public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/nss] rawhide: Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127
@ 2026-08-21 11:21 
  0 siblings, 0 replies; only message in thread
From:  @ 2026-08-21 11:21 UTC (permalink / raw)
  To: git-commits

            A new commit has been pushed.

            Repo   : rpms/nss
            Branch : rawhide
            Commit : 0ce38c589b7763d26616deba12ef01f99dce9a9b
            Author : Krenželok František <fkrenzel@redhat.com>
            Date   : 2026-08-20T14:31:52+02:00
            Stats  : +16/-42 in 1 file(s)
            URL    : https://src.fedoraproject.org/rpms/nss/c/0ce38c589b7763d26616deba12ef01f99dce9a9b?branch=rawhide

            Log:
            Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127

Context shifts caused by nss-3.124-fix-ed-key-storage adding opt_NoED/
opt_NoECMont/doED/doECMont after the ML-KEM entries in pk11importtest.c,
and by 3.127 upstream adding openssl-ed25519.p12 and
tools_p12_import_ed25519_private_key to tools.sh:

- pk11importtest.c hunks 1-3: extend context to include opt_NoED,
  opt_NoECMont, doED, doECMont entries
- tools.sh hunk 1: add openssl-ed25519.p12 context line
- tools.sh hunk 2: remove — tools_p12_ml_dsa_import() already upstream
  in 3.127
- tools.sh hunk 3: add tools_p12_import_ed25519_private_key context
  line and fix indentation of added call

---
diff --git a/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch b/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
index a1c5c40..b91a1b1 100644
--- a/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
+++ b/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
@@ -236,29 +236,35 @@ diff --git a/cmd/certutil/keystuff.c b/cmd/certutil/keystuff.c
 diff --git a/cmd/pk11importtest/pk11importtest.c b/cmd/pk11importtest/pk11importtest.c
 --- a/cmd/pk11importtest/pk11importtest.c
 +++ b/cmd/pk11importtest/pk11importtest.c
-@@ -217,6 +217,7 @@
+@@ -217,8 +217,9 @@
      opt_NoDSA,
      opt_NoDH,
      opt_NoEC,
 +    opt_NoMLDSA,
      opt_NoMLKEM,
+     opt_NoED,
+     opt_NoECMont,
  };
- 
-@@ -231,6 +232,7 @@
+
+@@ -231,8 +232,9 @@
      { /* opt_NoDSA            */ 'D', PR_FALSE, 0, PR_FALSE },
      { /* opt_NoDH             */ 'h', PR_FALSE, 0, PR_FALSE },
      { /* opt_NoEC             */ 'e', PR_FALSE, 0, PR_FALSE },
 +    { /* opt_NoMLDSA          */ 'm', PR_FALSE, 0, PR_FALSE },
      { /* opt_NoMLKEM          */ 'K', PR_FALSE, 0, PR_FALSE },
+     { /* opt_NoED             */ 'w', PR_FALSE, 0, PR_FALSE },
+     { /* opt_NoECMont         */ 'g', PR_FALSE, 0, PR_FALSE },
  };
- 
-@@ -247,6 +249,8 @@
+
+@@ -247,8 +249,10 @@
      PRBool doDSA = PR_TRUE;
      PRBool doDH = PR_FALSE; /* NSS currently can't export wrapped DH keys */
      PRBool doEC = PR_TRUE;
 +    PRBool doMLDSA = PR_FALSE;
 +    CK_ML_DSA_PARAMETER_SET_TYPE mldsaParamSet = CKP_ML_DSA_44;
      PRBool doMLKEM = PR_TRUE;
+     PRBool doED = PR_TRUE;
+     PRBool doECMont = PR_TRUE;
      PRBool noPub = PR_FALSE;
      PQGParams *pqgParams = NULL;
 @@ -305,6 +309,9 @@
@@ -414,7 +420,7 @@ diff --git a/tests/cert/cert.sh b/tests/cert/cert.sh
 diff --git a/tests/tools/tools.sh b/tests/tools/tools.sh
 --- a/tests/tools/tools.sh
 +++ b/tests/tools/tools.sh
-@@ -128,6 +128,15 @@
+@@ -128,7 +128,16 @@
    cp ${QADIR}/tools/pbmac1-invalid-bad-salt.p12 ${TOOLSDIR}/data
    cp ${QADIR}/tools/pbmac1-invalid-no-length.p12 ${TOOLSDIR}/data
    cp ${QADIR}/tools/corrupted_cert_bag.p12 ${TOOLSDIR}/data
@@ -427,48 +433,16 @@ diff --git a/tests/tools/tools.sh b/tests/tools/tools.sh
 +  cp ${QADIR}/tools/openssl-ml-dsa-44.p12 ${TOOLSDIR}/data
 +  cp ${QADIR}/tools/openssl-ml-dsa-65.p12 ${TOOLSDIR}/data
 +  cp ${QADIR}/tools/openssl-ml-dsa-87.p12 ${TOOLSDIR}/data
+   cp ${QADIR}/tools/openssl-ed25519.p12 ${TOOLSDIR}/data
    cp ${QADIR}/tools/openssl-ml-kem-768-seed.p12 ${TOOLSDIR}/data
    cp ${QADIR}/tools/openssl-ml-kem-768-priv.p12 ${TOOLSDIR}/data
    cp ${QADIR}/tools/openssl-ml-kem-768-both.p12 ${TOOLSDIR}/data
-@@ -536,6 +545,33 @@
-   return $ret
- }
- 
-+tools_p12_ml_dsa_import()
-+{
-+  echo "$SCRIPTNAME: Testing ml-dsa compatibility with pkcs12 --------------"
-+  for i in 44 65 87
-+  do
-+    echo "${BINDIR}/pk12util -i ${TOOLSDIR}/data/openssl-ml-dsa-$i.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1"
-+    ${BINDIR}/pk12util -i ${TOOLSDIR}/data/openssl-ml-dsa-$i.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1
-+    ret=$?
-+    html_msg $ret 0 "Importing openssl encoded ml-dsa-$i private key from PKCS#12 file"
-+    check_tmpfile
-+    for j in 'key' 'both'
-+    do
-+       echo "${BINDIR}/pk12util -i ${TOOLSDIR}/data/ietf-ml-dsa-$i-$j.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1"
-+       ${BINDIR}/pk12util -i ${TOOLSDIR}/data/ietf-ml-dsa-$i-$j.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1
-+       ret=$?
-+       html_msg $ret 0 "Importing openssl encoded ml-dsa-$i private key from PKCS#12 file"
-+       check_tmpfile
-+       html_msg $ret 0 "Importing ietf sample ml-dsa-$i-$j private key from PKCS#12 file"
-+
-+       # each cert has the same issuer/sn, so we can't hold more than one in
-+       # the data base
-+       echo "${BINDIR}/certutil -F -n \"ietf ml-dsa-$i-$j sample\" -d ${P_R_COPYDIR} -f ${R_PWFILE}"
-+       ${BINDIR}/certutil -F -n "ietf ml-dsa-$i-$j sample" -d ${P_R_COPYDIR} -f ${R_PWFILE}
-+    done
-+  done
-+}
-+
- tools_p12_ml_kem_import()
- {
-   echo "$SCRIPTNAME: Testing ml-kem compatibility with pkcs12 --------------"
-@@ -616,6 +652,7 @@
+@@ -616,7 +619,8 @@
    tools_p12_export_with_invalid_ciphers
    tools_p12_import_old_files
    tools_p12_import_pbmac1_samples
-+    tools_p12_ml_dsa_import
+   tools_p12_import_ed25519_private_key
++  tools_p12_ml_dsa_import
    tools_p12_ml_kem_import
    if using_sql; then
      tools_p12_import_rsa_pss_private_key

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-21 11:21 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-21 11:21 [rpms/nss] rawhide: Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127 

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox