# Build with new api? %if 0%{?fedora} || 0%{?rhel} > 8 %bcond_without new_api %else %bcond_with new_api %endif # Build the compat package? %bcond_without compat_pkg # Replace obsolete functions with a stub? %if %{with new_api} && %{with compat_pkg} %bcond_without enosys_stubs %else %bcond_with enosys_stubs %endif # Build the static library? %bcond_with staticlib # When we are bootstrapping, we omit the # verification of the source tarball with GnuPG. %bcond_without bootstrap # Shared object version of libcrypt. %if %{with new_api} %global soc 2 %global sol 0 %global sof 0 %global sov %{soc}.%{sol}.%{sof} %else %global soc 1 %global sol 1 %global sof 0 %global sov %{soc}.%{sol}.%{sof} %endif %if %{with compat_pkg} %global csoc 1 %global csol 1 %global csof 0 %global csov %{csoc}.%{csol}.%{csof} %endif # First version of glibc built without libcrypt. %global glibc_minver 2.28 # Minimum version of Perl needed for some build-scripts. %global perl_minver 5.14 # The libxcrypt-devel package conflicts with out-dated manuals # shipped with the man-pages packages *before* this EVR. %global man_pages_minver 4.15-3 # Need versioned requires on glibc and man-pages? %if !(0%{?fedora} || 0%{?rhel} > 9) %global trans_pkg 1 %endif # Hash methods and API supported by libcrypt. # NEVER EVER touch this, if you do NOT know what you are doing! %global hash_methods all %if %{with new_api} %global obsolete_api no %else %global obsolete_api glibc %endif %if %{with compat_pkg} %global compat_methods all %global compat_api glibc %endif # Do we replace the obsolete API functions with stubs? %if %{with enosys_stubs} %global enosys_stubs yes %else %global enosys_stubs no %endif # Needed for the distribution README file. %if 0%{?fedora} %global distname .fedora %else %if 0%{?rhel} %global distname .rhel %else %global distname .distribution %endif %endif # Needed for out-of-tree builds. %global _configure "$(realpath ../configure)" # Common configure options. %global common_configure_options \\\ --disable-failure-tokens \\\ --disable-silent-rules \\\ --enable-shared \\\ %if %{with staticlib} \ --enable-static \\\ %else \ --disable-static \\\ %endif \ --disable-valgrind \\\ --srcdir=$(realpath ..) \\\ --with-pkgconfigdir=%{_libdir}/pkgconfig # Macros for shorthand. %global _fipsdir %{_libdir}/fipscheck # Add generation of HMAC checksums of the final stripped # binaries. %%define with lazy globbing is used here # intentionally, because using %%global does not work. %define __spec_install_post \ %{?__debug_package:%{__debug_install_post}} \ %{__arch_install_post} \ %{__os_install_post} \ libdir="%{buildroot}%{_libdir}" \ fipsdir="$libdir/fipscheck" \ mkdir -p $fipsdir \ if [[ %{with compat_pkg} == 1 ]]; then \ fipshmac -d $fipsdir \\\ $libdir/libcrypt.so.%{csov} \ ln -s libcrypt.so.%{csov}.hmac \\\ $fipsdir/libcrypt.so.%{csoc}.hmac \ fi \ %{nil} # Fail linking if there are undefined symbols. # Required for proper ELF symbol versioning support. %global _ld_strict_symbol_defs 1 Name: libxcrypt-epel Version: 4.4.36 Release: 6%{?dist} Summary: Extended crypt library for descrypt, md5crypt, bcrypt, and others # For explicit license breakdown, see the # LICENSING file in the source tarball. License: LGPL-2.1-or-later AND BSD-3-Clause AND BSD-2-Clause AND BSD-2-Clause-FreeBSD AND 0BSD AND CC0-1.0 AND LicenseRef-Fedora-Public-Domain URL: https://github.com/besser82/libxcrypt Source0: %{url}/releases/download/v%{version}/libxcrypt-%{version}.tar.xz Source1: %{url}/releases/download/v%{version}/libxcrypt-%{version}.tar.xz.asc Source2: %{url}/releases/download/v%{version}/libxcrypt-gpgkey.gpg Source3: %{url}/releases/download/v%{version}/libxcrypt-%{version}.tar.xz.sha256sum Patch0: libxcrypt-configure-c99.patch # Patch 0000 - 2999: Backported patches from upstream. # Patch 3000 - 5999: Backported patches from pull requests. # Patch 6000 - 9999: Downstream patches. BuildRequires: autoconf BuildRequires: automake BuildRequires: coreutils BuildRequires: fipscheck BuildRequires: gcc %if %{without bootstrap} BuildRequires: gnupg2 %endif %if 0%{?trans_pkg} BuildRequires: glibc-devel >= %{glibc_minver} %endif BuildRequires: libtool BuildRequires: make BuildRequires: