Change logs for openjdk-lts source package in Eoan

  • openjdk-lts (11.0.7+10-2ubuntu2~19.10) eoan-security; urgency=medium
    
      * Backport from Focal.
    
    openjdk-lts (11.0.7+10-2ubuntu2) focal; urgency=medium
    
      * Backport the fix for 8214571 to fix Xdoclint regression.
    
    openjdk-lts (11.0.7+10-2ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.7+10-1:
      * OpenJDK 11.0.7+10 build (release).
      * Security fixes
        - JDK-8223898, CVE-2020-2754: Forward references to Nashorn
        - JDK-8223904, CVE-2020-2755: Improve Nashorn matching
        - JDK-8224541, CVE-2020-2756: Better mapping of serial ENUMs
        - JDK-8224549, CVE-2020-2757: Less Blocking Array Queues
        - JDK-8225603: Enhancement for big integers
        - JDK-8226346: Build better binary builders
        - JDK-8227467: Better class method invocations
        - JDK-8227542: Manifest improved jar headers
        - JDK-8229733: TLS message handling improvements
        - JDK-8231415, CVE-2020-2773: Better signatures in XML
        - JDK-8231785: Improved socket permissions
        - JDK-8232424, CVE-2020-2778: More constrained algorithms
        - JDK-8232581, CVE-2020-2767: Improve TLS verification
        - JDK-8233250: Better X11 rendering
        - JDK-8233410: Better Build Scripting
        - JDK-8234027: Better JCEKS key support
        - JDK-8234408, CVE-2020-2781: Improve TLS session handling
        - JDK-8234825, CVE-2020-2800: Better Headings for HTTP Servers
        - JDK-8234841, CVE-2020-2803: Enhance buffering of byte buffers
        - JDK-8235274, CVE-2020-2805: Enhance typing of methods
        - JDK-8235691, CVE-2020-2816: Enhance TLS connectivity
        - JDK-8236201, CVE-2020-2830: Better Scanner conversions
        - JDK-8238960: linux-i586 builds are inconsistent as the newly build
          jdk is not able to reserve enough space for object heap
      * Refresh patches.
      * Configure --with-jtreg=/usr/share/jtreg.
      * Enable the buildwatch script on sh4 (Adrian Glaubitz). Closes: #956728.
      * Build with -march=z13 -mtune=z15 on Ubuntu/s390x.
    
      * Sync packages with 11.0.7+10-2:
      * Backport the fix for 8228407, JVM crashes with shared archive file mismatch.
      * Enable again bootcycle build for all hotspot architectures.
      * Build again with -march=zEC12 on Ubuntu/s390x.
    
    openjdk-lts (11.0.7+9-1ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.7+9-1:
      * OpenJDK 11.0.7+9 build (early access).
      * Make autopkgtests cross-test-friendly (Steve Langasek). LP: #1861467.
      * d/tests/jtreg-autopkgtest.in: keep generated hs_err log files
        with test artifacts to improve later debug (Tiago Stürmer Daitx).
      * d/tests/jtdiff-autopkgtest.in: set default vm to correctly locate (Tiago
        Stürmer Daitx)
      * jhsdb isn't built on sh4 (Adrian Glaubitz). Closes: #951774.
    
    openjdk-lts (11.0.6+10-2ubuntu2) focal; urgency=medium
    
      [ Steve Langasek ]
      * Make autopkgtests cross-test-friendly. LP: #1861467.
    
      [ Tiago Stürmer Daitx ]
      * d/tests/jtreg-autopkgtest.in: keep generated hs_err log files
        with test artifacts to improve later debug.
      * d/tests/jtdiff-autopkgtest.in: set default vm to correctly locate
        test resuts when it defaults to zerovm.
    
    openjdk-lts (11.0.6+10-2ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.6+10-2:
      * Fix FTCBFS (Helmut Grohne). Addresses: #949460.
        - Missing Build-Depends: zlib1g-dev:native.
        - Use triplet-prefixed objcopy and strip.
      * Bump standards version.
    
     -- Tiago Stürmer Daitx <email address hidden>  Wed, 15 Apr 2020 21:12:54 +0000
  • openjdk-lts (11.0.6+10-1ubuntu1~19.10.1) eoan-security; urgency=medium
    
      * Backport from Focal.
    
    openjdk-lts (11.0.6+10-1ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.6+10-1:
      * OpenJDK 11.0.6+10 build (release).
        - S8220598: Malformed copyright year range in a few files in java.base.
        - S8224909, CVE-2020-2583: Unlink Set of LinkedHashSets.
        - S8225261: Better method resolutions.
        - S8225279: Better XRender interpolation.
        - S8226352, CVE-2020-2590: Improve Kerberos interop capabilities.
        - S8227758: More valid PKIX processing.
        - S8227816: More Colorful ICC profiles.
        - S8228548, CVE-2020-2593: Normalize normalization for all.
        - S8229728: Implement negotiation parameters.
        - S8229951, CVE-2020-2601: Better Ticket Granting Services.
        - S8230279: Improve Pack200 file reading.
        - S8230318: Better trust store usage.
        - S8230967: Improve Registry support of clients.
        - S8231139: Improved keystore support.
        - S8231422, CVE-2020-2604: Better serial filter handling.
        - S8231780, CVE-2020-2655: Better TLS messaging support.
        - S8231790: Provide better FileSystemProviders.
        - S8232419: Improve Registry registration.
        - S8234037, CVE-2020-2654: Improve Object Identifier Processing.
      * Disable zero on sparc64 (Adrian Glaubitz). Closes: #942030.
      * Make the generated character data source files reproducible (Emmanuel
        Bourg). Closes: #933339.
      * Make the generated module-info.java files reproducible (Emmanuel Bourg).
        Closes: #933342.
      * Make the generated copyright headers reproducible (Emmanuel Bourg).
        Closes: #933349.
      * Make the build user reproducible (Emmanuel Bourg). Closes: #933373.
    
    openjdk-lts (11.0.6+7-1ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.6+7-1:
        - OpenJDK 11.0.6+7 build (early access).
    
    openjdk-lts (11.0.5+10-2ubuntu1) focal; urgency=medium
    
      * Sync packages with 11.0.5+10-1:
        - OpenJDK 11.0.5+10 build (release).
      * Sync packages with 11.0.5+10-2:
        - Fix the jtreg consistency check when building without jtreg.
        - Don't call dh_strip_nondeterminism when building for older releases.
        - Fix disabling the zero build on arm64 on trusty.
      * debian/tests/control.in: mark all autopkgtests as flaky in the source
        file, not the generated file.
    
     -- Tiago Stürmer Daitx <email address hidden>  Wed, 15 Jan 2020 15:14:00 +0000
  • openjdk-lts (11.0.5+10-0ubuntu1.1) eoan-security; urgency=high
    
      * Update to 11.0.5-10.
      * Security fixes:
        - S8209901: Canonical file handling.
        - S8213429, CVE-2019-2933: Windows file handling redux.
        - S8218573, CVE-2019-2945: Better socket support.
        - S8218877: Help transform transformers.
        - S8219914: Change the environment variable for Java Access Bridge.
          logging to have a directory..
        - S8220186: Improve use of font temporary files.
        - S8220302, CVE-2019-2949: Better Kerberos ccache handling.
        - S8221497: Optional Panes in Swing.
        - S8221858, CVE-2019-2958: Build Better Processes.
        - S8222684, CVE-2019-2964: Better support for patterns.
        - S8222690, CVE-2019-2962: Better Glyph Images.
        - S8223163: Better pattern recognition.
        - S8223505, CVE-2019-2973: Better pattern compilation.
        - S8223518, CVE-2019-2975: Unexpected exception in jjs.
        - S8223886: Add in font table referene.
        - S8223892, CVE-2019-2978: Improved handling of jar files.
        - S8224025: Fix for JDK-8220302 is not complete.
        - S8224062, CVE-2019-2977: Improve String index handling.
        - S8224532, CVE-2019-2981: Better Path supports.
        - S8224915, CVE-2019-2983: Better serial attributes.
        - S8225286, CVE-2019-2987: Better rendering of native glyphs.
        - S8225292, CVE-2019-2988: Better Graphics2D drawing.
        - S8225298, CVE-2019-2989: Improve TLS connection support.
        - S8225597, CVE-2019-2992: Enhance font glyph mapping.
        - S8226765, CVE-2019-2999: Commentary on Javadoc comments.
        - S8227601: Better collection of references.
        - S8228825, CVE-2019-2894: Enhance ECDSA operations.
      * debian/tests/control: mark all autopkgtests as flaky, Depends on g++
        instead of gcc.
    
