public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/nss] rawhide: Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127
@ 2026-08-21 11:21
0 siblings, 0 replies; only message in thread
From: @ 2026-08-21 11:21 UTC (permalink / raw)
To: git-commits
A new commit has been pushed.
Repo : rpms/nss
Branch : rawhide
Commit : 0ce38c589b7763d26616deba12ef01f99dce9a9b
Author : Krenželok František <fkrenzel@redhat.com>
Date : 2026-08-20T14:31:52+02:00
Stats : +16/-42 in 1 file(s)
URL : https://src.fedoraproject.org/rpms/nss/c/0ce38c589b7763d26616deba12ef01f99dce9a9b?branch=rawhide
Log:
Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127
Context shifts caused by nss-3.124-fix-ed-key-storage adding opt_NoED/
opt_NoECMont/doED/doECMont after the ML-KEM entries in pk11importtest.c,
and by 3.127 upstream adding openssl-ed25519.p12 and
tools_p12_import_ed25519_private_key to tools.sh:
- pk11importtest.c hunks 1-3: extend context to include opt_NoED,
opt_NoECMont, doED, doECMont entries
- tools.sh hunk 1: add openssl-ed25519.p12 context line
- tools.sh hunk 2: remove — tools_p12_ml_dsa_import() already upstream
in 3.127
- tools.sh hunk 3: add tools_p12_import_ed25519_private_key context
line and fix indentation of added call
---
diff --git a/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch b/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
index a1c5c40..b91a1b1 100644
--- a/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
+++ b/nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch
@@ -236,29 +236,35 @@ diff --git a/cmd/certutil/keystuff.c b/cmd/certutil/keystuff.c
diff --git a/cmd/pk11importtest/pk11importtest.c b/cmd/pk11importtest/pk11importtest.c
--- a/cmd/pk11importtest/pk11importtest.c
+++ b/cmd/pk11importtest/pk11importtest.c
-@@ -217,6 +217,7 @@
+@@ -217,8 +217,9 @@
opt_NoDSA,
opt_NoDH,
opt_NoEC,
+ opt_NoMLDSA,
opt_NoMLKEM,
+ opt_NoED,
+ opt_NoECMont,
};
-
-@@ -231,6 +232,7 @@
+
+@@ -231,8 +232,9 @@
{ /* opt_NoDSA */ 'D', PR_FALSE, 0, PR_FALSE },
{ /* opt_NoDH */ 'h', PR_FALSE, 0, PR_FALSE },
{ /* opt_NoEC */ 'e', PR_FALSE, 0, PR_FALSE },
+ { /* opt_NoMLDSA */ 'm', PR_FALSE, 0, PR_FALSE },
{ /* opt_NoMLKEM */ 'K', PR_FALSE, 0, PR_FALSE },
+ { /* opt_NoED */ 'w', PR_FALSE, 0, PR_FALSE },
+ { /* opt_NoECMont */ 'g', PR_FALSE, 0, PR_FALSE },
};
-
-@@ -247,6 +249,8 @@
+
+@@ -247,8 +249,10 @@
PRBool doDSA = PR_TRUE;
PRBool doDH = PR_FALSE; /* NSS currently can't export wrapped DH keys */
PRBool doEC = PR_TRUE;
+ PRBool doMLDSA = PR_FALSE;
+ CK_ML_DSA_PARAMETER_SET_TYPE mldsaParamSet = CKP_ML_DSA_44;
PRBool doMLKEM = PR_TRUE;
+ PRBool doED = PR_TRUE;
+ PRBool doECMont = PR_TRUE;
PRBool noPub = PR_FALSE;
PQGParams *pqgParams = NULL;
@@ -305,6 +309,9 @@
@@ -414,7 +420,7 @@ diff --git a/tests/cert/cert.sh b/tests/cert/cert.sh
