Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package java-1_8_0-openjdk for 
openSUSE:Factory checked in at 2026-09-18 22:07:48
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/java-1_8_0-openjdk (Old)
 and      /work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "java-1_8_0-openjdk"

Fri Sep 18 22:07:48 2026 rev:118 rq:1378781 version:1.8.0.504

Changes:
--------
--- /work/SRC/openSUSE:Factory/java-1_8_0-openjdk/java-1_8_0-openjdk.changes    
2026-08-31 15:59:21.258535686 +0200
+++ 
/work/SRC/openSUSE:Factory/.java-1_8_0-openjdk.new.383539/java-1_8_0-openjdk.changes
        2026-09-18 22:08:42.002028723 +0200
@@ -1,0 +2,9 @@
+Fri Sep 18 07:44:35 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Build with all elliptical curves enabled.
+  * Fixes bsc#1280690: OpenJDK 8 fails to parse X9.62 named curves
+    generated by crypto-policies
+  * Fixes bsc#1241704: java-1_8_0-openjdk fails to use crypto
+    operations due to unknown entries in jdk.disabled.namedCurves
+
+-------------------------------------------------------------------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ java-1_8_0-openjdk.spec ++++++
--- /var/tmp/diff_new_pack.nAdDSW/_old  2026-09-18 22:08:43.716100560 +0200
+++ /var/tmp/diff_new_pack.nAdDSW/_new  2026-09-18 22:08:43.718100643 +0200
@@ -154,15 +154,11 @@
 %bcond_without bootstrap
 %bcond_with zero
 # Turn on/off some features depending on openSUSE version
-%if 0%{?suse_version} >= 1130
 %if ! %{with zero}
 %global with_systemtap 1
 %else
 %global with_systemtap 0
 %endif
-%else
-%global with_systemtap 0
-%endif
 %if %{with_systemtap}
 # Where to install systemtap tapset (links)
 # We would like these to be in a package specific subdir,
@@ -305,27 +301,14 @@
 %if %{with zero}
 BuildRequires:  libffi-devel
 %endif
-%if 0%{?suse_version} <= 1130
-BuildRequires:  xorg-x11-devel
-%else
 BuildRequires:  libX11-devel
 BuildRequires:  libXcomposite-devel
 BuildRequires:  libXi-devel
 BuildRequires:  libXinerama-devel
 BuildRequires:  libXt-devel
 BuildRequires:  libXtst-devel
-%endif
 # runtime certificates generation available in 11.3+ - bnc#596177
-%if 0%{?suse_version} >= 1130
 BuildRequires:  java-ca-certificates
-Requires(post): file
-Requires(post): java-ca-certificates
-%else
-BuildRequires:  openssl-certs
-# the certificates will converted in a prep to standard keystore file - cacerts
-# The openssl requirment seems to be necessary for build only.
-Requires:       openssl
-%endif
 %if %{with_systemtap}
 BuildRequires:  systemtap-sdt-devel
 %endif
@@ -350,6 +333,10 @@
 # java.io.FileNotFoundException: /usr/lib64/libnss3.so
 #was bnc#634793
 Requires:       mozilla-nss
+%if 0%{?suse_version} >= 1130
+Requires(posttrans): file
+Requires(posttrans): java-ca-certificates
+%endif
 # Standard JPackage base provides.
 Provides:       java-%{javaver}-headless = %{version}-%{release}
 Provides:       java-headless = %{javaver}
@@ -425,9 +412,7 @@
 # Standard JPackage javadoc provides.
 Provides:       java-%{javaver}-javadoc = %{version}-%{release}
 Provides:       java-javadoc = %{version}-%{release}
-%if 0%{?suse_version} >= 1120
 BuildArch:      noarch
-%endif
 %if %{without libalternatives}
 Requires(post): update-alternatives
 Requires(postun): update-alternatives
@@ -477,12 +462,6 @@
 export NUM_PROC=`%{_bindir}/getconf _NPROCESSORS_ONLN 2> /dev/null || :`
 export NUM_PROC=${NUM_PROC:-1}
 