perl(:VERSION) >= %{perl_minver} BuildRequires: perl(Class::Struct) BuildRequires: perl(Cwd) BuildRequires: perl(Exporter) BuildRequires: perl(File::Spec::Functions) BuildRequires: perl(File::Temp) BuildRequires: perl(FindBin) BuildRequires: perl(if) BuildRequires: perl(IPC::Open3) BuildRequires: perl(lib) BuildRequires: perl(open) BuildRequires: perl(POSIX) BuildRequires: perl(Symbol) BuildRequires: perl(utf8) BuildRequires: perl(warnings) BuildRequires: perl-interpreter # We do not need to keep this forever. %if 0%{?trans_pkg} # Inherited from former libcrypt package. Obsoletes: libcrypt-nss < %{glibc_minver} Provides: libcrypt-nss = %{glibc_minver} Provides: libcrypt-nss%{?_isa} = %{glibc_minver} # Obsolete former libcrypt properly and provide a virtual libcrypt # package as it has been done by the former packages, which were # built by glibc before. Obsoletes: libcrypt < %{glibc_minver} Provides: libcrypt = %{glibc_minver} Provides: libcrypt%{?_isa} = %{glibc_minver} # Obsolete former libxcrypt-common properly. Obsoletes: %{name}-common < 4.3.3-4 Provides: %{name}-common = %{version}-%{release} # We need a version of glibc, that doesn't build libcrypt anymore. Requires: glibc%{?_isa} >= %{glibc_minver} %endif %if %{with new_api} && %{without compat_pkg} Obsoletes: %{name}-compat < %{version}-%{release} %endif %if 0%{?fedora} Recommends: mkpasswd %endif %description libxcrypt is a modern library for one-way hashing of passwords. It supports a wide variety of both modern and historical hashing methods: yescrypt, gost-yescrypt, scrypt, bcrypt, sha512crypt, sha256crypt, md5crypt, SunMD5, sha1crypt, NT, bsdicrypt, bigcrypt, and descrypt. It provides the traditional Unix crypt and crypt_r interfaces, as well as a set of extended interfaces pioneered by Openwall Linux, crypt_rn, crypt_ra, crypt_gensalt, crypt_gensalt_rn, and crypt_gensalt_ra. libxcrypt is intended to be used by login(1), passwd(1), and other similar programs; that is, to hash a small number of passwords during an interactive authentication dialogue with a human. It is not suitable for use in bulk password-cracking applications, or in any other situation where speed is more important than careful handling of sensitive data. However, it is intended to be fast and lightweight enough for use in servers that must field thousands of login attempts per minute. %if %{with new_api} This version of the library does not provide the legacy API functions that have been provided by glibc's libcrypt.so.1. %endif %if %{with compat_pkg} %package -n libxcrypt-compat Summary: Compatibility library providing legacy API functions %if %{without bootstrap} # For testing the glibc compatibility symbols. BuildRequires: libxcrypt-compat %endif Requires: libxcrypt%{?_isa} = %{version} %description -n libxcrypt-compat This package contains the library providing the compatibility API for applications that are linked against glibc's libxcrypt, or that are still using the unsafe and deprecated, encrypt, encrypt_r, setkey, setkey_r, and fcrypt functions, which are still required by recent versions of POSIX, the Single UNIX Specification, and various other standards. All existing binary executables linked against glibc's libcrypt should work unmodified with the library supplied by this package. %endif %prep %if %{without bootstrap} # Omitted during bootstrap. %{gpgverify} --keyring=%{SOURCE2} --signature=%{SOURCE1} --data=%{SOURCE0} %endif pushd %{_sourcedir} sha256sum -c %{SOURCE3} popd %autosetup -p 1 -n libxcrypt-%{version} # Regen Autotools. autoreconf -fiv -Wall,error %if %{with new_api} cat << EOF >> README%{distname} This version of the %{name} package ships the libcrypt.so.2 library and does not provide the legacy API functions that have been provided by glibc's libcrypt.so.1. The removed functions by name are encrypt, encrypt_r, setkey, setkey_r, and fcrypt. %if %{with compat_pkg} If you are using a third-party application that links against those functions, or that is linked against glibc's libcrypt, you may need to install the %{name}-compat package manually. All existing binary executables linked against glibc's libcrypt should work unmodified with the libcrypt.so.1 library supplied by the %{name}-compat package. %endif EOF %endif %if %{with enosys_stubs} cat << EOF >> README.posix This version of the libcrypt.so.1 library has entirely removed the functionality of the encrypt, encrypt_r, setkey, and setkey_r functions, while keeping fully binary compatibility with existing (third-party) applications possibly still using those funtions. If such an application attemps to call one of these functions, the corresponding function will indicate that it is not supported by the system in a POSIX-compliant way. For security reasons, the encrypt and encrypt_r functions will also overwrite their data-block argument with random bits. All existing binary executables linked against glibc's libcrypt should work unmodified with the provided version of the libcrypt.so.1 library in place. EOF %endif %if %{with staticlib} cat << EOF >> README.static Applications that use certain legacy APIs supplied by glibc’s libcrypt (encrypt, encrypt_r, setkey, setkey_r, and fcrypt) cannot be compiled nor linked against the supplied build of the object files provided in the static library libcrypt.a. EOF %endif %build mkdir -p %{_vpath_builddir} # Build the default system library. pushd %{_vpath_builddir} %configure \ %{common_configure_options} \ --enable-hashes=%{hash_methods} \ --enable-obsolete-api=%{obsolete_api} \ %if %{with new_api} --enable-obsolete-api-enosys=%{obsolete_api} %else --enable-obsolete-api-enosys=%{enosys_stubs} %endif %make_build %make_build test-programs popd %if %{with compat_pkg} mkdir -p %{_vpath_builddir}-compat # Build the compatibility library. pushd %{_vpath_builddir}-compat %configure \ %{common_configure_options} \ --enable-hashes=%{compat_methods} \ --enable-obsolete-api=%{compat_api} \ --enable-obsolete-api-enosys=%{enosys_stubs} %make_build %make_build test-programs popd %endif mkdir -p %{_vpath_builddir}-all_possible_tests # The configure scripts want to use -Wl,--wrap to run some # special tests, which is not compatible with LTO. %global system_lto_cflags_bak %{_lto_cflags} %define _lto_cflags %{nil} # Reset compiler flags in env. unset CFLAGS unset CXXFLAGS unset FFLAGS unset FCFLAGS unset LDFLAGS unset LT_SYS_LIBRARY_PATH # Build a library suitable for all possible tests. pushd %{_vpath_builddir}-all_possible_tests # Disable arc4random_buf on purpose, so we are able # to run test/getrandom-fallback from testsuite. %configure \ ac_cv_func_arc4random_buf=no \ %if %{with compat_pkg} %{common_configure_options} \ --enable-hashes=all \ --enable-obsolete-api=%{compat_api} \ --enable-obsolete-api-enosys=%{enosys_stubs} %else %{common_configure_options} \ --enable-hashes=%{hash_methods} \ --enable-obsolete-api=%{obsolete_api} \ %if %{with new_api} --enable-obsolete-api-enosys=%{obsolete_api} %else --enable-obsolete-api-enosys=%{enosys_stubs} %endif %endif %define _lto_cflags %{system_lto_cflags_bak} %make_build %make_build test-programs popd %install %if %{with compat_pkg} # Install the compatibility library. %make_install -C %{_vpath_builddir}-compat # Cleanup everything we do not need from the compatibility library. find %{buildroot} \ -not -type d -not -name 'libcrypt.so.%{csoc}*' -delete -print %endif # Get rid of libtool crap. find %{buildroot} -name '*.la' -delete -print # Install documentation to shared %%_pkgdocdir. install -Dpm 0644 -t %{buildroot}%{_pkgdocdir} \ README.posix %check build_dirs="%{_vpath_builddir}" %if %{with compat_pkg} build_dirs="${build_dirs} %{_vpath_builddir}-compat" %endif build_dirs="${build_dirs} %{_vpath_builddir}-all_possible_tests" for dir in ${build_dirs}; do %make_build -C ${dir} check || \ { rc=$?; echo "-----BEGIN TESTLOG: ${dir}-----"; cat ${dir}/test-suite.log; echo "-----END TESTLOG: ${dir}-----"; exit $rc; } done %if %{with compat_pkg} %ldconfig_scriptlets compat %endif %if %{with compat_pkg} %files -n libxcrypt-compat %license AUTHORS COPYING.LIB LICENSING %dir %{_fipsdir} %if %{with enosys_stubs} %doc %{_pkgdocdir}/README.posix %endif %{_fipsdir}/libcrypt.so.%{csoc}.hmac %{_fipsdir}/libcrypt.so.%{csov}.hmac %{_libdir}/libcrypt.so.%{csoc} %{_libdir}/libcrypt.so.%{csov} %endif %changelog * Wed Apr 3 2024 Michel Lind - 4.4.36-6 - Initial epel-only package, based on libxcrypt with the same EVR