     -- Tiago Stürmer Daitx <email address hidden>  Wed, 16 Oct 2019 00:57:17 +0000
  • openjdk-lts (11.0.5+10-0ubuntu1) eoan; urgency=high
    
      * Update to 11.0.5-10.
      * Security fixes:
        - S8209901: Canonical file handling.
        - S8213429, CVE-2019-2933: Windows file handling redux.
        - S8218573, CVE-2019-2945: Better socket support.
        - S8218877: Help transform transformers.
        - S8219914: Change the environment variable for Java Access Bridge.
          logging to have a directory..
        - S8220186: Improve use of font temporary files.
        - S8220302, CVE-2019-2949: Better Kerberos ccache handling.
        - S8221497: Optional Panes in Swing.
        - S8221858, CVE-2019-2958: Build Better Processes.
        - S8222684, CVE-2019-2964: Better support for patterns.
        - S8222690, CVE-2019-2962: Better Glyph Images.
        - S8223163: Better pattern recognition.
        - S8223505, CVE-2019-2973: Better pattern compilation.
        - S8223518, CVE-2019-2975: Unexpected exception in jjs.
        - S8223886: Add in font table referene.
        - S8223892, CVE-2019-2978: Improved handling of jar files.
        - S8224025: Fix for JDK-8220302 is not complete.
        - S8224062, CVE-2019-2977: Improve String index handling.
        - S8224532, CVE-2019-2981: Better Path supports.
        - S8224915, CVE-2019-2983: Better serial attributes.
        - S8225286, CVE-2019-2987: Better rendering of native glyphs.
        - S8225292, CVE-2019-2988: Better Graphics2D drawing.
        - S8225298, CVE-2019-2989: Improve TLS connection support.
        - S8225597, CVE-2019-2992: Enhance font glyph mapping.
        - S8226765, CVE-2019-2999: Commentary on Javadoc comments.
        - S8227601: Better collection of references.
        - S8228825, CVE-2019-2894: Enhance ECDSA operations.
      * debian/tests/control: mark all autopkgtests as flaky, Depends on g++
        instead of gcc.
    
     -- Tiago Stürmer Daitx <email address hidden>  Wed, 16 Oct 2019 00:57:17 +0000
  • openjdk-lts (11.0.5+9-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.5+9-1:
        - OpenJDK 11.0.5+9 build (early access).
        - Bump standards version.
        - Use dh_strip_nondeterminism (Emmanuel Bourg). Closes: #933389.
        - Fix 8230708, server build on sparc64 (Adrian Glaubitz). Closes: #939565.
        - Fix FTBFS with DEB_BUILD_PROFILES=nocheck (Helmut Grohne). Closes: #939521.
        - Add more breaks to the openjdk-11-jre-headless package. Closes: #935624.
        - Fix debug and src symlinks. Closes: #893134, #910694, #910696.
    
     -- Matthias Klose <email address hidden>  Mon, 07 Oct 2019 11:49:08 +0200
  • openjdk-lts (11.0.5+6-1ubuntu2) eoan; urgency=medium
    
      * Don't build zero on armhf, ftbfs at least in eoan.
    
     -- Matthias Klose <email address hidden>  Thu, 05 Sep 2019 05:37:23 +0200
  • openjdk-lts (11.0.5+6-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.5+6-1:
        - OpenJDK 11.0.5+6 build (early access).
    
        [ Matthias Klose ]
        - Tighten dependency on jtreg.
        - Build using GCC 9 on recent development releases.
        - Refresh patches.
    
        [ Tiago Stürmer Daitx ]
        - Properly generate Breaks: rules for bionic (fix typo).
        - Remove libgtk-3-dev from build-deps: libgtk-3-dev is not actually
          required, package builds fine without it; libgtk2.0-0 or libgtk-3-0
          should be explicitly declared instead in bdeps and tests;
          libxrandr-dev should be explicitly added as it is required and was
          being included due to libgtk-3-dev dependency.
        - Set minimum dependency on jtreg based on testsuite requirements.
        - Fail during pre-build if installed jtreg version is lower then
          the minimum required version.
        - Improve and fix build tests and autopkgtests:
          - Depend on default-jre-headless so jtreg will use the
            JRE from /usr/default-java; remove JT_JAVA exports as it
            no longer needs to be set.
          - Update debian/tests/hotspot,jdk,langtools to ignore
            jtreg-autopkgtest.sh return code.
          - Create debian/tests/jtdiff-autopkgtest.in as it depends
            on debian/rules variables.
          - debian/tests/jtreg-autopkgtest.sh:
            + Enable retry of failed tests to trim out flaky tests.
            + Fix unbound variable.
            + Keep .jtr files from failed tests only.
          - debian/tests/jtdiff-autopkgtest.sh:
            + Fail only if an actual regression is detected.
            + Add the super-diff comparison from jtdiff.
          - debian/rules:
            + Preserve all JTreport directories in the test output
              directory.
            + Use JDK_DIR instead of JDK_TO_TEST for autopkgtest
              generation.
            + Package all .jtr files from JTwork as jtreg-autopkgtest.sh
              makes sure it contains only failing tests.
    
     -- Matthias Klose <email address hidden>  Wed, 04 Sep 2019 16:36:07 +0200
  • openjdk-lts (11.0.4+11-1ubuntu2) eoan; urgency=medium
    
      * Improve and fix build tests and autopkgtests:
        - Update debian/tests/hotspot,jdk,langtools to ignore
          jtreg-autopkgtest.sh return code.
        - Create debian/tests/jtdiff-autopkgtest.in as it depends
          on debian/rules variables.
        - debian/tests/jtreg-autopkgtest.sh:
          + Enable retry of failed tests to trim out flaky tests.
          + Fix unbound variable.
          + Force JT_JAVA otherwise jtreg will look for
            /usr/lib/jvm/default-java which might not be installed
            or be the right JVM to use.
          + Keep .jtr files from failed tests only.
        - debian/tests/jtdiff-autopkgtest.sh:
          + Fail only if an actual regression is detected.
          + Force JT_JAVA otherwise jtreg will look for
            /usr/lib/jvm/default-java which might not be installed
            or be the right JVM to use.
          + Add the super-diff comparison from jtdiff.
        - debian/rules:
          + Preserve all JTreport directories in the test output
            directory.
          + Use JDK_DIR instead of JDK_TO_TEST for autopkgtest
            generation.
          + Package all .jtr files from JTwork as jtreg-autopkgtest.sh
            makes sure it contains only failing tests.
    
     -- Tiago Stürmer Daitx <email address hidden>  Thu, 18 Jul 2019 17:53:52 +0000
  • openjdk-lts (11.0.4+11-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+11-1:
        - OpenJDK 11.0.4+11 build (release).
          - S8212328, CVE-2019-2762: Exceptional throw cases.
          - S8213431, CVE-2019-2766: Improve file protocol handling.
          - S8213432, CVE-2019-2769: Better copies of CopiesList.
          - S8216381, CVE-2019-2786: More limited privilege usage.
          - S8217563: Improve realm maintenance.
          - S8218863: Better endpoint checks.
          - S8218873: Improve JSSE endpoint checking.
          - S8218876, CVE-2019-7317: Improve PNG support options.
          - S8219775: Certificate validation improvements.
          - S8220517: Enhanced GIF support.
          - S8221345, CVE-2019-2818: Better Poly1305 support.
          - S8221518, CVE-2019-2816: Normalize normalization.
          - S8222678, CVE-2019-2821: Improve TLS negotiation.
        - Fix more build issues for Ubuntu precise builds.
        - Bump standards version.
    
     -- Matthias Klose <email address hidden>  Wed, 17 Jul 2019 02:37:32 +0200
  • openjdk-lts (11.0.4+10-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+10-1:
        - OpenJDK 11.0.4+10 build (early access).
        - Add riscv64 support for zero (Ed Nevill).
        - Fix build dependencies for Ubuntu precise builds.
        - Fix dependency generation on the libjpeg runtime. Closes: #927965.
        - Drop dependency on transitional libgl1-mesa-glx package. Closes: #930611.
    
     -- Matthias Klose <email address hidden>  Tue, 02 Jul 2019 15:08:32 +0200
  • openjdk-lts (11.0.4+9-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+9-1:
        - OpenJDK 11.0.4+9 build (early access).
        - Add another break for libequinox-osgi-java (<< 3.9.1). Closes: #931115.
    
     -- Matthias Klose <email address hidden>  Wed, 26 Jun 2019 14:02:42 +0200
  • openjdk-lts (11.0.4+8-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+8-1:
        - OpenJDK 11.0.4+8 build (early access).
        - Apply patch for JDK-8225716.
      * Remove the icedtea-sound build logic.
      * Install swing.properties into <java-home>/conf instead of <java-home>/lib.
    
     -- Matthias Klose <email address hidden>  Sat, 22 Jun 2019 18:16:21 +0200
  • openjdk-lts (11.0.4+6-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+6-1:
        - OpenJDK 11.0.4+6 build (early access).
    
     -- Matthias Klose <email address hidden>  Thu, 06 Jun 2019 09:36:22 +0200
  • openjdk-lts (11.0.4+4-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+4-1:
        - OpenJDK 11.0.4+4 build (early access).
        - Configure with --with-version-pre='ea' for upstream tags which are
          not upstream releases (has to be set manually). Not enabled during
          the buster freeze.
        - Allow to skip the bootcycle build (DEB_BUILD_OPTIONS=nobootcycle).
        - Add a watch file (Paul Wise).
        - Print some information about the host configuration before starting
          the build.
    
     -- Matthias Klose <email address hidden>  Wed, 29 May 2019 08:08:09 +0200
  • openjdk-lts (11.0.4+2-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+2-1:
        - OpenJDK 11.0.4+2 build.
        - Fix src.zip symlink. Closes: #928369.
        - Tighten dependency on ca-certificates-java. Closes: #914860.
        - Refresh patches.
    
     -- Matthias Klose <email address hidden>  Wed, 15 May 2019 01:12:09 +0200
  • openjdk-lts (11.0.4+1-1ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.4+1-1:
        - OpenJDK 11.0.4+1 build.
    
     -- Matthias Klose <email address hidden>  Mon, 06 May 2019 17:53:46 +0200
  • openjdk-lts (11.0.3+7-4ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.3+7-4:
      * Add breaks to the openjdk-11-jre-headless package:
        - For unattended upgrades: jetty9, netbeans, tomcat8, visualvm.
        - For eclipse 3.8 removal: eclipse-platform. Closes: #925071.
        - For configuration with vendor flag: libreoffice-core.
      * Install jspawnhelper.
      * Apply updates from jdk11u-dev, and remove locally applied patches:
        - 8218618: Program fails when using JDK addressed by UNC path and using
          Security Managerdefault tip.
        - 8221924: get(null) on single-entry unmodifiable Map returns null
          instead of throwing NPE.
        - 8206955: MethodHandleProxies.asInterfaceInstance does not support default
          methodsdefault tip.
        - 8221304: Problem list java/awt/FontMetrics/MaxAdvanceIsMax.java.
        - 8218854: FontMetrics.getMaxAdvance may be less than the maximum
          FontMetrics.charWidth.
        - 8214002: Cannot use italic font style if the font has embedded bitmap.
        - 8222522: Add configure options for Mac Bundle creation.
        - 8221880: Better customization for Windows RC properties FileDescription
          and ProductName.
        - 8222133: Add temporary exceptions for root certs that are due to expire
          soon.
        - 8222089: [TESTBUG] sun/security/lib/cacerts/VerifyCACerts.java fails due
          to cert within 90-day expiry window.
        - 8170494: JNI exception pending in PlainDatagramSocketImpl.c.
        - 8217879: hs_err should print more instructions in hex dump.
        - 8222410: java/nio/file/attribute/BasicFileAttributeView/UnixSocketFile
          hangs when "nc" does not accept "-U".
        - 8222397: x86_32 tests with UseSHA1Intrinsics SEGV due to garbled
          registers.
        - 8209914: javadoc search sometimes generates bad URIs.
        - 8218020: Fix version number in mesa.md 3rd party legal file.
        - 8188133: C2: Static field accesses in clinit can trigger
          deoptimizations.
        - 8215472: (zipfs) Cleanups in implementation classes of jdk.zipfs and
          tests.
        - 8211266: [TESTBUG] ZipFSTester.java failed intermittently in
          ZipFSTester.checkRead(): bound must be positive.
        - 8210899: (zipfs) ZipFileSystem.EntryOutputStreamCRC32 mistakenly set the
          crc32 value into size field.
        - 8217647: JFR: recordings on 32-bit systems unreadable.
        - 8216970: condy causes JVM crash.
        - 8222032: x86_32 fails with "wrong size of mach node" on AVX-512 machine.
        - 8221917: serviceability/sa/TestPrintMdo.java fails on 32-bit platforms.
        - 8220349: The fix done for JDK-8214253 have caused issues in JTree
          behaviour.
        - 8221833: Readability check in Symbol::is_valid not performed for some
          addresses.
        - 8220441: [PPC64] Clobber memory effect missing for memory barriers in
          atomics.
        - 8218991: s390: Add intrinsic for GHASH algorithm.
        - 8220625: tools/javac/classreader/8171132/BadConstantValue.java failed
          with "did not see expected error".
    
     -- Matthias Klose <email address hidden>  Thu, 25 Apr 2019 10:21:12 +0200
  • openjdk-lts (11.0.3+7-3ubuntu1) eoan; urgency=medium
    
      * Sync packages with 11.0.3+7-3:
      * Add breaks to the openjdk-11-jre-headless package:
        - For unattended upgrades: jetty9, netbeans, tomcat8, visualvm.
        - For eclipse 3.8 removal: eclipse-platform. Closes: #925071.
        - For configuration with vendor flag: libreoffice-core.
    