-# handle zlib packages without pkg-config file
-%if 0%{?suse_version} <= 1130
-export ZLIB_CFLAGS=" "
-export ZLIB_LIBS="-L/%{_lib} -lz"
-%endif
-
 CFLAGS=$(rpm -E '%{optflags}' | sed 's/-Wall\>//')
 CFLAGS="$CFLAGS -Wno-error"
 CXXFLAGS=${CFLAGS}
@@ -510,7 +489,7 @@
         --with-pkgversion="build %{javaver}_%{updatever}-b%{buildver} 
suse-0%{?suse_version}-%{_arch}" \
         --disable-nss \
         --enable-sysconf-nss \
-        --enable-non-nss-curves \
+        --with-curves=all \
 %if %{with bootstrap}
         --enable-bootstrap \
 %else
@@ -526,10 +505,6 @@
         --enable-zero \
         --disable-jfr \
 %endif
-%if 0%{?suse_version} <= 1110
-        --disable-system-gio \
-        --disable-system-gconf \
-%endif
 %if %{with_system_lcms}
         --enable-system-lcms \
 %else
@@ -622,18 +597,6 @@
         rm -f %{buildoutputdir}images/j2sdk-image/jre/lib/security/cacerts
 fi
 
-%if 0%{?suse_version} < 1130
-# ========== a default keystore ==========
-# a cacerts generation - 11.3+ use java-ca-certificates package
-for PEM in %{_sysconfdir}/ssl/certs/*.pem; do
-    ALIAS=$(basename ${PEM} .pem)
-    awk '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/{ print $0; 
}' ${PEM} > ${ALIAS}.pem
-
-    yes | $JAVA_HOME/jre/bin/keytool -import -alias ${ALIAS} -keystore 
%{buildoutputdir}images/j2sdk-image/jre/lib/security/cacerts -storepass 
'changeit' -file ${ALIAS}.pem || :
-    rm ${ALIAS}.pem
-done
-%endif
-
 # Check debug symbols are present and can identify code
 SERVER_JVM="$JAVA_HOME/jre/lib/%{archinstall}/server/libjvm.so"
 if [ -f "$SERVER_JVM" ] ; then
@@ -847,15 +810,6 @@
 %fdupes -s %{buildroot}/%{_jvmdir}/%{sdkdir}/demo
 %fdupes -s %{buildroot}%{_javadocdir}/%{sdklnk}
 
-%if 0%{?suse_version} <= 1130
-# bnc496378 - check the size of installed cacerts
-# 32 bytes means a default empty one
-if [[ $(stat -c "%%s" %{buildroot}/%{cacerts}) == "32" ]]; then
-    echo "ERROR: Default keystore seems empty"
-    exit 1
-fi
-%endif
-
 touch %{name}.files-headless
 touch %{name}.files-devel
 
@@ -965,7 +919,6 @@
 fi
 %endif
 
-%if 0%{?suse_version} >= 1130
 %posttrans headless
 # bnc#781690#c11: don't trust user defined JAVA_HOME and use the current VM
 # XXX: this might conflict between various versions of openjdk
@@ -973,7 +926,7 @@
 
 # check if the java-cacerts is a valid keystore (bnc#781690)
 if [ X"`%{_bindir}/file --mime-type -b %{javacacerts}`" \
-    != "Xapplication/x-java-keystore;" ]; then
+    != "Xapplication/x-java-keystore" ]; then
 %if 0%{?suse_version} <= 1310
     # workaround for bnc#847952 - pre 13.1 keyring.jar attempts to load 
invalid keystore and fail on it
     rm -f "%{javacacerts}"
@@ -989,12 +942,11 @@
 # if cacerts does exists, neither does not contain/point to a
 # valid keystore (bnc#781690) ...
 if [ X"`%{_bindir}/file --mime-type -b -L %{cacerts}`" \
-    != "Xapplication/x-java-keystore;" ]; then
+    != "Xapplication/x-java-keystore" ]; then
     # bnc#727223
     rm -f %{cacerts}
     ln -s %{javacacerts} %{cacerts}
 fi
-%endif
 
 %post devel
 ext=.gz
@@ -1219,9 +1171,7 @@
 %{_jvmjardir}/%{jrelnk}
 %{_jvmprivdir}/*
 %{jvmjardir}
-%if 0%{?suse_version} <= 1130
-%config(noreplace) %{cacerts}
-%endif
+
 %config(noreplace) %{_jvmdir}/%{jredir}/lib/security/java.policy
 %config(noreplace) %{_jvmdir}/%{jredir}/lib/security/java.security
 %config(noreplace) %{_jvmdir}/%{jredir}/lib/security/blacklisted.certs

Reply via email to