diff --git a/tests/tools/tools.sh b/tests/tools/tools.sh
--- a/tests/tools/tools.sh
+++ b/tests/tools/tools.sh
-@@ -128,6 +128,15 @@
+@@ -128,7 +128,16 @@
cp ${QADIR}/tools/pbmac1-invalid-bad-salt.p12 ${TOOLSDIR}/data
cp ${QADIR}/tools/pbmac1-invalid-no-length.p12 ${TOOLSDIR}/data
cp ${QADIR}/tools/corrupted_cert_bag.p12 ${TOOLSDIR}/data
@@ -427,48 +433,16 @@ diff --git a/tests/tools/tools.sh b/tests/tools/tools.sh
+ cp ${QADIR}/tools/openssl-ml-dsa-44.p12 ${TOOLSDIR}/data
+ cp ${QADIR}/tools/openssl-ml-dsa-65.p12 ${TOOLSDIR}/data
+ cp ${QADIR}/tools/openssl-ml-dsa-87.p12 ${TOOLSDIR}/data
+ cp ${QADIR}/tools/openssl-ed25519.p12 ${TOOLSDIR}/data
cp ${QADIR}/tools/openssl-ml-kem-768-seed.p12 ${TOOLSDIR}/data
cp ${QADIR}/tools/openssl-ml-kem-768-priv.p12 ${TOOLSDIR}/data
cp ${QADIR}/tools/openssl-ml-kem-768-both.p12 ${TOOLSDIR}/data
-@@ -536,6 +545,33 @@
- return $ret
- }
-
-+tools_p12_ml_dsa_import()
-+{
-+ echo "$SCRIPTNAME: Testing ml-dsa compatibility with pkcs12 --------------"
-+ for i in 44 65 87
-+ do
-+ echo "${BINDIR}/pk12util -i ${TOOLSDIR}/data/openssl-ml-dsa-$i.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1"
-+ ${BINDIR}/pk12util -i ${TOOLSDIR}/data/openssl-ml-dsa-$i.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1
-+ ret=$?
-+ html_msg $ret 0 "Importing openssl encoded ml-dsa-$i private key from PKCS#12 file"
-+ check_tmpfile
-+ for j in 'key' 'both'
-+ do
-+ echo "${BINDIR}/pk12util -i ${TOOLSDIR}/data/ietf-ml-dsa-$i-$j.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1"
-+ ${BINDIR}/pk12util -i ${TOOLSDIR}/data/ietf-ml-dsa-$i-$j.p12 -d ${P_R_COPYDIR} -k ${R_PWFILE} -W 'test' 2>&1
-+ ret=$?
-+ html_msg $ret 0 "Importing openssl encoded ml-dsa-$i private key from PKCS#12 file"
-+ check_tmpfile
-+ html_msg $ret 0 "Importing ietf sample ml-dsa-$i-$j private key from PKCS#12 file"
-+
-+ # each cert has the same issuer/sn, so we can't hold more than one in
-+ # the data base
-+ echo "${BINDIR}/certutil -F -n \"ietf ml-dsa-$i-$j sample\" -d ${P_R_COPYDIR} -f ${R_PWFILE}"
-+ ${BINDIR}/certutil -F -n "ietf ml-dsa-$i-$j sample" -d ${P_R_COPYDIR} -f ${R_PWFILE}
-+ done
-+ done
-+}
-+
- tools_p12_ml_kem_import()
- {
- echo "$SCRIPTNAME: Testing ml-kem compatibility with pkcs12 --------------"
-@@ -616,6 +652,7 @@
+@@ -616,7 +619,8 @@
tools_p12_export_with_invalid_ciphers
tools_p12_import_old_files
tools_p12_import_pbmac1_samples
-+ tools_p12_ml_dsa_import
+ tools_p12_import_ed25519_private_key
++ tools_p12_ml_dsa_import
tools_p12_ml_kem_import
if using_sql; then
tools_p12_import_rsa_pss_private_key
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-21 11:21 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-21 11:21 [rpms/nss] rawhide: Fix context in nss-3.118-ml-dsa-test-for-sign-verify-pkcs12.patch for 3.127
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox