeMillis()) > ((long) 40) * 365 * 24 * 60 * 60 * 1000) { + throw new RuntimeException("time is more than 40 years from present: " + time); } specialCaseCutOverTimes[specialCaseCount] = time; specialCaseOldCurrencies[specialCaseCount] = oldCurrency; ++++++ openjdk-git.tar.xz ++++++ /work/SRC/openSUSE:Factory/java-1_8_0-openjdk/openjdk-git.tar.xz /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.16738/openjdk-git.tar.xz differ: char 15, line 1 ++++++ reproducible-classuse-order.patch ++++++ # Give the javadoc class-use tables a total ordering # # ClassUseWriter.pkgDivide sorts each list of uses with Collections.sort, i.e. # by Doc.compareTo, whose key is the member's own name plus its signature # (ExecutableMemberDocImpl.generateKey). The declaring class is not part of # that key, so every _Dyn*Stub.get_val() in org.omg.DynamicAny has the # identical key "get_val()", all the comparisons return 0, and the stable sort # leaves those rows in the order they were inserted. # # That insertion order is the order of RootDoc.classes(), which comes from the # package Scope and ultimately from the order javac's file manager listed the # source directory, so it varies between builds. Thirteen class-use pages # differed between two builds this way - the same rows, rotated. # # Break the tie on the qualified name, which does include the declaring class. # Entries that already compared unequal keep their position, so nothing else in # the generated documentation moves. IndexBuilder.DocComparator already breaks # its ties the same way, which is why the index pages were unaffected. # # JDK-8039410 fixed this upstream in 9 by routing the sort through # Util.makeComparatorForClassUse(); that change also rewrites IndexBuilder and # adds 160 lines of comparator plumbing to Util.java, none of which JDK 8 needs. # # Diffed against the icedtea8 drop rather than exported from the jdk8u tree: # icedtea's langtools has a newer ClassUseWriter.java than jdk8u492-ga, so a # patch generated from git does not apply here. # --- a/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/ClassUseWriter.java 2026-07-29 21:17:30.204172822 +0200 +++ b/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/ClassUseWriter.java 2026-07-29 21:17:41.462022551 +0200 @@ -28,6 +28,7 @@ import java.io.IOException; import java.util.ArrayList; import java.util.Collections; +import java.util.Comparator; import java.util.HashMap; import java.util.Iterator; import java.util.List; @@ -176,11 +177,22 @@ } } + private static final Comparator<ProgramElementDoc> useComparator = + new Comparator<ProgramElementDoc>() { + public int compare(ProgramElementDoc a, ProgramElementDoc b) { + int result = a.compareTo(b); + if (result == 0) { + result = a.qualifiedName().compareTo(b.qualifiedName()); + } + return result; + } + }; + private Map<String,List<ProgramElementDoc>> pkgDivide(Map<String,? extends List<? extends ProgramElementDoc>> classMap) { Map<String,List<ProgramElementDoc>> map = new HashMap<String,List<ProgramElementDoc>>(); List<? extends ProgramElementDoc> list= classMap.get(classdoc.qualifiedName()); if (list != null) { - Collections.sort(list); + Collections.sort(list, useComparator); for (ProgramElementDoc doc : list) { PackageDoc pkg = doc.containingPackage(); pkgSet.add(pkg); ++++++ reproducible-copyright-year.patch ++++++ # Derive the copyright year from SOURCE_DATE_EPOCH # # configure takes COPYRIGHT_YEAR from the wall clock unless # --with-copyright-year is given. That year is substituted into the bottom # line of every generated javadoc page (make/Javadoc.gmk CopyrightLine), so # two builds that straddle New Year produce a different javadoc bundle in # its entirety - which is what the whole -javadoc subpackage differing came # down to. # # Honour SOURCE_DATE_EPOCH when it is set and no explicit year was asked # for, which is what later releases do via JDK-8282567. # # The spec re-runs openjdk/common/autoconf/autogen.sh after applying the # patches, so generated-configure.sh does not need patching too. # diff --git a/openjdk/common/autoconf/jdk-options.m4 b/openjdk/common/autoconf/jdk-options.m4 index 18ba585209b..bd1bf7bd549 100644 --- a/openjdk/common/autoconf/jdk-options.m4 +++ b/openjdk/common/autoconf/jdk-options.m4 @@ -596,6 +596,16 @@ AC_DEFUN_ONCE([JDKOPT_SETUP_JDK_VERSION_NUMBERS], AC_MSG_ERROR([Copyright year must have a value]) elif test "x$with_copyright_year" != x; then COPYRIGHT_YEAR="$with_copyright_year" + elif test "x$SOURCE_DATE_EPOCH" != x; then + # Derive the copyright year from SOURCE_DATE_EPOCH, so that it does not + # depend on when the build is run. Try GNU date first, then BSD date. + COPYRIGHT_YEAR=`date --utc --date=@$SOURCE_DATE_EPOCH +'%Y' 2> /dev/null` + if test "x$COPYRIGHT_YEAR" = x; then + COPYRIGHT_YEAR=`date -u -j -f %s $SOURCE_DATE_EPOCH +'%Y' 2> /dev/null` + fi + if test "x$COPYRIGHT_YEAR" = x; then + AC_MSG_ERROR([Cannot convert SOURCE_DATE_EPOCH to a copyright year]) + fi else COPYRIGHT_YEAR=`date +'%Y'` fi ++++++ reproducible-dist-id.patch ++++++ # Take the build identification date from SOURCE_DATE_EPOCH # # IT_GET_LSB_DATA builds DIST_ID from the wall clock. In the OBS build root # lsb_release is not installed, so it takes the fallback branch and yields # "Custom build (Tue Jun 9 15:33:30 UTC 2026)". That string is compiled into # libjvm.so, and libjvm.so's version string is in turn recorded in the CDS # archive, so both files differ between two builds. # # Compute the date once, honouring SOURCE_DATE_EPOCH, and use it in both # branches that need one. The shape of the string is unchanged. # --- icedtea-3.39.0/acinclude.m4 2026-04-28 23:59:50.418989522 +0200 +++ icedtea-3.39.0/acinclude.m4 2026-07-29 16:44:55.559633336 +0200 @@ -1242,16 +1242,21 @@ [ AC_REQUIRE([IT_GET_PKGVERSION]) AC_MSG_CHECKING([build identification]) +if test -n "$SOURCE_DATE_EPOCH"; then + it_build_date="$(date --utc --date=@$SOURCE_DATE_EPOCH)" +else + it_build_date="$(date)" +fi if test -n "$LSB_RELEASE"; then lsb_info="$($LSB_RELEASE -ds | sed 's/^"//;s/"$//')" if test "x$PKGVERSION" = "xnone"; then - DIST_ID="Built on $lsb_info ($(date))" + DIST_ID="Built on $lsb_info ($it_build_date)" else DIST_ID="$lsb_info, package $PKGVERSION" fi DIST_NAME="$($LSB_RELEASE -is | sed 's/^"//;s/"$//')" else - DIST_ID="Custom build ($(date))" + DIST_ID="Custom build ($it_build_date)" DIST_NAME="$build_os" fi AC_MSG_RESULT([${DIST_ID}]) ++++++ reproducible-generated-source-dates.patch ++++++ # Use SOURCE_DATE_EPOCH for dates written into generated sources # # Three build tools stamp the current date into the sources they generate, so # the result depends on when the build runs, and all three end up in the # shipped src.zip. # # - CopyrightHeaders.getYear() in the CLDR converter used the current year, # which puts "Copyright (c) 2012, 2026" into one build and "2012, 2027" # into the next. # # - GenerateCharacter wrote "This file was generated AUTOMATICALLY from a # template file <full timestamp>" into the CharacterData*.java files. # # - EquivMapsGenerator did the same as the CLDR converter for the copyright # header of sun/util/locale/LocaleEquivalentMaps.java. # # Take the date from SOURCE_DATE_EPOCH when it is set, and keep the current # time otherwise. The year is still computed in America/Los_Angeles, as # before, so only the instant changes. # # Backported from the same fix made for java-11-openjdk. # diff --git a/openjdk/jdk/make/src/classes/build/tools/cldrconverter/CopyrightHeaders.java b/openjdk/jdk/make/src/classes/build/tools/cldrconverter/CopyrightHeaders.java index 1ea0186bc03..7c349ec0c07 100644 --- a/openjdk/jdk/make/src/classes/build/tools/cldrconverter/CopyrightHeaders.java +++ b/openjdk/jdk/make/src/classes/build/tools/cldrconverter/CopyrightHeaders.java @@ -145,8 +145,17 @@ class CopyrightHeaders { } private static int getYear() { - return new GregorianCalendar(TimeZone.getTimeZone("America/Los_Angeles"), - Locale.US).get(Calendar.YEAR); + GregorianCalendar cal = + new GregorianCalendar(TimeZone.getTimeZone("America/Los_Angeles"), + Locale.US); + String sourceDateEpoch = System.getenv("SOURCE_DATE_EPOCH"); + if (sourceDateEpoch != null && !sourceDateEpoch.isEmpty()) { + try { + cal.setTimeInMillis(Long.parseLong(sourceDateEpoch.trim()) * 1000L); + } catch (NumberFormatException e) { + } + } + return cal.get(Calendar.YEAR); } // no instantiation diff --git a/openjdk/jdk/make/src/classes/build/tools/generatecharacter/GenerateCharacter.java b/openjdk/jdk/make/src/classes/build/tools/generatecharacter/GenerateCharacter.java index 83973ef07c4..dbc4230fb51 100644 --- a/openjdk/jdk/make/src/classes/build/tools/generatecharacter/GenerateCharacter.java +++ b/openjdk/jdk/make/src/classes/build/tools/generatecharacter/GenerateCharacter.java @@ -686,6 +686,17 @@ OUTER: for (int i = 0; i < n; i += m) { * @see GenerateCharacter#replaceCommand */ + static java.util.Date generationDate() { + String sourceDateEpoch = System.getenv("SOURCE_DATE_EPOCH"); + if (sourceDateEpoch != null && !sourceDateEpoch.isEmpty()) { + try { + return new java.util.Date(Long.parseLong(sourceDateEpoch.trim()) * 1000L); + } catch (NumberFormatException e) { + } + } + return new java.util.Date(); + } + static void generateCharacterClass(String theTemplateFileName, String theOutputFileName) throws FileNotFoundException, IOException { @@ -693,7 +704,7 @@ OUTER: for (int i = 0; i < n; i += m) { PrintWriter out = new PrintWriter(new BufferedWriter(new FileWriter(theOutputFileName))); out.println(commentStart + " This file was generated AUTOMATICALLY from a template file " + - new java.util.Date() + commentEnd); + generationDate() + commentEnd); int marklen = commandMarker.length(); LOOP: while(true) { try { diff --git a/openjdk/jdk/make/src/classes/build/tools/generatelsrequivmaps/EquivMapsGenerator.java b/openjdk/jdk/make/src/classes/build/tools/generatelsrequivmaps/EquivMapsGenerator.java index ba83f92a183..7e732752697 100644 --- a/openjdk/jdk/make/src/classes/build/tools/generatelsrequivmaps/EquivMapsGenerator.java +++ b/openjdk/jdk/make/src/classes/build/tools/generatelsrequivmaps/EquivMapsGenerator.java @@ -226,9 +226,16 @@ public class EquivMapsGenerator { + "}"; private static String getOpenJDKCopyright() { - int year = Calendar.getInstance(TimeZone - .getTimeZone("America/Los_Angeles")).get(Calendar.YEAR); - return String.format(Locale.US, COPYRIGHT, year); + Calendar cal = Calendar.getInstance(TimeZone + .getTimeZone("America/Los_Angeles")); + String sourceDateEpoch = System.getenv("SOURCE_DATE_EPOCH"); + if (sourceDateEpoch != null && !sourceDateEpoch.isEmpty()) { + try { + cal.setTimeInMillis(Long.parseLong(sourceDateEpoch.trim()) * 1000L); + } catch (NumberFormatException e) { + } + } + return String.format(Locale.US, COPYRIGHT, cal.get(Calendar.YEAR)); } /** ++++++ reproducible-generated-timestamps.patch ++++++ # Drop build timestamps from generated javadoc and CORBA output # # Three more places stamp the wall clock into shipped files: # # - HtmlDocletWriter emits <meta name="date" content="..."> into every # javadoc page. This is the same concern as the "Generated by javadoc" # comment that reproducible-javadoc-timestamp.patch already suppresses, # so suppress it the same way, when SOURCE_DATE_EPOCH is set. On its own # it accounted for all 11969 differing HTML files. # # - MC.java writes "Generated from input file <f> on <date>" into the CORBA # log wrapper sources. # # - The IDL compiler writes the generation time into the prolog of every # file it generates. # # The two CORBA generators just drop the date; it carries no information the # build does not already have, and both feed src.zip - 525 of its entries # differed between two builds because of them. # diff --git a/openjdk/corba/src/share/classes/com/sun/tools/corba/se/idl/toJavaPortable/Util.java b/openjdk/corba/src/share/classes/com/sun/tools/corba/se/idl/toJavaPortable/Util.java index 7e0d8373dab..e271bf7820e 100644 --- a/openjdk/corba/src/share/classes/com/sun/tools/corba/se/idl/toJavaPortable/Util.java +++ b/openjdk/corba/src/share/classes/com/sun/tools/corba/se/idl/toJavaPortable/Util.java @@ -68,11 +68,8 @@ package com.sun.tools.corba.se.idl.toJavaPortable; import java.io.File; import java.io.PrintWriter; import java.math.BigInteger; -import java.text.DateFormat; -import java.util.Date; import java.util.Enumeration; import java.util.Hashtable; -import java.util.Locale; import java.util.Vector; import com.sun.tools.corba.se.idl.ConstEntry; @@ -1131,26 +1128,6 @@ public class Util extends com.sun.tools.corba.se.idl.Util //stream.println ("* " + Util.getMessage ("toJavaProlog2", Compile.compiler.arguments.file)); stream.println ("* " + Util.getMessage ("toJavaProlog2", Compile.compiler.arguments.file.replace (File.separatorChar, '/'))); - /////////////// - // This SHOULD work, but there's a bug in the JDK. - // stream.println ("* " + DateFormat.getDateTimeInstance (DateFormat.FULL, DateFormat.FULL, Locale.getDefault ()).format (new Date ())); - // This gets around the bug: - - DateFormat formatter = DateFormat.getDateTimeInstance (DateFormat.FULL, DateFormat.FULL, Locale.getDefault ()); - - // Japanese-specific workaround. JDK bug 4069784 being repaired by JavaSoft. - // Keep this transient solution until bug fix is reported.cd . - - if (Locale.getDefault () == Locale.JAPAN) - formatter.setTimeZone (java.util.TimeZone.getTimeZone ("JST")); - else - formatter.setTimeZone (java.util.TimeZone.getDefault ()); - - stream.println ("* " + formatter.format (new Date ())); - - // <daz> - /////////////// - stream.println ("*/"); stream.println (); } // writeProlog diff --git a/openjdk/corba/src/share/classes/com/sun/tools/corba/se/logutil/MC.java b/openjdk/corba/src/share/classes/com/sun/tools/corba/se/logutil/MC.java index b2fd98a5205..007827f5e05 100644 --- a/openjdk/corba/src/share/classes/com/sun/tools/corba/se/logutil/MC.java +++ b/openjdk/corba/src/share/classes/com/sun/tools/corba/se/logutil/MC.java @@ -30,7 +30,6 @@ import java.io.FileOutputStream; import java.io.IOException; import java.util.Arrays; -import java.util.Date; import java.util.Formatter; import java.util.List; import java.util.Queue; @@ -154,7 +153,7 @@ public class MC { groupName); pw.println("//"); pw.printMsg("// Generated by MC.java version @, DO NOT EDIT BY HAND!", VERSION); - pw.printMsg("// Generated from input file @ on @", inFile, new Date()); + pw.printMsg("// Generated from input file @", inFile); pw.println(); } diff --git a/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/HtmlDocletWriter.java b/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/HtmlDocletWriter.java index 76229a1f7b7..baa1cd37659 100644 --- a/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/HtmlDocletWriter.java +++ b/openjdk/langtools/src/share/classes/com/sun/tools/doclets/formats/html/HtmlDocletWriter.java @@ -400,7 +400,7 @@ public class HtmlDocletWriter extends HtmlDocWriter { head.addContent(meta); } head.addContent(getTitle()); - if (!configuration.notimestamp) { + if (!configuration.notimestamp && System.getenv("SOURCE_DATE_EPOCH") == null) { SimpleDateFormat dateFormat = new SimpleDateFormat("yyyy-MM-dd"); Content meta = HtmlTree.META("date", dateFormat.format(new Date())); head.addContent(meta); ++++++ reproducible-jvm-cfg-order.patch ++++++ # Append the extra VM entries to jvm.cfg in a fixed order # # stamps/add-cacao, stamps/add-jamvm and stamps/add-zero each append a line to # the same $(BUILD_JRE_ARCH_DIR)/jvm.cfg, and all three are independent # prerequisites of stamps/icedtea-stage2. Under a parallel make they run in # whatever order the recipes finish in, so the shipped jvm.cfg differs between # a 1-core and a many-core build - "-jamvm ERROR" showed up after "-shark # ERROR" in one build and before "-zero ERROR" in the other. # # Chain the three stamps so the order is fixed at cacao, jamvm, zero (which # also emits the shark line). Same for the -debug variants, which have the # identical race on the debug image's jvm.cfg. # --- icedtea-3.39.0/Makefile.am 2026-04-28 23:59:50.409989500 +0200 +++ icedtea-3.39.0/Makefile.am 2026-07-29 