      * Apply updates from jdk11u-dev, and remove locally applied patches:
        - 8206955: MethodHandleProxies.asInterfaceInstance does not support default
          methodsdefault tip.
        - 8221304: Problem list java/awt/FontMetrics/MaxAdvanceIsMax.java.
        - 8218854: FontMetrics.getMaxAdvance may be less than the maximum
          FontMetrics.charWidth.
        - 8214002: Cannot use italic font style if the font has embedded bitmap.
        - 8222522: Add configure options for Mac Bundle creation.
        - 8221880: Better customization for Windows RC properties FileDescription
          and ProductName.
        - 8222133: Add temporary exceptions for root certs that are due to expire
          soon.
        - 8222089: [TESTBUG] sun/security/lib/cacerts/VerifyCACerts.java fails due
          to cert within 90-day expiry window.
        - 8170494: JNI exception pending in PlainDatagramSocketImpl.c.
        - 8217879: hs_err should print more instructions in hex dump.
        - 8222410: java/nio/file/attribute/BasicFileAttributeView/UnixSocketFile
          hangs when "nc" does not accept "-U".
        - 8222397: x86_32 tests with UseSHA1Intrinsics SEGV due to garbled
          registers.
        - 8209914: javadoc search sometimes generates bad URIs.
        - 8218020: Fix version number in mesa.md 3rd party legal file.
        - 8188133: C2: Static field accesses in clinit can trigger
          deoptimizations.
        - 8215472: (zipfs) Cleanups in implementation classes of jdk.zipfs and
          tests.
        - 8211266: [TESTBUG] ZipFSTester.java failed intermittently in
          ZipFSTester.checkRead(): bound must be positive.
        - 8210899: (zipfs) ZipFileSystem.EntryOutputStreamCRC32 mistakenly set the
          crc32 value into size field.
        - 8217647: JFR: recordings on 32-bit systems unreadable.
        - 8216970: condy causes JVM crash.
        - 8222032: x86_32 fails with "wrong size of mach node" on AVX-512 machine.
        - 8221917: serviceability/sa/TestPrintMdo.java fails on 32-bit platforms.
        - 8220349: The fix done for JDK-8214253 have caused issues in JTree
          behaviour.
        - 8221833: Readability check in Symbol::is_valid not performed for some
          addresses.
        - 8220441: [PPC64] Clobber memory effect missing for memory barriers in
          atomics.
        - 8218991: s390: Add intrinsic for GHASH algorithm.
        - 8220625: tools/javac/classreader/8171132/BadConstantValue.java failed
          with "did not see expected error".
    
     -- Matthias Klose <email address hidden>  Wed, 24 Apr 2019 12:37:06 +0200
  • openjdk-lts (11.0.3+7-1ubuntu2) eoan; urgency=medium
    
      * Security fixes:
        - S8211936, CVE-2019-2602: Better String parsing
        - S8218453, CVE-2019-2684: More dynamic RMI interactions
        - S8214809: CDS storage improvements
      * debian/control, debian/control.in: add breaks clause to prevent
        openjdk-11-jre-headless from being updated when jetty9, netbeans,
        tomcat8, or visualvm are being hold back in unattended-upgrades
        due to local conffiles changes.
      * Add support for automatic updates:
        - debian/watch: upstream has started releasing tarballs and signatures at
          https://openjdk-sources.osci.io/openjdk11/ which allows us to track new
          releases and check signatures by using uscan. For now it is using the
          unmodified upstream tarball while previously the use of get-orig from
          the debian/rules file would remove a few files from it - this can be
          replicated by either providing a repack script or by adding the
          exclusions directly to debian/copyright.
        - debian/upstream/signing-key.asc: public signing key used by upstream
          to sign their tarball releases.
    
     -- Tiago Stürmer Daitx <email address hidden>  Tue, 23 Apr 2019 02:17:15 +0000
  • openjdk-lts (11.0.3+7-1ubuntu1) disco; urgency=medium
    
      * Sync packages with 11.0.3+7-1:
        - OpenJDK 11.0.3+7 build.
        - Support using the Java ATK wrapper (Samuel Thibault). Closes: #900912.
          - patches/jaw-classpath.diff: Fix finding the Java ATK wrapper.
          - patches/jaw-optional.diff: Make failing to load the Java ATK wrapper
            non-fatal.
    
     -- Matthias Klose <email address hidden>  Wed, 17 Apr 2019 05:00:11 +0200
  • openjdk-lts (11.0.3+5-1ubuntu2) disco; urgency=medium
    
      * Fix configuring with the vendor flags.
    
     -- Matthias Klose <email address hidden>  Tue, 02 Apr 2019 16:42:19 +0200