%global upstream_name haproxy %global _hardened_build 1 %global source_sha256 791e1815f8af6e8b850a227a9a0a190f3d3478c9e8d38a0f51c98b7f4bfe368b Summary: Reliable, high-performance TCP/HTTP load-balancing reverse proxy Name: haproxy-lts Version: 3.4.6 Release: %autorelease License: GPL-2.0-or-later AND LGPL-2.1-or-later URL: https://www.haproxy.org/ Source0: https://www.haproxy.org/download/3.4/src/haproxy-3.4.6.tar.gz Source1: %{upstream_name}.service Source2: %{upstream_name}.cfg Source3: %{upstream_name}.logrotate Source4: %{upstream_name}.sysconfig Source5: %{upstream_name}.sysusersd Source6: halog.1 Source7: haproxy.tmpfiles BuildRequires: %{__cc} BuildRequires: libxcrypt-devel BuildRequires: lua-devel BuildRequires: make # The pkg-config version constraint avoids RPM epoch comparisons. BuildRequires: openssl-devel BuildRequires: pkgconfig(openssl) >= 3.5.2 BuildRequires: pcre2-devel BuildRequires: systemd-devel BuildRequires: systemd-rpm-macros Requires(pre): shadow-utils Recommends: logrotate %{?systemd_requires} %{?sysusers_requires_compat} Conflicts: haproxy %description HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high availability environments. Indeed, it can: - route HTTP requests depending on statically assigned cookies - spread load among several servers while assuring server persistence through the use of HTTP cookies - switch to backup servers in the event a main one fails - accept connections to special ports dedicated to service monitoring - stop accepting connections without breaking existing ones - add, modify, and delete HTTP headers in both directions - block requests matching particular patterns - report detailed status to authenticated users from a URI intercepted from the application %prep echo '%{source_sha256} %{SOURCE0}' | sha256sum --check --strict %autosetup -n %{upstream_name}-%{version} -p1 %build %make_build \ TARGET="linux-glibc" \ EXTRAVERSION="-%{release}" \ USE_PCRE2=1 \ USE_OPENSSL=1 \ USE_QUIC=1 \ USE_LUA=1 \ USE_PROMEX=1 \ USE_SYSTEMD=1 \ USE_SLZ=1 \ USE_CRYPT_H=1 \ USE_LINUX_TPROXY=1 \ USE_GETADDRINFO=1 \ CC=%{__cc} \ CFLAGS="%{build_cflags}" \ LDFLAGS="%{build_ldflags}" \ OPT_CFLAGS="" ARCH_FLAGS="" \ EXTRA="admin/halog/halog admin/iprange/iprange admin/iprange/ip6range" %install make install-bin install-man DESTDIR=%{buildroot} PREFIX=%{_prefix} SBINDIR=%{_sbindir} # Upstream installs EXTRA into SBINDIR; EL10 keeps bin and sbin separate. install --directory --mode=0755 %{buildroot}%{_bindir} install --preserve-timestamps --mode=0755 \ admin/halog/halog admin/iprange/iprange admin/iprange/ip6range \ %{buildroot}%{_bindir}/ install --preserve-timestamps --mode=0644 -D %{SOURCE1} %{buildroot}%{_unitdir}/%{upstream_name}.service install --preserve-timestamps --mode=0644 -D %{SOURCE2} %{buildroot}%{_sysconfdir}/%{upstream_name}/%{upstream_name}.cfg install --preserve-timestamps --mode=0644 -D %{SOURCE3} %{buildroot}%{_sysconfdir}/logrotate.d/%{upstream_name} install --preserve-timestamps --mode=0644 -D %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/%{upstream_name} install --preserve-timestamps --mode=0644 -D %{SOURCE5} %{buildroot}%{_sysusersdir}/%{upstream_name}.conf install --preserve-timestamps --mode=0644 -D %{SOURCE6} %{buildroot}%{_mandir}/man1/halog.1 install --directory --mode=0755 \ %{buildroot}%{_sysconfdir}/%{upstream_name}/conf.d \ %{buildroot}%{_localstatedir}/lib/%{upstream_name} \ %{buildroot}%{_datadir}/%{upstream_name} install --preserve-timestamps --mode=0644 -D %{SOURCE7} %{buildroot}%{_tmpfilesdir}/%{upstream_name}.conf install --preserve-timestamps --mode=0644 examples/errorfiles/*.http %{buildroot}%{_datadir}/%{upstream_name}/ # Convert from ISO-8859-1 to UTF-8 iconv --from-code=ISO-8859-1 --to-code=UTF-8 --output doc/internals/connection-scale.txt{.utf8,} touch --no-create --reference doc/internals/connection-scale.txt{,.utf8} mv --force doc/internals/connection-scale.txt{.utf8,} # Prepare doc/ and examples/ for %%doc inclusion mv --force doc/{gpl,lgpl}.txt . rm --force doc/{gpl,lgpl}.txt doc/%{upstream_name}.1 examples/%{upstream_name}.init %check # Configuration validation does not bind a socket or require root. ./haproxy -vv cat > packaging-check.cfg <<'EOF' defaults mode http timeout connect 5s timeout client 5s timeout server 5s frontend packaging_check bind 127.0.0.1:18080 http-request return status 200 EOF ./haproxy -c -f packaging-check.cfg %pre %sysusers_create_compat %{SOURCE5} %post %systemd_post %{upstream_name}.service %preun %systemd_preun %{upstream_name}.service %postun %systemd_postun_with_restart %{upstream_name}.service %files %license LICENSE gpl.txt lgpl.txt %doc CHANGELOG README.md doc/* examples/ %dir %{_sysconfdir}/%{upstream_name}/ %config(noreplace) %{_sysconfdir}/%{upstream_name}/%{upstream_name}.cfg %dir %{_sysconfdir}/%{upstream_name}/conf.d/ %dir %{_sysconfdir}/logrotate.d/ %config(noreplace) %{_sysconfdir}/logrotate.d/%{upstream_name} %config(noreplace) %{_sysconfdir}/sysconfig/%{upstream_name} %{_bindir}/halog %{_bindir}/iprange %{_bindir}/ip6range %{_sbindir}/%{upstream_name} %{_unitdir}/%{upstream_name}.service %{_sysusersdir}/%{upstream_name}.conf %{_mandir}/man1/halog.1* %{_mandir}/man1/%{upstream_name}.1* %dir %attr(0755,root,root) %{_localstatedir}/lib/%{upstream_name}/ %{_tmpfilesdir}/%{upstream_name}.conf %dir %{_datadir}/%{upstream_name}/ %{_datadir}/%{upstream_name}/*.http %changelog %autochangelog