16:46:01.460571158 +0200 @@ -1944,7 +1944,7 @@ # Targets for additional VMs -stamps/add-jamvm.stamp: stamps/icedtea.stamp stamps/jamvm.stamp +stamps/add-jamvm.stamp: stamps/icedtea.stamp stamps/jamvm.stamp stamps/add-cacao.stamp if ADD_JAMVM_BUILD mkdir -p $(BUILD_JRE_ARCH_DIR)/jamvm install -m 644 jamvm/install/lib/libjvm.so \ @@ -1962,7 +1962,7 @@ fi rm -f stamps/add-jamvm.stamp -stamps/add-jamvm-debug.stamp: stamps/icedtea-debug.stamp stamps/jamvm.stamp +stamps/add-jamvm-debug.stamp: stamps/icedtea-debug.stamp stamps/jamvm.stamp stamps/add-cacao-debug.stamp if ADD_JAMVM_BUILD mkdir -p $(BUILD_DEBUG_JRE_ARCH_DIR)/jamvm install -m 644 jamvm/install/lib/libjvm.so \ @@ -2115,7 +2115,7 @@ BUILD_JDK=false \ DISTRIBUTION_PATCHES='$(foreach p,$(DISTRIBUTION_PATCHES),$(if $(findstring cacao,$(p)),,$(if $(findstring jamvm,$(p)),,$(p))))' -stamps/add-zero.stamp: stamps/icedtea.stamp +stamps/add-zero.stamp: stamps/icedtea.stamp stamps/add-jamvm.stamp mkdir -p stamps if ADD_ZERO_BUILD mkdir -p zerovm @@ -2156,7 +2156,7 @@ fi rm -f stamps/add-zero.stamp -stamps/add-zero-debug.stamp: stamps/icedtea-debug.stamp +stamps/add-zero-debug.stamp: stamps/icedtea-debug.stamp stamps/add-jamvm-debug.stamp mkdir -p stamps if ADD_ZERO_BUILD mkdir -p zerovm ++++++ reproducible-zip-extra-fields.patch ++++++ # Pass -X to zip so archives carry no access times # # SetupZipArchive builds the demo src.zip files with InfoZIP zip, which by # default records a "UT" extra field per entry holding the file's mtime and # its access time. The access time differs between builds, and # strip-nondeterminism does not normalise it - it only rewrites the mtime, # which is why two demo src.zip files still differed after everything else # had been fixed. # # -X drops the extra attributes entirely. # diff --git a/openjdk/make/common/JavaCompilation.gmk b/openjdk/make/common/JavaCompilation.gmk index bc34720245e..ba46b2b0c52 100644 --- a/openjdk/make/common/JavaCompilation.gmk +++ b/openjdk/make/common/JavaCompilation.gmk @@ -305,7 +305,7 @@ define SetupZipArchive $$($1_ZIP) : $$($1_ALL_SRCS) $$($1_EXTRA_DEPS) $(MKDIR) -p $$(@D) $(ECHO) Updating $$($1_NAME) - $$(foreach i,$$($1_SRC),(cd $$i && $(ZIP) -qru $$@ . $$($1_ZIP_INCLUDES) $$($1_ZIP_EXCLUDES) -x \*_the.\* $$(addprefix -x$(SPACE),$$(patsubst $$i/%,%,$$($1_EXCLUDE_FILES))) || test "$$$$?" = "12" )$$(NEWLINE)) true + $$(foreach i,$$($1_SRC),(cd $$i && $(ZIP) -qruX $$@ . $$($1_ZIP_INCLUDES) $$($1_ZIP_EXCLUDES) -x \*_the.\* $$(addprefix -x$(SPACE),$$(patsubst $$i/%,%,$$($1_EXCLUDE_FILES))) || test "$$$$?" = "12" )$$(NEWLINE)) true $(TOUCH) $$@ endef ++++++ riscv64-zero.patch ++++++ --- /var/tmp/diff_new_pack.Sl7SRA/_old 2026-08-04 23:28:27.769884700 +0200 +++ /var/tmp/diff_new_pack.Sl7SRA/_new 2026-08-04 23:28:27.781885124 +0200 @@ -1,6 +1,8 @@ ---- openjdk/common/autoconf/build-aux/autoconf-config.sub 2026-02-02 11:26:27.909663959 +0100 -+++ openjdk/common/autoconf/build-aux/autoconf-config.sub 2026-02-02 11:26:41.627981464 +0100 -@@ -302,6 +302,7 @@ +Index: openjdk/common/autoconf/build-aux/autoconf-config.sub +=================================================================== +--- openjdk.orig/common/autoconf/build-aux/autoconf-config.sub ++++ openjdk/common/autoconf/build-aux/autoconf-config.sub +@@ -302,6 +302,7 @@ case $basic_machine in | pdp10 | pdp11 | pj | pjl \ | powerpc | powerpc64 | powerpc64le | powerpcle | ppcbe \ | pyramid \ @@ -8,7 +10,7 @@ | score \ | sh | sh[1234] | sh[24]a | sh[23]e | sh[34]eb | sheb | shbe | shle | sh[1234]le | sh3ele \ | sh64 | sh64le \ -@@ -383,6 +384,7 @@ +@@ -383,6 +384,7 @@ case $basic_machine in | pdp10-* | pdp11-* | pj-* | pjl-* | pn-* | power-* \ | powerpc-* | powerpc64-* | powerpc64le-* | powerpcle-* | ppcbe-* \ | pyramid-* \ @@ -16,32 +18,11 @@ | romp-* | rs6000-* \ | sh-* | sh[1234]-* | sh[24]a-* | sh[23]e-* | sh[34]eb-* | sheb-* | shbe-* \ | shle-* | sh[1234]le-* | sh3ele-* | sh64-* | sh64le-* \ ---- openjdk/common/autoconf/platform.m4 2026-02-02 11:26:27.910692427 +0100 -+++ openjdk/common/autoconf/platform.m4 2026-02-02 11:26:41.629818609 +0100 -@@ -102,6 +102,12 @@ - VAR_CPU_BITS=64 - VAR_CPU_ENDIAN=little - ;; -+ riscv64) -+ VAR_CPU=riscv64 -+ VAR_CPU_ARCH=riscv -+ VAR_CPU_BITS=64 -+ VAR_CPU_ENDIAN=little -+ ;; - *) - AC_MSG_ERROR([unsupported cpu $1]) - ;; -@@ -397,6 +403,7 @@ - sparc*) ZERO_ARCHDEF=SPARC ;; - x86_64*) ZERO_ARCHDEF=AMD64 ;; - x86) ZERO_ARCHDEF=IA32 ;; -+ riscv*) ZERO_ARCHDEF=RISCV ;; - *) ZERO_ARCHDEF=$(echo "${OPENJDK_TARGET_CPU_LEGACY_LIB}" | tr a-z A-Z) - esac - AC_SUBST(ZERO_ARCHDEF) ---- openjdk/hotspot/src/os/linux/vm/os_linux.cpp 2026-02-02 11:26:27.994153937 +0100 -+++ openjdk/hotspot/src/os/linux/vm/os_linux.cpp 2026-02-02 11:28:02.905112153 +0100 -@@ -365,7 +365,7 @@ +Index: openjdk/hotspot/src/os/linux/vm/os_linux.cpp +=================================================================== +--- openjdk.orig/hotspot/src/os/linux/vm/os_linux.cpp ++++ openjdk/hotspot/src/os/linux/vm/os_linux.cpp +@@ -365,7 +365,7 @@ void os::init_system_properties_values() // 1: ... // ... // 7: The default directories, normally /lib and /usr/lib. @@ -50,32 +31,4 @@ #define DEFAULT_LIBPATH "/usr/lib64:/lib64:/lib:/usr/lib" #else #if defined(AARCH64) -@@ -1962,6 +1962,10 @@ - #define EM_LOONGARCH 258 /* LoongArch */ - #endif - -+ #ifndef EM_RISCV -+ #define EM_RISCV 243 -+ #endif -+ - static const arch_t arch_array[]={ - {EM_386, EM_386, ELFCLASS32, ELFDATA2LSB, (char*)"IA 32"}, - {EM_486, EM_386, ELFCLASS32, ELFDATA2LSB, (char*)"IA 32"}, -@@ -1985,6 +1989,7 @@ - {EM_68K, EM_68K, ELFCLASS32, ELFDATA2MSB, (char*)"M68k"}, - {EM_AARCH64, EM_AARCH64, ELFCLASS64, ELFDATA2LSB, (char*)"AARCH64"}, - {EM_LOONGARCH, EM_LOONGARCH, ELFCLASS64, ELFDATA2LSB, (char*)"LoongArch"}, -+ {EM_RISCV, EM_RISCV, ELFCLASS64, ELFDATA2LSB, (char*)"RISCV"}, - }; - - #if (defined IA32) -@@ -2019,6 +2024,8 @@ - static Elf32_Half running_arch_code=EM_AARCH64; - #elif (defined LOONGARCH64) - static Elf32_Half running_arch_code=EM_LOONGARCH; -+#elif (defined RISCV) -+ static Elf32_Half running_arch_code=EM_RISCV; - #else - #error Method os::dll_load requires that one of following is defined:\ - IA32, AMD64, IA64, __sparc, __powerpc__, ARM, S390, ALPHA, MIPS, MIPSEL, PARISC, M68K, AARCH64, LOONGARCH64 ++++++ shenandoah-git.tar.xz ++++++ /work/SRC/openSUSE:Factory/java-1_8_0-openjdk/shenandoah-git.tar.xz /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.16738/shenandoah-git.tar.xz differ: char 15, line 1
