%global pkgname dirsrv # Exclude i686 architecture ExcludeArch: i686 %bcond bundle_jemalloc 1 %if %{with bundle_jemalloc} %global jemalloc_name jemalloc %global jemalloc_ver 5.3.0 %global __provides_exclude ^libjemalloc\\.so.*$ %endif %bcond bundle_libdb %{defined rhel} %if %{with bundle_libdb} %global libdb_version 5.3 %global libdb_base_version db-%{libdb_version}.28 %global libdb_full_version lib%{libdb_base_version}-59 %global libdb_bundle_name libdb-%{libdb_version}-389ds.so %if 0%{?fedora} >= 41 || 0%{?rhel} >= 11 # RPM 4.20 %global libdb_base_dir lib%{libdb_base_version}-build/%{libdb_base_version} %else %global libdb_base_dir %{libdb_base_version} %endif %endif %bcond repl_reports 0 %if 0%{?fedora} >= 40 && 0%{?fedora} < 44 %bcond repl_reports 1 %endif %if 0%{?fedora} >= 43 %bcond libbdb_ro 1 %else %bcond libbdb_ro 0 %endif # This is used in certain builds to help us know if it has extra features. %global variant base %global prerel .202609011317gite0d4e289a%{nil} # This enables a sanitized build. %bcond asan 0 %bcond msan 0 %bcond tsan 0 %bcond ubsan 0 %if %{with asan} || %{with msan} || %{with tsan} || %{with ubsan} %global variant base-xsan %endif # Use Clang instead of GCC %bcond clang 0 %if %{with msan} %bcond clang 1 %endif %if %{with clang} %global toolchain clang %global _lto_cflags %nil %endif # Build cockpit plugin # Enabled on Fedora and EPEL community builds. # Disabled on RHEL/CentOS Stream unless RHDS (distribution contains "dsrv"). %if 0%{?rhel} && !0%{?epel} %bcond cockpit %(echo "%{?distribution}" | grep -q dsrv && echo 1 || echo 0) %else %bcond cockpit 1 %endif # HIBP password breach checking %bcond hibp 1 %bcond usdt 1 # Perl log analyzer (logconv.pl) # Disabled on Fedora >= 46 and RHEL >= 11, use logconv.py instead %if 0%{?fedora} >= 46 || 0%{?rhel} >= 11 %bcond logconvpl 0 %else %bcond logconvpl 1 %endif # systemd support %global groupname %{pkgname}.target # Filter argparse-manpage from autogenerated package Requires %global __requires_exclude ^python.*argparse-manpage # Filter perl auto-dep from jemalloc's jeprof profiler script %global __requires_exclude_from %{_libdir}/%{pkgname}/bin/jeprof # Force to require nss version greater or equal as the version available at the build time # See bz1986327 %define dirsrv_requires_ge() %(LC_ALL="C" echo '%*' | xargs -r rpm -q --qf 'Requires: %%{name} >= %%{epoch}:%%{version}\\n' | sed -e 's/ (none):/ /' -e 's/ 0:/ /' | grep -v "is not") Summary: 389 Directory Server (%{variant}) Name: 389-ds-base Version: 3.3.0%{?prerel} Release: %{autorelease -n %{?with_asan:-e asan}}%{?dist} License: GPL-3.0-or-later WITH GPL-3.0-389-ds-base-exception AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR LGPL-2.1-or-later OR MIT) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT) AND Unicode-3.0 AND (CC-BY-4.0 AND MIT) AND (MIT OR Unlicense) AND 0BSD AND Apache-2.0 AND BSD-3-Clause AND ISC AND MIT AND MIT AND ISC AND MPL-2.0 AND Zlib URL: https://www.port389.org # BuildRequires for the main package: BuildRequires: nspr-devel BuildRequires: nss-devel >= 3.34 BuildRequires: openldap-clients BuildRequires: openldap-devel BuildRequires: lmdb-devel BuildRequires: cyrus-sasl-devel BuildRequires: icu BuildRequires: libicu-devel BuildRequires: pcre2-devel BuildRequires: cracklib-devel BuildRequires: json-c-devel BuildRequires: libxcrypt-devel BuildRequires: zlib-devel %if %{with clang} BuildRequires: libatomic BuildRequires: clang BuildRequires: compiler-rt BuildRequires: lld %else BuildRequires: gcc BuildRequires: gcc-c++ %if %{with asan} BuildRequires: libasan %endif %if %{with tsan} BuildRequires: libtsan %endif %if %{with ubsan} BuildRequires: libubsan %endif %endif %if %{without libbdb_ro} %if %{without bundle_libdb} BuildRequires: libdb-devel %endif %endif # For SNMP ldap-agent BuildRequires: net-snmp-devel BuildRequires: bzip2-devel BuildRequires: openssl-devel # For HIBP password breach checking %if %{with hibp} BuildRequires: libcurl-devel %endif # For PAM passthru auth plug-in BuildRequires: pam-devel BuildRequires: systemd-units BuildRequires: systemd-devel BuildRequires: systemd-rpm-macros %{?sysusers_requires_compat} %if %{with usdt} BuildRequires: systemtap-sdt-devel %endif BuildRequires: cargo BuildRequires: rust BuildRequires: pkgconfig BuildRequires: pkgconfig(systemd) BuildRequires: pkgconfig(krb5) BuildRequires: pkgconfig(libpcre2-8) # For autotools regeneration BuildRequires: autoconf BuildRequires: automake BuildRequires: libtool BuildRequires: make # For doxygen documentation BuildRequires: doxygen # For cmocka unit tests BuildRequires: libcmocka-devel # For lib389 BuildRequires: python%{python3_pkgversion}-devel # For cockpit %if %{with cockpit} BuildRequires: rsync BuildRequires: /usr/bin/npm BuildRequires: /usr/bin/node %endif # Runtime requires for the main package Requires: %{name}-libs = %{version}-%{release} Requires: python%{python3_pkgversion}-lib389 = %{version}-%{release} # For semanage in setup scripts Requires: policycoreutils-python-utils Requires: libsemanage-python%{python3_pkgversion} # NoNewPrivileges support in dirsrv service units requires # selinux-policy with init_nnp_daemon_domain for dirsrv_t. # See: https://bugzilla.redhat.com/show_bug.cgi?id=2457951 %if 0%{?rhel} == 10 Requires: selinux-policy >= 42.1.22-1 %endif %if 0%{?fedora} == 43 Requires: selinux-policy >= 43.7-1 %endif %if 0%{?fedora} == 44 Requires: selinux-policy >= 44.1-1 %endif # For CLI scripts Requires: openldap-clients Requires: acl # For SSL/TLS setup Requires: nss-tools %dirsrv_requires_ge nss # Mandatory LDAP SASL mechanisms Requires: cyrus-sasl-gssapi Requires: cyrus-sasl-md5 Requires: cyrus-sasl-plain # For back-ldbm %if %{with libbdb_ro} Requires: %{name}-robdb-libs = %{version}-%{release} %else %if %{without bundle_libdb} Requires: libdb %endif %endif Requires: lmdb-libs # Needed for password dictionary checks Requires: cracklib-dicts Requires: json-c # logconv.py, MIME type Requires: python3-file-magic # Picks up our systemd deps. %{?systemd_requires} # Ensure sysusers are created %{?sysusers_requires_compat} %if %{with usdt} # Optional eBPF tracer for the shipped USDT bpftrace scripts. # Use Suggests so it is not installed by default (debug-only, pulls in gcc). Suggests: bpftrace %endif Source0: %{name}-%{version}.tar.bz2 Source2: %{name}-devel.README %if %{with bundle_jemalloc} Source3: https://github.com/jemalloc/%{jemalloc_name}/releases/download/%{jemalloc_ver}/%{jemalloc_name}-%{jemalloc_ver}.tar.bz2 Source5: jemalloc-5.3.0_throw_bad_alloc.patch %endif Source4: https://fedorapeople.org/groups/389ds/libdb-5.3.28-59.tar.bz2 # To override vendor/Cargo.lock/cockpit_dist from the upstream tarball # with separately uploaded sources # uncomment and replace double percent with a single one #Source6: vendor-%%{version}-1.tar.gz #Source7: Cargo-%%{version}-1.lock #Source8: cockpit_dist-%%{version}-1.tar.bz2 ##### Bundled cargo crates list - START ##### Provides: bundled(crate(allocator-api2)) = 0.2.21 Provides: bundled(crate(anstream)) = 1.0.0 Provides: bundled(crate(anstyle)) = 1.0.14 Provides: bundled(crate(anstyle-parse)) = 1.0.0 Provides: bundled(crate(anstyle-query)) = 1.1.5 Provides: bundled(crate(anstyle-wincon)) = 3.0.11 Provides: bundled(crate(anyhow)) = 1.0.102 Provides: bundled(crate(base64)) = 0.23.1 Provides: bundled(crate(bitflags)) = 2.11.0 Provides: bundled(crate(bumpalo)) = 3.20.2 Provides: bundled(crate(byteorder)) = 1.5.0 Provides: bundled(crate(cbindgen)) = 0.29.4 Provides: bundled(crate(cc)) = 1.4.4 Provides: bundled(crate(cfg-if)) = 1.0.4 Provides: bundled(crate(clap)) = 4.6.4 Provides: bundled(crate(clap_builder)) = 4.6.2 Provides: bundled(crate(clap_lex)) = 1.1.0 Provides: bundled(crate(colorchoice)) = 1.0.5 Provides: bundled(crate(concread)) = 0.5.10 Provides: bundled(crate(crossbeam-epoch)) = 0.9.18 Provides: bundled(crate(crossbeam-queue)) = 0.3.12 Provides: bundled(crate(crossbeam-utils)) = 0.8.21 Provides: bundled(crate(equivalent)) = 1.0.2 Provides: bundled(crate(errno)) = 0.3.14 Provides: bundled(crate(fastrand)) = 2.3.0 Provides: bundled(crate(fernet)) = 0.2.2 Provides: bundled(crate(find-msvc-tools)) = 0.1.11 Provides: bundled(crate(foldhash)) = 0.2.0 Provides: bundled(crate(foreign-types)) = 0.3.2 Provides: bundled(crate(foreign-types-shared)) = 0.1.1 Provides: bundled(crate(getrandom)) = 0.4.1 Provides: bundled(crate(hashbrown)) = 0.16.1 Provides: bundled(crate(heck)) = 0.5.0 Provides: bundled(crate(id-arena)) = 2.3.0 Provides: bundled(crate(indexmap)) = 2.13.0 Provides: bundled(crate(is_terminal_polyfill)) = 1.70.2 Provides: bundled(crate(itoa)) = 1.0.17 Provides: bundled(crate(jobserver)) = 0.1.34 Provides: bundled(crate(js-sys)) = 0.3.95 Provides: bundled(crate(leb128fmt)) = 0.1.0 Provides: bundled(crate(libc)) = 0.2.189 Provides: bundled(crate(linux-raw-sys)) = 0.11.0 Provides: bundled(crate(log)) = 0.4.29 Provides: bundled(crate(lru)) = 0.16.3 Provides: bundled(crate(memchr)) = 2.8.0 Provides: bundled(crate(once_cell)) = 1.21.3 Provides: bundled(crate(once_cell_polyfill)) = 1.70.2 Provides: bundled(crate(openssl)) = 0.10.81 Provides: bundled(crate(openssl-macros)) = 0.1.1 Provides: bundled(crate(openssl-sys)) = 0.9.117 Provides: bundled(crate(paste)) = 1.0.15 Provides: bundled(crate(pin-project-lite)) = 0.2.16 Provides: bundled(crate(pkg-config)) = 0.3.32 Provides: bundled(crate(prettyplease)) = 0.2.37 Provides: bundled(crate(proc-macro2)) = 1.0.106 Provides: bundled(crate(quote)) = 1.0.44 Provides: bundled(crate(r-efi)) = 5.3.0 Provides: bundled(crate(rustix)) = 1.1.3 Provides: bundled(crate(rustversion)) = 1.0.22 Provides: bundled(crate(semver)) = 1.0.27 Provides: bundled(crate(serde)) = 1.0.228 Provides: bundled(crate(serde_core)) = 1.0.228 Provides: bundled(crate(serde_derive)) = 1.0.228 Provides: bundled(crate(serde_json)) = 1.0.149 Provides: bundled(crate(serde_spanned)) = 1.1.1 Provides: bundled(crate(shlex)) = 2.0.1 Provides: bundled(crate(smallvec)) = 1.15.1 Provides: bundled(crate(sptr)) = 0.3.2 Provides: bundled(crate(strsim)) = 0.11.1 Provides: bundled(crate(syn)) = 2.0.117 Provides: bundled(crate(tempfile)) = 3.25.0 Provides: bundled(crate(tokio)) = 1.49.0 Provides: bundled(crate(toml)) = 0.9.12+spec_1.1.0 Provides: bundled(crate(toml_datetime)) = 0.7.5+spec_1.1.0 Provides: bundled(crate(toml_parser)) = 1.1.2+spec_1.1.0 Provides: bundled(crate(toml_writer)) = 1.1.2+spec_1.1.0 Provides: bundled(crate(tracing)) = 0.1.44 Provides: bundled(crate(tracing-attributes)) = 0.1.31 Provides: bundled(crate(tracing-core)) = 0.1.36 Provides: bundled(crate(unicode-ident)) = 1.0.24 Provides: bundled(crate(unicode-xid)) = 0.2.6 Provides: bundled(crate(utf8parse)) = 0.2.2 Provides: bundled(crate(uuid)) = 1.26.0 Provides: bundled(crate(vcpkg)) = 0.2.15 Provides: bundled(crate(wasi)) = 0.11.1+wasi_snapshot_preview1 Provides: bundled(crate(wasip2)) = 1.0.2+wasi_0.2.9 Provides: bundled(crate(wasip3)) = 0.4.0+wasi_0.3.0_rc_2026_01_06 Provides: bundled(crate(wasm-bindgen)) = 0.2.118 Provides: bundled(crate(wasm-bindgen-macro)) = 0.2.118 Provides: bundled(crate(wasm-bindgen-macro-support)) = 0.2.118 Provides: bundled(crate(wasm-bindgen-shared)) = 0.2.118 Provides: bundled(crate(wasm-encoder)) = 0.244.0 Provides: bundled(crate(wasm-metadata)) = 0.244.0 Provides: bundled(crate(wasmparser)) = 0.244.0 Provides: bundled(crate(windows-link)) = 0.2.1 Provides: bundled(crate(windows-sys)) = 0.61.2 Provides: bundled(crate(winnow)) = 1.0.4 Provides: bundled(crate(wit-bindgen)) = 0.51.0 Provides: bundled(crate(wit-bindgen-core)) = 0.51.0 Provides: bundled(crate(wit-bindgen-rust)) = 0.51.0 Provides: bundled(crate(wit-bindgen-rust-macro)) = 0.51.0 Provides: bundled(crate(wit-component)) = 0.244.0 Provides: bundled(crate(wit-parser)) = 0.244.0 Provides: bundled(crate(zeroize)) = 1.8.2 Provides: bundled(crate(zeroize_derive)) = 1.4.3 Provides: bundled(crate(zmij)) = 1.0.21 Provides: bundled(npm(@fortawesome/fontawesome-common-types)) = 0.2.36 Provides: bundled(npm(@fortawesome/fontawesome-svg-core)) = 1.2.36 Provides: bundled(npm(@fortawesome/free-solid-svg-icons)) = 5.15.4 Provides: bundled(npm(@fortawesome/react-fontawesome)) = 0.2.6 Provides: bundled(npm(@patternfly/patternfly)) = 5.4.2 Provides: bundled(npm(@patternfly/react-charts)) = 7.4.9 Provides: bundled(npm(@patternfly/react-core)) = 5.4.14 Provides: bundled(npm(@patternfly/react-icons)) = 5.4.2 Provides: bundled(npm(@patternfly/react-log-viewer)) = 5.3.0 Provides: bundled(npm(@patternfly/react-styles)) = 5.4.1 Provides: bundled(npm(@patternfly/react-table)) = 5.4.16 Provides: bundled(npm(@patternfly/react-tokens)) = 5.4.1 Provides: bundled(npm(@types/d3-array)) = 3.2.2 Provides: bundled(npm(@types/d3-color)) = 3.1.3 Provides: bundled(npm(@types/d3-ease)) = 3.0.2 Provides: bundled(npm(@types/d3-interpolate)) = 3.0.4 Provides: bundled(npm(@types/d3-path)) = 3.1.1 Provides: bundled(npm(@types/d3-scale)) = 4.0.9 Provides: bundled(npm(@types/d3-shape)) = 3.1.8 Provides: bundled(npm(@types/d3-time)) = 3.0.4 Provides: bundled(npm(@types/d3-timer)) = 3.0.2 Provides: bundled(npm(@xterm/addon-canvas)) = 0.7.0 Provides: bundled(npm(@xterm/xterm)) = 5.5.0 Provides: bundled(npm(argparse)) = 1.0.10 Provides: bundled(npm(attr-accept)) = 2.2.5 Provides: bundled(npm(autolinker)) = 3.16.2 Provides: bundled(npm(core-util-is)) = 1.0.3 Provides: bundled(npm(d3-array)) = 3.2.4 Provides: bundled(npm(d3-color)) = 3.1.0 Provides: bundled(npm(d3-ease)) = 3.0.1 Provides: bundled(npm(d3-format)) = 3.1.2 Provides: bundled(npm(d3-interpolate)) = 3.0.1 Provides: bundled(npm(d3-path)) = 3.1.0 Provides: bundled(npm(d3-scale)) = 4.0.2 Provides: bundled(npm(d3-shape)) = 3.2.0 Provides: bundled(npm(d3-time)) = 3.1.0 Provides: bundled(npm(d3-time-format)) = 4.1.0 Provides: bundled(npm(d3-timer)) = 3.0.1 Provides: bundled(npm(delaunator)) = 4.0.1 Provides: bundled(npm(delaunay-find)) = 0.0.6 Provides: bundled(npm(dequal)) = 2.0.3 Provides: bundled(npm(encoding)) = 0.1.13 Provides: bundled(npm(file-selector)) = 2.1.2 Provides: bundled(npm(focus-trap)) = 7.6.2 Provides: bundled(npm(gettext-parser)) = 2.1.0 Provides: bundled(npm(hoist-non-react-statics)) = 3.3.2 Provides: bundled(npm(iconv-lite)) = 0.6.3 Provides: bundled(npm(inherits)) = 2.0.4 Provides: bundled(npm(internmap)) = 2.0.3 Provides: bundled(npm(isarray)) = 1.0.0 Provides: bundled(npm(js-sha1)) = 0.7.0 Provides: bundled(npm(js-sha256)) = 0.12.0 Provides: bundled(npm(js-tokens)) = 4.0.0 Provides: bundled(npm(json-stable-stringify-without-jsonify)) = 1.0.1 Provides: bundled(npm(json-stringify-safe)) = 5.0.1 Provides: bundled(npm(lodash)) = 4.18.1 Provides: bundled(npm(loose-envify)) = 1.4.0 Provides: bundled(npm(memoize-one)) = 5.2.1 Provides: bundled(npm(object-assign)) = 4.1.1 Provides: bundled(npm(prettier)) = 3.9.6 Provides: bundled(npm(process-nextick-args)) = 2.0.1 Provides: bundled(npm(prop-types)) = 15.8.1 Provides: bundled(npm(react)) = 18.3.1 Provides: bundled(npm(react-dom)) = 18.3.1 Provides: bundled(npm(react-dropzone)) = 14.4.1 Provides: bundled(npm(react-fast-compare)) = 3.2.2 Provides: bundled(npm(react-is)) = 16.13.1 Provides: bundled(npm(readable-stream)) = 2.3.8 Provides: bundled(npm(remarkable)) = 2.0.1 Provides: bundled(npm(safe-buffer)) = 5.2.1 Provides: bundled(npm(safer-buffer)) = 2.1.2 Provides: bundled(npm(scheduler)) = 0.23.2 Provides: bundled(npm(sprintf-js)) = 1.0.3 Provides: bundled(npm(string_decoder)) = 1.1.1 Provides: bundled(npm(tabbable)) = 6.5.0 Provides: bundled(npm(throttle-debounce)) = 5.0.2 Provides: bundled(npm(tslib)) = 2.8.1 Provides: bundled(npm(util-deprecate)) = 1.0.2 Provides: bundled(npm(uuid)) = 14.0.2 Provides: bundled(npm(victory-area)) = 37.3.6 Provides: bundled(npm(victory-axis)) = 37.3.6 Provides: bundled(npm(victory-bar)) = 37.3.6 Provides: bundled(npm(victory-box-plot)) = 37.3.6 Provides: bundled(npm(victory-brush-container)) = 37.3.6 Provides: bundled(npm(victory-chart)) = 37.3.6 Provides: bundled(npm(victory-core)) = 37.3.6 Provides: bundled(npm(victory-create-container)) = 37.3.6 Provides: bundled(npm(victory-cursor-container)) = 37.3.6 Provides: bundled(npm(victory-group)) = 37.3.6 Provides: bundled(npm(victory-legend)) = 37.3.6 Provides: bundled(npm(victory-line)) = 37.3.6 Provides: bundled(npm(victory-pie)) = 37.3.6 Provides: bundled(npm(victory-polar-axis)) = 37.3.6 Provides: bundled(npm(victory-scatter)) = 37.3.6 Provides: bundled(npm(victory-selection-container)) = 37.3.6 Provides: bundled(npm(victory-shared-events)) = 37.3.6 Provides: bundled(npm(victory-stack)) = 37.3.6 Provides: bundled(npm(victory-tooltip)) = 37.3.6 Provides: bundled(npm(victory-vendor)) = 37.3.6 Provides: bundled(npm(victory-voronoi-container)) = 37.3.6 Provides: bundled(npm(victory-zoom-container)) = 37.3.6 ##### Bundled cargo crates list - END ##### %description 389 Directory Server is an LDAPv3 compliant server. The base package includes the LDAP server and command line utilities for server administration. %if %{with asan} WARNING! This build is linked to Address Sanitisation libraries. This probably isn't what you want. Please contact support immediately. Please see http://seclists.org/oss-sec/2016/q1/363 for more information. %endif %if %{with libbdb_ro} %package robdb-libs Summary: Read-only Berkeley Database Library License: GPL-3.0-or-later WITH GPL-3.0-389-ds-base-exception AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR LGPL-2.1-or-later OR MIT) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT) AND Unicode-3.0 AND (CC-BY-4.0 AND MIT) AND (MIT OR Unlicense) AND 0BSD AND Apache-2.0 AND BSD-3-Clause AND ISC AND MIT AND MIT AND ISC AND MPL-2.0 AND Zlib %description robdb-libs The %{name}-robdb-lib package contains a library derived from rpm project (https://github.com/rpm-software-management/rpm) that provides some basic functions to search and read Berkeley Database records %endif %package libs Summary: Core libraries for 389 Directory Server (%{variant}) %dirsrv_requires_ge nss Requires: nspr Requires: openldap Requires: systemd-libs # SASL Requires: cyrus-sasl-lib # Kerberos Requires: krb5-libs %if %{with clang} Requires: llvm Requires: compiler-rt %else %if %{with asan} Requires: libasan %endif %if %{with tsan} Requires: libtsan %endif %if %{with ubsan} Requires: libubsan %endif %endif %description libs Core libraries for the 389 Directory Server base package. These libraries are used by the main package and the -devel package. This allows the -devel package to be installed with just the -libs package and without the main package. %package devel Summary: Development libraries for 389 Directory Server (%{variant}) Requires: %{name}-libs = %{version}-%{release} Requires: pkgconfig Requires: nspr-devel Requires: nss-devel >= 3.34 Requires: openldap-devel # For systemd headers Requires: systemd-libs %description devel Development Libraries and headers for the 389 Directory Server base package. %package snmp Summary: SNMP Agent for 389 Directory Server Requires: %{name} = %{version}-%{release} %description snmp SNMP Agent for the 389 Directory Server base package. %if %{with logconvpl} %package logconv-perl Summary: Legacy Perl log analyzer for 389 Directory Server Requires: %{name} = %{version}-%{release} %if %{without libbdb_ro} %if %{without bundle_libdb} Requires: perl-DB_File %endif %endif Requires: perl-Archive-Tar Requires: perl-debugger Requires: perl-sigtrap Provides: deprecated() %description logconv-perl Legacy Perl log analyzer (logconv.pl) for 389 Directory Server. This tool is deprecated, use logconv.py instead. %endif %if %{with bundle_libdb} %package bdb Summary: Berkeley Database backend for 389 Directory Server Requires: %{name} = %{version}-%{release} Requires: %{name}-libs = %{version}-%{release} # Berkeley DB database libdb was marked as deprecated since F40: # https://fedoraproject.org/wiki/Changes/389_Directory_Server_3.0.0 # because libdb was marked as deprecated since F33 # https://fedoraproject.org/wiki/Changes/Libdb_deprecated Provides: deprecated() %description bdb Berkeley Database backend for 389 Directory Server Warning! This backend is deprecated in favor of lmdb and its support may be removed in future versions. %endif %package -n python%{python3_pkgversion}-lib389 Summary: A library for accessing, testing, and configuring the 389 Directory Server BuildArch: noarch Requires: %{name} = %{version}-%{release} Requires: openssl Requires: iproute Requires: python%{python3_pkgversion}-libselinux Recommends: bash-completion %description -n python%{python3_pkgversion}-lib389 This module contains tools and libraries for accessing, testing, and configuring the 389 Directory Server. %if %{with repl_reports} %package -n python%{python3_pkgversion}-lib389-repl-reports Summary: HTML and PNG report generation for 389 Directory Server replication monitoring tools BuildArch: noarch Requires: python%{python3_pkgversion}-lib389 = %{version}-%{release} Requires: python%{python3_pkgversion}-plotly Requires: python%{python3_pkgversion}-matplotlib %description -n python%{python3_pkgversion}-lib389-repl-reports Extended reporting capabilities for 389 Directory Server replication analysis. This package provides additional report formats (HTML and PNG) with interactive visualizations and graphs for replication lag analysis. These formats require additional dependencies and are optional - the base package supports CSV reports without this extension. %endif %if %{with cockpit} %package -n cockpit-389-ds Summary: Cockpit UI Plugin for configuring and administering the 389 Directory Server BuildArch: noarch Requires: cockpit Requires: %{name} = %{version}-%{release} Requires: python%{python3_pkgversion} Requires: python%{python3_pkgversion}-lib389 = %{version}-%{release} %description -n cockpit-389-ds A cockpit UI Plugin for configuring and administering the 389 Directory Server %endif %generate_buildrequires cd src/lib389 # Tests do not run in %%check (lib389's tests need to be fixed) # but test dependencies are needed to check import lib389.topologies %pyproject_buildrequires -g test %prep %autosetup -p1 -n %{name}-%{version} %if %{defined SOURCE6} rm -rf vendor tar xzf %{SOURCE6} %endif %if %{defined SOURCE7} cp %{SOURCE7} src/Cargo.lock %endif %if %{with bundle_jemalloc} %setup -q -n %{name}-%{version} -T -D -b 3 %endif %if %{with bundle_libdb} %setup -q -n %{name}-%{version} -T -D -b 4 %endif %if %{defined SOURCE8} # Unpack prebuilt cockpit files tar xvjf %{SOURCE8} -C src/cockpit/389-console %endif cp %{SOURCE2} README.devel %build %if %{with clang} CLANG_FLAGS="--enable-clang" %endif %if %{with asan} ASAN_FLAGS="--enable-asan --enable-debug" %endif %if %{with msan} MSAN_FLAGS="--enable-msan --enable-debug" %endif %if %{with tsan} TSAN_FLAGS="--enable-tsan --enable-debug" %endif %if %{with ubsan} UBSAN_FLAGS="--enable-ubsan --enable-debug" %endif RUST_FLAGS="--enable-rust --enable-rust-offline" %if %{without cockpit} COCKPIT_FLAGS="--disable-cockpit" %endif %if %{with usdt} USDT_FLAGS="--enable-usdt" %else USDT_FLAGS="--disable-usdt" %endif %if %{with bundle_jemalloc} # Override page size, bz #1545539 # 4K %ifarch %ix86 %arm x86_64 s390x %define lg_page --with-lg-page=12 %endif # 64K %ifarch ppc64 ppc64le aarch64 %define lg_page --with-lg-page=16 %endif # Override huge page size on aarch64 # 2M instead of 512M %ifarch aarch64 %define lg_hugepage --with-lg-hugepage=21 %endif # Build jemalloc pushd ../%{jemalloc_name}-%{jemalloc_ver} patch -p1 -F3 < %{SOURCE5} %configure \ --libdir=%{_libdir}/%{pkgname}/lib \ --bindir=%{_libdir}/%{pkgname}/bin \ --enable-prof %{lg_page} %{lg_hugepage} %make_build popd %endif # Build custom libdb package %if %{with bundle_libdb} mkdir -p ../%{libdb_base_version} pushd ../%{libdb_base_version} tar -xjf %{_topdir}/SOURCES/%{libdb_full_version}.tar.bz2 mv %{libdb_full_version} SOURCES %if 0%{?fedora} sed -i -e '/^CFLAGS=/s/-fno-strict-aliasing/& -std=gnu99/' %{_builddir}/%{name}-%{version}/rpm/bundle-libdb.spec.in %endif rpmbuild --define "_topdir $PWD" -bc %{_builddir}/%{name}-%{version}/rpm/bundle-libdb.spec.in popd %endif # Rebuild autotools artifacts autoreconf -fiv %configure \ %if %{with libbdb_ro} --with-libbdb-ro \ %else --without-libbdb-ro \ %endif %if %{with bundle_libdb} --with-bundle-libdb=%{_builddir}/%{libdb_base_version}/BUILD/%{libdb_base_dir}/dist/dist-tls \ %endif --with-selinux \ --with-systemd \ $ASAN_FLAGS $MSAN_FLAGS $TSAN_FLAGS $UBSAN_FLAGS $RUST_FLAGS $CLANG_FLAGS $COCKPIT_FLAGS $USDT_FLAGS \ --with-libldap-r=no \ %if %{with hibp} --enable-hibp \ %endif --enable-cmocka # lib389 pushd ./src/lib389 %{python3} validate_version.py --update %pyproject_wheel popd # Generate symbolic info for debuggers export XCFLAGS="%{optflags}" %make_build %install mkdir -p %{buildroot}%{_datadir}/gdb/auto-load%{_sbindir} %if %{with cockpit} mkdir -p %{buildroot}%{_datadir}/cockpit %endif %make_install %if %{with cockpit} find %{buildroot}%{_datadir}/cockpit/389-console -type d | sed -e "s@%{buildroot}@@" | sed -e 's/^/\%dir /' > cockpit.list find %{buildroot}%{_datadir}/cockpit/389-console -type f | sed -e "s@%{buildroot}@@" >> cockpit.list %endif find %{buildroot}%{_libdir}/%{pkgname}/plugins/ -type f -iname 'lib*.so' | sed -e "s@%{buildroot}@@" > plugins.list %if %{with bundle_libdb} sed -i -e "/libback-bdb/d" plugins.list %endif # Copy in our docs from doxygen. cp -r %{_builddir}/%{name}-%{version}/man/man3 %{buildroot}/%{_mandir}/man3 # lib389 pushd src/lib389 %pyproject_install %if 0%{?fedora} <= 41 || (0%{?rhel} && 0%{?rhel} <= 10) for clitool in dsconf dscreate dsctl dsidm openldap_to_ds; do mv %{buildroot}%{_bindir}/$clitool %{buildroot}%{_sbindir}/ done %endif %pyproject_save_files -l lib389 popd # Register CLI tools for bash completion for clitool in dsconf dsctl dsidm dscreate ds-replcheck do register-python-argcomplete "${clitool}" > "${clitool}" install -p -m 0644 -D -t '%{buildroot}%{bash_completions_dir}' "${clitool}" done mkdir -p %{buildroot}/var/log/%{pkgname} mkdir -p %{buildroot}/var/lib/%{pkgname} mkdir -p %{buildroot}/var/lock/%{pkgname} \ && chmod 770 %{buildroot}/var/lock/%{pkgname} # For systemd mkdir -p %{buildroot}%{_sysconfdir}/systemd/system/%{groupname}.wants # Remove libtool and static libs rm -f %{buildroot}%{_libdir}/%{pkgname}/*.a rm -f %{buildroot}%{_libdir}/%{pkgname}/*.la rm -f %{buildroot}%{_libdir}/%{pkgname}/plugins/*.a rm -f %{buildroot}%{_libdir}/%{pkgname}/plugins/*.la rm -f %{buildroot}%{_libdir}/libsvrcore.a rm -f %{buildroot}%{_libdir}/libsvrcore.la %if %{with bundle_jemalloc} pushd ../%{jemalloc_name}-%{jemalloc_ver} make DESTDIR="%{buildroot}" install_lib install_bin cp -pa COPYING ../%{name}-%{version}/COPYING.jemalloc cp -pa README ../%{name}-%{version}/README.jemalloc popd %endif %if %{with bundle_libdb} pushd ../%{libdb_base_version} libdbbuilddir=$PWD/BUILD/%{libdb_base_dir} libdbdestdir=$PWD/../%{name}-%{version} cp -pa $libdbbuilddir/LICENSE $libdbdestdir/LICENSE.libdb cp -pa $libdbbuilddir/README $libdbdestdir/README.libdb cp -pa $libdbbuilddir/lgpl-2.1.txt $libdbdestdir/lgpl-2.1.txt.libdb cp -pa $libdbbuilddir/dist/dist-tls/.libs/%{libdb_bundle_name} %{buildroot}%{_libdir}/%{pkgname}/%{libdb_bundle_name} popd %endif %if %{with libbdb_ro} pushd lib/librobdb cp -pa COPYING %{_builddir}/%{name}-%{version}/COPYING.librobdb cp -pa COPYING.RPM %{_builddir}/%{name}-%{version}/COPYING.RPM install -m 0755 -d %{buildroot}/%{_libdir} install -m 0755 -d %{buildroot}/%{_docdir}/%{name}-robdb-libs install -m 0755 -d %{buildroot}/%{_licensedir}/%{name} install -m 0755 -d %{buildroot}/%{_licensedir}/%{name}-robdb-libs install -m 0644 $PWD/README.md %{buildroot}/%{_docdir}/%{name}-robdb-libs/README.md install -m 0644 $PWD/COPYING %{buildroot}/%{_licensedir}/%{name}-robdb-libs/COPYING install -m 0644 $PWD/COPYING.RPM %{buildroot}/%{_licensedir}/%{name}-robdb-libs/COPYING.RPM install -m 0644 $PWD/COPYING %{buildroot}/%{_licensedir}/%{name}/COPYING.librobdb install -m 0644 $PWD/COPYING.RPM %{buildroot}/%{_licensedir}/%{name}/COPYING.RPM popd %endif %check # Run cmocka unit tests %if %{with tsan} export TSAN_OPTIONS=print_stacktrace=1:second_deadlock_stack=1:history_size=7 %endif %if %{without asan} && %{without msan} if ! make DESTDIR="%{buildroot}" check; then cat ./test-suite.log && false; fi %endif # Check import for lib389 modules %pyproject_check_import -e '*.test*' %post if [ -n "$DEBUGPOSTTRANS" ] ; then output=$DEBUGPOSTTRANS else output=/dev/null fi # Reload to pick up any changes to systemd files /bin/systemctl daemon-reload >$output 2>&1 || : # Reload sysctl before restarting instances sysctl --system &> "$output"; true # Gather running instances, stop and restart them instbase="%{_sysconfdir}/%{pkgname}" instances="" ninst=0 for dir in "$instbase"/slapd-* ; do echo "dir = $dir" >> "$output" 2>&1 || : if [ ! -d "$dir" ] ; then continue ; fi case "$dir" in *.removed) continue ;; esac basename=$(basename "$dir") inst="%{pkgname}@${basename#slapd-}" echo "found instance $inst - getting status" >> "$output" 2>&1 || : if /bin/systemctl -q is-active "$inst" ; then echo "instance $inst is running - stopping for upgrade" >> "$output" 2>&1 || : instances="$instances $inst" /bin/systemctl stop "$inst" >> "$output" 2>&1 || : else echo "instance $inst is not running" >> "$output" 2>&1 || : fi ninst=$((ninst + 1)) done if [ $ninst -eq 0 ] ; then echo "no instances to upgrade" >> "$output" 2>&1 || : exit 0 fi # Restart previously running instances for inst in $instances ; do echo "starting instance $inst" >> "$output" 2>&1 || : /bin/systemctl start "$inst" >> "$output" 2>&1 || : done %preun if [ $1 -eq 0 ]; then # Final removal # remove instance specific service files/links rm -rf %{_sysconfdir}/systemd/system/%{groupname}.wants/* > /dev/null 2>&1 || : fi %postun if [ $1 = 0 ]; then # Final removal rm -rf /var/run/%{pkgname} fi %post snmp %systemd_post %{pkgname}-snmp.service %preun snmp %systemd_preun %{pkgname}-snmp.service %{groupname} %postun snmp %systemd_postun_with_restart %{pkgname}-snmp.service %files -f plugins.list %if %{with bundle_jemalloc} %doc LICENSE LICENSE.GPLv3+ LICENSE.openssl README.jemalloc %license COPYING.jemalloc %else %doc LICENSE LICENSE.GPLv3+ LICENSE.openssl %endif %dir %{_sysconfdir}/%{pkgname} %dir %{_sysconfdir}/%{pkgname}/schema %config(noreplace)%{_sysconfdir}/%{pkgname}/schema/*.ldif %dir %{_sysconfdir}/%{pkgname}/config %dir %{_sysconfdir}/systemd/system/%{groupname}.wants %{_sysusersdir}/%{name}.conf %config(noreplace)%{_sysconfdir}/%{pkgname}/config/slapd-collations.conf %config(noreplace)%{_sysconfdir}/%{pkgname}/config/certmap.conf %{_datadir}/%{pkgname} %{_datadir}/gdb/auto-load/* %{_unitdir} %{_bindir}/dbscan %{_mandir}/man1/dbscan.1.gz %{_bindir}/ds-replcheck %{_mandir}/man1/ds-replcheck.1.gz %{bash_completions_dir}/ds-replcheck %{_bindir}/ds-logpipe.py %{_mandir}/man1/ds-logpipe.py.1.gz %{_bindir}/ldclt %{_mandir}/man1/ldclt.1.gz %{_bindir}/logconv.py %{_mandir}/man1/logconv.py.1.gz %{_bindir}/pwdhash %{_mandir}/man1/pwdhash.1.gz %{_sbindir}/ns-slapd %{_mandir}/man8/ns-slapd.8.gz %{_sbindir}/openldap_to_ds %{_mandir}/man8/openldap_to_ds.8.gz %{_libexecdir}/%{pkgname}/ds_systemd_ask_password_acl %{_libexecdir}/%{pkgname}/ds_selinux_restorecon.sh %{_mandir}/man5/99user.ldif.5.gz %{_mandir}/man5/certmap.conf.5.gz %{_mandir}/man5/slapd-collations.conf.5.gz %{_mandir}/man5/dirsrv.5.gz %{_mandir}/man5/dirsrv.systemd.5.gz %{_libdir}/%{pkgname}/python %dir %{_libdir}/%{pkgname}/plugins %{_prefix}/lib/sysctl.d/* %dir %{_localstatedir}/lib/%{pkgname} %dir %{_localstatedir}/log/%{pkgname} %ghost %dir %{_localstatedir}/lock/%{pkgname} %exclude %{_sbindir}/ldap-agent* %exclude %{_mandir}/man1/ldap-agent.1.gz %exclude %{_unitdir}/%{pkgname}-snmp.service %exclude %{_bindir}/logconv.pl %exclude %{_mandir}/man1/logconv.pl.1.gz %if %{with bundle_jemalloc} %{_libdir}/%{pkgname}/lib/ %{_libdir}/%{pkgname}/bin/ %exclude %{_libdir}/%{pkgname}/bin/jemalloc-config %exclude %{_libdir}/%{pkgname}/bin/jemalloc.sh %exclude %{_libdir}/%{pkgname}/lib/libjemalloc.a %exclude %{_libdir}/%{pkgname}/lib/libjemalloc.so %exclude %{_libdir}/%{pkgname}/lib/libjemalloc_pic.a %exclude %{_libdir}/%{pkgname}/lib/pkgconfig %endif %if %{with libbdb_ro} %exclude %{_libdir}/%{pkgname}/librobdb.so %endif %files devel %doc LICENSE LICENSE.GPLv3+ LICENSE.openssl README.devel %{_mandir}/man3/* %{_includedir}/svrcore.h %{_includedir}/%{pkgname} %{_libdir}/libsvrcore.so %{_libdir}/%{pkgname}/libslapd.so %{_libdir}/%{pkgname}/libns-dshttpd.so %{_libdir}/%{pkgname}/libldaputil.so %{_libdir}/pkgconfig/svrcore.pc %{_libdir}/pkgconfig/dirsrv.pc %files libs %doc LICENSE LICENSE.GPLv3+ LICENSE.openssl README.devel %dir %{_libdir}/%{pkgname} %{_libdir}/libsvrcore.so.* %{_libdir}/%{pkgname}/libslapd.so.* %{_libdir}/%{pkgname}/libns-dshttpd.so.* %{_libdir}/%{pkgname}/libldaputil.so.* %{_libdir}/%{pkgname}/librewriters.so* %if %{with bundle_jemalloc} %{_libdir}/%{pkgname}/lib/libjemalloc.so.2 %endif %files snmp %doc LICENSE LICENSE.GPLv3+ LICENSE.openssl README.devel %config(noreplace)%{_sysconfdir}/%{pkgname}/config/ldap-agent.conf %{_sbindir}/ldap-agent* %{_mandir}/man1/ldap-agent.1.gz %{_unitdir}/%{pkgname}-snmp.service %if %{with bundle_libdb} %files bdb %doc LICENSE LICENSE.GPLv3+ README.devel LICENSE.libdb README.libdb lgpl-2.1.txt.libdb %{_libdir}/%{pkgname}/%{libdb_bundle_name} %{_libdir}/%{pkgname}/plugins/libback-bdb.so %endif %files -n python%{python3_pkgversion}-lib389 -f %{pyproject_files} %doc src/lib389/README.md %license LICENSE LICENSE.GPLv3+ # Binaries %if 0%{?fedora} >= 42 || 0%{?rhel} >= 11 %{_bindir}/dsconf %{_bindir}/dscreate %{_bindir}/dsctl %{_bindir}/dsidm %{_bindir}/openldap_to_ds %else %{_sbindir}/dsconf %{_sbindir}/dscreate %{_sbindir}/dsctl %{_sbindir}/dsidm %{_sbindir}/openldap_to_ds %endif %{_libexecdir}/%{pkgname}/dscontainer # Man pages %{_mandir}/man8/dsconf.8.gz %{_mandir}/man8/dscreate.8.gz %{_mandir}/man8/dsctl.8.gz %{_mandir}/man8/dsidm.8.gz %{_mandir}/man8/openldap_to_ds.8.gz %exclude %{_mandir}/man1 # Bash completions for scripts provided by python3-lib389 %{bash_completions_dir}/dsctl %{bash_completions_dir}/dsconf %{bash_completions_dir}/dscreate %{bash_completions_dir}/dsidm %if %{with logconvpl} %files logconv-perl %{_bindir}/logconv.pl %{_mandir}/man1/logconv.pl.1.gz %endif %if %{with repl_reports} %files -n python%{python3_pkgversion}-lib389-repl-reports # No files needed as this is just a meta-package for dependencies %endif %if %{with cockpit} %files -n cockpit-389-ds -f cockpit.list %{_datarootdir}/metainfo/389-console/org.port389.cockpit_console.metainfo.xml %doc README.md %endif %if %{with libbdb_ro} %files robdb-libs %license COPYING.librobdb COPYING.RPM %doc %{_defaultdocdir}/%{name}-robdb-libs/README.md %{_libdir}/%{pkgname}/librobdb.so %{_licensedir}/%{name}-robdb-libs/COPYING %{_licensedir}/%{name}/COPYING.RPM %{_licensedir}/%{name}/COPYING.librobdb %endif %changelog %autochangelog