From 8ac1ad5a5684a46fc2c727f1520efbd0231a18fc Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Tue, 9 May 2023 05:35:38 +0000 Subject: [PATCH] import rng-tools-6.15-3.el9 --- .rng-tools.metadata | 2 +- ...atch => 1-rt-comment-out-have-aesni.patch} | 0 ...patch => 2-rt-revert-build-randstat.patch} | 0 SOURCES/3-rt-fix-jent-define.patch | 14 ---------- SOURCES/rngd.service | 1 + SOURCES/rngd.sysconfig | 2 +- SPECS/rng-tools.spec | 26 ++++++++++++++----- 7 files changed, 22 insertions(+), 23 deletions(-) rename SOURCES/{2-rt-comment-out-have-aesni.patch => 1-rt-comment-out-have-aesni.patch} (100%) rename SOURCES/{1-rt-revert-build-randstat.patch => 2-rt-revert-build-randstat.patch} (100%) delete mode 100644 SOURCES/3-rt-fix-jent-define.patch diff --git a/.rng-tools.metadata b/.rng-tools.metadata index d5ba298..af35ae6 100644 --- a/.rng-tools.metadata +++ b/.rng-tools.metadata @@ -1 +1 @@ -79de2f603a8d5266691edd5b53efc1a7b6a02cd3 SOURCES/rng-tools-6.15.tar.gz +f8720f7aaef3f5ca0d63cf7b88d0de802a358ae0 SOURCES/rng-tools-6.15.tar.gz diff --git a/SOURCES/2-rt-comment-out-have-aesni.patch b/SOURCES/1-rt-comment-out-have-aesni.patch similarity index 100% rename from SOURCES/2-rt-comment-out-have-aesni.patch rename to SOURCES/1-rt-comment-out-have-aesni.patch diff --git a/SOURCES/1-rt-revert-build-randstat.patch b/SOURCES/2-rt-revert-build-randstat.patch similarity index 100% rename from SOURCES/1-rt-revert-build-randstat.patch rename to SOURCES/2-rt-revert-build-randstat.patch diff --git a/SOURCES/3-rt-fix-jent-define.patch b/SOURCES/3-rt-fix-jent-define.patch deleted file mode 100644 index e208c1a..0000000 --- a/SOURCES/3-rt-fix-jent-define.patch +++ /dev/null @@ -1,14 +0,0 @@ ---- configure.ac 2022-03-24 13:14:11.000000000 +0100 -+++ configure.ac.new 2022-03-24 15:58:56.187367770 +0100 -@@ -95,7 +95,10 @@ AS_IF( - [AM_CONDITIONAL([JITTER], [true]) - AC_DEFINE([HAVE_JITTER],1,[Enable JITTER]) - AC_CHECK_LIB(jitterentropy, jent_notime_settick, -- [AC_DEFINE([HAVE_JITTER_NOTIME],1,[Enable JITTER_NOTIME])], -+ [ -+ AC_DEFINE([HAVE_JITTER_NOTIME],1,[Enable JITTER_NOTIME]) -+ AC_DEFINE([JENT_CONF_ENABLE_INTERNAL_TIMER],1,[Enable JENT_CONF_ENABLE_INTERNAL_TIMER]) -+ ], - [],-lpthread)], - AC_MSG_NOTICE([No Jitterentropy library found]),-lpthread) - ], [AC_MSG_NOTICE([Disabling JITTER entropy source])] diff --git a/SOURCES/rngd.service b/SOURCES/rngd.service index 2bd9e09..ffa8901 100644 --- a/SOURCES/rngd.service +++ b/SOURCES/rngd.service @@ -1,6 +1,7 @@ [Unit] Description=Hardware RNG Entropy Gatherer Daemon ConditionVirtualization=!container +ConditionKernelCommandLine=!fips=1 # The "-f" option is required for the systemd service rngd to work with Type=simple [Service] diff --git a/SOURCES/rngd.sysconfig b/SOURCES/rngd.sysconfig index dbb6f7a..cce3c6e 100644 --- a/SOURCES/rngd.sysconfig +++ b/SOURCES/rngd.sysconfig @@ -1,3 +1,3 @@ # Optional arguments passed to rngd. See rngd(8) and # https://bugzilla.redhat.com/show_bug.cgi?id=1252175#c21 -RNGD_ARGS="--fill-watermark=0 -x pkcs11 -x nist -D daemon:daemon" +RNGD_ARGS="--fill-watermark=0 -x pkcs11 -x nist -x qrypt -D daemon:daemon" diff --git a/SPECS/rng-tools.spec b/SPECS/rng-tools.spec index ab0c5fa..119723e 100644 --- a/SPECS/rng-tools.spec +++ b/SPECS/rng-tools.spec @@ -12,7 +12,7 @@ Summary: Random number generator related utilities Name: rng-tools Version: 6.15 -Release: 1%{?dist} +Release: 3%{?dist} License: GPLv2+ URL: https://github.com/nhorman/rng-tools Source0: %{url}/archive/v%{version}/%{name}-%{version}.tar.gz @@ -22,7 +22,7 @@ Source2: rngd.sysconfig BuildRequires: gcc make binutils BuildRequires: gettext BuildRequires: systemd systemd-rpm-macros -BuildRequires: autoconf automake +BuildRequires: autoconf >= 2.57, automake >= 1.7 BuildRequires: libgcrypt-devel libcurl-devel BuildRequires: libxml2-devel openssl-devel BuildRequires: jitterentropy-devel @@ -38,11 +38,13 @@ BuildRequires: libp11-devel Requires(post): systemd Requires(preun): systemd Requires(postun): systemd -Requires: selinux-policy >= 34.1.31-2 -Patch0: 1-rt-revert-build-randstat.patch -Patch1: 2-rt-comment-out-have-aesni.patch -Patch2: 3-rt-fix-jent-define.patch +# This ensures that the selinux-policy package and all its dependencies +# are not pulled into containers and other systems that do not use SELinux. +Requires: (selinux-policy >= 34.1.31-2 if selinux-policy) + +Patch0: 1-rt-comment-out-have-aesni.patch +Patch1: 2-rt-revert-build-randstat.patch %description This is a random number generator daemon and its tools. It monitors @@ -86,7 +88,7 @@ install -D %{SOURCE2} -m0644 %{buildroot}%{_sysconfdir}/sysconfig/rngd %files %{!?_licensedir:%global license %%doc} %license COPYING -%doc AUTHORS README +%doc AUTHORS README.md %{_bindir}/rngtest %{_sbindir}/rngd %{_mandir}/man1/rngtest.1.* @@ -95,6 +97,16 @@ install -D %{SOURCE2} -m0644 %{buildroot}%{_sysconfdir}/sysconfig/rngd %config(noreplace) %attr(0644,root,root) %{_sysconfdir}/sysconfig/rngd %changelog +* Tue Dec 27 2022 Vladis Dronov - 6.15-3 +- Update to the upstream v6.15 + tip of origin/master @ cb8cc624 (bz 2156554) +- Fix a number of issues found by covscan code scanner +- Add a jitter init timeout for tests +- Add a start condition for the FIPS mode (bz 2154804) + +* Tue Oct 04 2022 Vladis Dronov - 6.15-2 +- Update to the upstream v6.15 + tip of origin/master @ 6dcc9ec2 (bz 2124605) +- Do not require selinux-policy if it is not present + * Sat Apr 16 2022 Vladis Dronov - 6.15-1 - Update to the upstream v6.15 @ 172bf0e3 (bz 2075977) - Allow rngd process to drop privileges with "-D user:group"