Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package cacti for openSUSE:Factory checked in at 2026-09-18 22:05:20 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/cacti (Old) and /work/SRC/openSUSE:Factory/.cacti.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "cacti" Fri Sep 18 22:05:20 2026 rev:61 rq:1378671 version:1.2.31+git128.263b4c1c Changes: -------- --- /work/SRC/openSUSE:Factory/cacti/cacti.changes 2026-08-05 17:50:20.213926262 +0200 +++ /work/SRC/openSUSE:Factory/.cacti.new.383539/cacti.changes 2026-09-18 22:05:53.989987358 +0200 @@ -1,0 +2,122 @@ +Thu Sep 17 14:15:36 UTC 2026 - Joel Baltazor <[email protected]> + +- Adjusted _service file to look at release/ tags and ignore the rel* warning +- Update cacti-config-dist.patch to apply cleanly and build +- Update cacti.spec to ignore export-plural-rules and csrf-secret.php +- Update to version 1.2.31+git128.263b4c1c: + * fix(installer): tolerate a microtime string with no fractional part (1.2.x backport) (#8029) + * fix enum test ' and " (#8027) + * fix: Unable to remove data queries due to new request hardening (#8028) + * fix(auth): backport session and remember-cookie lifecycle hardening (#7990) + * ci: Remove platform as it causes conflicts during ci (#8018) + * fix(csrf): backport tokenized POST item actions (#7992) + * 1.2.x: Propagate reconnected database handles (#7998) + * security: reject LDAP logins that skip a domain bind (#8008) + * 1.2.x: Clarify missing SNMP notification receivers (#7997) + * fix(realtime): preserve inline graph size (#7996) + * fix(functions): preserve observed child exit codes (#7989) + * fix(csv): backport aligned sample windows to 1.2 (#7988) + * security: harden CLI process and temporary-file handling (#7972) + * fix: harden Boost lifecycle, PHP 8.5 graph CF, and UI initialization (#7963) + * [1.2.x] Preserve layout after plugin dependency errors (#7962) + * Fixing Issues When Boost Redirect is Enabled (#8015) + * security(poller): validate PID bounds and process ownership (#7955) + * Revert "deps(deps): bump phpseclib/phpseclib in the composer-1-2-x group (#8005)" (#8017) + * fix: Installer in batch through false positive fail (#8016) + * Update translation files + * Translated using Weblate (Swedish) + * fix(cli): normalize aliases, help, and error statuses (#7907) + * deps(deps): bump phpseclib/phpseclib in the composer-1-2-x group (#8005) + * fix(automation): use server timezone for schedules (#7995) + * Backport graph filter, automation OS, and lm-sensors fixes (#7983) + * ci(csp): fail closed on empty Pest runs (#7994) + * Fix SNMP uptime selection on 1.2.x (#7982) + * 1.2.x: Close detached select menus on scroll (#7999) + * fix: report missing session cookie failures (#7871) + * build: declare the PHP 8.1 floor 1.2.31 already shipped (#7938) + * fix: commit transactions on MySQL as well as MariaDB (#7930) + * test: refresh the 1.2.x security baselines (#7924) + * security(cli): keep database credentials off the command line (#7910) + * issue: update bundled jQuery UI to 1.14.2 and Tablesorter to 2.31.3 (#7887) + * security: update bundled DOMPurify to 3.4.14 (#7912) + * QA: Preparing for Cacti release (#7870) + * fix: prevent cookie domain login loops (#7869) + * fix: poller overrun cleanup and CSV export row cap (#7862) + * security: verify package signatures against trusted keys only (#7863) + * security: 1.2.x hardening batch (clog filenames, dsstats/aggregate escaping, auth) (#7847) + * security: substitute query data before escaping graph titles and labels (#7845) + * security: stop trusting Host for HTTPS redirects (#7832) + * fix: allow graph tree sidebar to shrink (#7836) + * issue#7809: stop reading a missing source key on output-only data query fields (#7834) + * ci(deps): bump docker/setup-buildx-action (#7827) + * fix: remove obsolete PHP compatibility branches (#7820) + * hardening: constrain user_admin sort_column, escape sites LIKE wildcards, unpredictable package temp dir (#7821) + * fix(database): restore qualified table metadata lookup (#7826) + * hardening: confine external link content includes (#7817) + * fix(user_admin): validate group filter as an integer (#7813) + * fix(html_tree): escape data query index in graph tree title (#7814) + * hardening: trim vendored runtime surface (#7805) + * fix: restore RRDproxy crypto with phpseclib 3 (#7804) + * security(csrf): harden secret and request handoffs (#7803) + * Build self-contained 1.2.x release artifacts from Composer lock (#7802) + * fix(composer): keep extension diagnostics in installer (#7811) + * docs: add missing 1.2.x changelog entries (#7789) + * fix: url encode the base64 regex filter before it reaches the query string (#7777) + * ci: stabilize PPA and apt refresh on 1.2.x (#7763) + * ci: restore PHP 8.1 integration coverage (#7756) + * [1.2.x] Harden Boost data handoffs and graph cache writes (#7728) + * update changelog (#7753) + * ci(deps): bump the github-actions-1-2-x group with 7 updates (#7748) + * Make 1.2 dependency builds reproducible (#7747) + * deps(deps): update paragonie/constant_time_encoding requirement (#7738) + * security: restrict graph input fields across handoffs (1.2.x) (#7692) + * ci(security): compare the 1.2.x baselines on a line-agnostic signature (#7724) + * Bind the MIB column names in MibCache::select() (#7708) + * Make the CSP report size limit reachable and stop the counters piling up (#7704) + * security: enforce strict-bool package signature check in import_package (GHSA-274c-97hj-pv2v) (#7675) + * 1.2.x - fix log entry (two spaces) "fields which is NOT okay" (#7727) + * Guard three divisors that PHP 8 makes fatal (#7699) + * Document the PHP baseline accurately on 1.2.x (#7698) + * security: reject path traversal in package file writes (GHSA-vp35-4h28-r883) (#7671) + * fix(functions): take cacti_exec exit code from proc_close (#7668) + * chore(deps): update phpseclib to 3.0.56 (#7734) + * refactor(tests): reorganize unit tests into domain category folders (#7731) + * fix(poller): launch cactid without a shell (#7602) + * fix(installer): propagate background installation failures (#7630) + * fix(installer): reject incomplete selection payloads (#7628) + * fix(snmp): log the reason a session read failed (#7606) + * feat(logging): emit structured security events for validation failures (#7604) + * fix(auth): expire persistent auth tokens when permissions change (#7600) + * fix(automation): bind host template ID filters as prepared parameters (#7598) + * ci(security): require advisory changelog references (#7596) + * Fail closed on incomplete installer schemas (#7625) + * fix(installer): restore select-all controls on 1.2.x (#7624) + * docs(config): expose HTMLPurifier cache path (#7595) + * fix(session): guard request URI reads on 1.2.x (#7593) + * fix(csp): honor alternate frame ancestors (#7591) + * fix(security): harden advisory command and DDL sinks (#7235) + * fix: #7510 - Fix system MIB collection interval lock (#7559) + * test: restore missing helper source and skip orphaned unit tests (#7547) + * fix(data query): walk output_format fields with the bulk walk size (#7556) + * test: pin draw_edit_form change handler binding (#7553) (#7554) + * fix(html): keep the HTMLPurifier definition cache out of the library tree (#7555) + * fix: backport VDEF xport safeguards (#7508) + * fix: monthly automation schedules corrupt next_start to 1970 and run every cycle (#7428) + * fix: stop tracking the generated CSRF secret so each install gets its own (#7415) + * fix: #5679 attempt SNMP in Ping-OR-SNMP availability when ping fails (#7417) + * fix: update host status by id instead of hostname (#7416) + * fix: guard process registration against pid reuse (#7414) + * fix(scripts): correct SNMP disk counter wrap math (1.2.x) (#7413) + * fix: correct octet carry in automation_get_next_host for wide ranges (#7410) + * fix: remove inert Automatically Trust Signer control from package import (#7430) + * test: add regression coverage for #7407 and #7408 fixes (#7496) + * fix(database): commit transaction check uses the passed connection (#7409) + * hardening: guard system PIDs in timeout_kill_registered_processes (#7400) + * fix: backport remote agent timeout options (#7507) + * fix: correct unsigned reconstruction for negative disk sizes in ss_host_disk (#7408) + * fix: timeout_kill_registered_processes never matched any row (#7407) + * fix: #7070 align percentile rank with observed export samples (#7406) + * fix variable (#7402) + * ci(security): refresh 1.2.x sink inventory baseline (#7495) + +------------------------------------------------------------------- Old: ---- cacti-1.2.31+git14.396480d3.obscpio New: ---- cacti-1.2.31+git128.263b4c1c.obscpio cacti-1.2.31+git128.263b4c1c.tar ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ cacti.spec ++++++ --- /var/tmp/diff_new_pack.D0y8ag/_old 2026-09-18 22:05:56.954111584 +0200 +++ /var/tmp/diff_new_pack.D0y8ag/_new 2026-09-18 22:05:56.956111667 +0200 @@ -21,7 +21,7 @@ %define cacti_dir %{datadir}/cacti Name: cacti -Version: 1.2.31+git14.396480d3 +Version: 1.2.31+git128.263b4c1c %global base_version %(echo %{version} | sed 's/+[^+]*//') %global next_base_version %(echo %{base_version} | awk -F. -v OFS=. '{$NF++; print}') Release: 0 @@ -97,7 +97,9 @@ # fix env interpreter lines sed -i 's|%{_bindir}/env perl|%{_bindir}/perl|g' $(find * -name "*.pl") -sed -i 's|%{_bindir}/env php|%{_bindir}/php|g' include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules +if [ -f include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules ]; then + sed -i 's|%{_bindir}/env php|%{_bindir}/php|g' include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules +fi sed -i 's|%{_bindir}/env bash|%{_bindir}/bash|g' $(find * -name "*.sh") sed -i 's|/usr/local/spine/bin/spine|%{_bindir}/spine|' install/functions.php @@ -203,7 +205,7 @@ %doc quickstart.txt %attr(-,%{apache_user},%{apache_group}) %dir %{_localstatedir}/lib/%{name} %attr(-,%{apache_user},%{apache_group}) %dir %{_localstatedir}/log/%{name} -%attr(-,%{apache_user},%{apache_group}) %{cacti_dir}/include/vendor/csrf/csrf-secret.php +#%%attr(-,%{apache_user},%{apache_group}) %{cacti_dir}/include/vendor/csrf/csrf-secret.php %attr(-,%{apache_user},%{apache_group}) %{cacti_dir}/log %{cacti_dir}/log %config(noreplace) %{cacti_dir}/include/config.php ++++++ _service ++++++ --- /var/tmp/diff_new_pack.D0y8ag/_old 2026-09-18 22:05:57.007113805 +0200 +++ /var/tmp/diff_new_pack.D0y8ag/_new 2026-09-18 22:05:57.012114015 +0200 @@ -4,6 +4,8 @@ <param name="scm">git</param> <param name="exclude">.git</param> <param name="revision">1.2.x</param> + <!-- Forces Git to only look at release/ tags and ignore the rel* warning tag --> + <param name="match-tag">release/*</param> <param name="versionformat">@PARENT_TAG@+git@TAG_OFFSET@.%h</param> <!-- Removes "release/" from the beginning of the version string --> <param name="versionrewrite-pattern">release/(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.D0y8ag/_old 2026-09-18 22:05:57.038115104 +0200 +++ /var/tmp/diff_new_pack.D0y8ag/_new 2026-09-18 22:05:57.044115356 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/Cacti/cacti.git</param> - <param name="changesrevision">396480d3fc2027c68ffe872bf5e3356cf34eefd6</param></service></servicedata> + <param name="changesrevision">263b4c1caee8c11bd9ca30c9429fd8cc3ba2d2b7</param></service></servicedata> (No newline at EOF) ++++++ cacti-1.2.31+git14.396480d3.obscpio -> cacti-1.2.31+git128.263b4c1c.obscpio ++++++ ++++ 133476 lines of diff (skipped) ++++++ cacti-config-dist.patch ++++++ --- /var/tmp/diff_new_pack.D0y8ag/_old 2026-09-18 22:06:00.167246246 +0200 +++ /var/tmp/diff_new_pack.D0y8ag/_new 2026-09-18 22:06:00.179246749 +0200 @@ -1,7 +1,7 @@ -Index: cacti-1.2.23/include/config.php.dist +Index: cacti-1.2.31/include/config.php.dist =================================================================== ---- cacti-1.2.23.orig/include/config.php.dist -+++ cacti-1.2.23/include/config.php.dist +--- cacti-1.2.31.orig/include/config.php.dist ++++ cacti-1.2.31/include/config.php.dist @@ -45,17 +45,17 @@ $database_persist = false; * must remain commented out. */ @@ -46,7 +46,7 @@ +//$cacti_session_name = 'Cacti'; /** - * Default Cookie domain - The cookie domain to be used for Cacti + * Optional cookie domain. This must match the browser-visible host or one of @@ -88,7 +88,7 @@ $cacti_session_name = 'Cacti'; * Save sessions to a database for load balancing */ ++++++ cacti.obsinfo ++++++ --- /var/tmp/diff_new_pack.D0y8ag/_old 2026-09-18 22:06:00.290251401 +0200 +++ /var/tmp/diff_new_pack.D0y8ag/_new 2026-09-18 22:06:00.295251610 +0200 @@ -1,5 +1,5 @@ name: cacti -version: 1.2.31+git14.396480d3 -mtime: 1784942578 -commit: 396480d3fc2027c68ffe872bf5e3356cf34eefd6 +version: 1.2.31+git128.263b4c1c +mtime: 1789516109 +commit: 263b4c1caee8c11bd9ca30c9429fd8cc3ba2d2b7
