Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package logback for openSUSE:Factory checked 
in at 2026-10-02 23:04:45
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/logback (Old)
 and      /work/SRC/openSUSE:Factory/.logback.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "logback"

Fri Oct  2 23:04:45 2026 rev:19 rq:1382084 version:1.6.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/logback/logback.changes  2026-07-24 
22:05:51.806800356 +0200
+++ /work/SRC/openSUSE:Factory/.logback.new.1631729/logback.changes     
2026-10-02 23:05:57.347850740 +0200
@@ -1,0 +2,188 @@
+Thu Oct  1 18:53:03 UTC 2026 - Fridrich Strba <[email protected]>
+
+- Upgrade to upstream version 1.6.5
+  * Changes of version 1.6.5
+    + Fixed a vulnerability closely related to CVE-2026-19880
+      (bsc#1284020). The fix made in version 1.6.3, which strips
+      forward and backward slashes from MDC values, was not
+      sufficient. An MDC value could still contain relative path
+      components such as .., variable references such as /, or
+      characters that are special in file name patterns and email
+      addresses.
+      MDCBasedDiscriminator, used by SiftingAppender, now rejects
+      MDC values instead of stripping characters from them. An MDC
+      value is rejected if it is empty, if it is longer than 64
+      characters, if it contains the sequence .., or if it contains
+      any of the following characters: / \ $ { } [ ] ( ) | ? * + % ,
+      @. When an MDC value is rejected, the discriminator returns
+      the value of its DefaultValue property. A warning is emitted
+      for each rejected value. These warnings are rate-limited.
+    + When compression is enabled, TimeBasedRollingPolicy and
+      SizeAndTimeBasedRollingPolicy now also remove old log files
+      that were never compressed, for example because the
+      application was not running at rollover time. Previously, such
+      files were ignored by maxHistory and accumulated indefinitely.
+    + SimpleInvocationGate, deprecated in version 1.6.3, is now
+      marked for removal. Use FixedIntervalInvocationGate instead.
+  * Changes of version 1.6.4
+    + Variable substitution is again applied to the scan attribute
+      of the <configuration> element. The scanning refactoring in
+      version 1.5.27 had dropped substitution, so values such as
+      ${logback.scan.enabled:-true} were no longer resolved. As
+      before version 1.5.27, an unrecognized non-empty value turns
+      scanning on. The same substitution now applies to the scan
+      attribute of <propertiesConfigurator>.
+    + OutputStreamAppender and FileAppender now handle stateful
+      encoders. The Encoder interface has a new default method
+      called isStateful(), which returns false. An encoder that
+      keeps state between calls to encode() can return true. For
+      such encoders, the appender holds its write lock while
+      encoding and while writing, so the output of concurrent
+      appends cannot interleave. Stateless encoders still encode
+      outside the lock, so their performance does not change.
+      Existing encoders need no changes.
+    + Several race conditions in OutputStreamAppender and
+      FileAppender were fixed. The appender is now marked started
+      and the encoder header is written while the same lock is
+      held, so a concurrent append can no longer write an event
+      before the header. After acquiring the lock, the appender
+      checks again whether it has been stopped, so no event is
+      written after the footer. In prudent mode, FileAppender now
+      encodes and writes each event while holding the lock.
+    + Fixed a data race on the logger count in LoggerContext.
+      Loggers are created under the lock of their parent logger, so
+      loggers with different parents could be created at the same
+      time and increments of the shared counter could be lost. As a
+      result, LoggerContext.size() could return a value lower than
+      the actual number of loggers. The counter is now an
+      AtomicInteger.
+    + TimeBasedRollingPolicy now supports half-day periods. Date
+      patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a},
+      used to be detected as daily and rolled over only at
+      midnight. They now roll over at both 00:00 and 12:00. This
+      issue was reported in issues/976 by shakthifuture.
+    + If org.jline.jansi.AnsiConsole cannot be found on the class
+      path, JansiConsoleAppender now emits warnings that explain
+      how to add org.jline:jansi-core and then writes to the plain
+      console stream. See codes.html#missingJlineJansi.
+    + The unused
+      ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was
+      removed. LogbackMDCAdapter remains the default MDC adapter.
+  * Changes of version 1.6.3
+    + In relation to CVE-2026-19880 (bsc#1284020),
+      MDCBasedDiscriminator (used by SiftingAppender) now strips
+      forward and backward slashes (/, \) from MDC values before
+      they are used as discriminating keys. This prevents path
+      segments from escaping into destinations controlled by an
+      attacker. When sanitisation actually changes a value, a
+      warning is emitted; the warning is rate-limited (a small
+      batch, then a lull of about ten minutes).
+    + Colour console support is split out into a dedicated
+      JansiConsoleAppender
+      (ch.qos.logback.core.JansiConsoleAppender). It wraps stdout
+      or stderr with Jansi so ANSI escape sequences (for example
+      coloured patterns) render correctly on terminals that need
+      it, notably Windows. Prefer this class over the older path
+      described next.
+    + The withJansi property on ConsoleAppender is deprecated.
+      Existing configurations that still set
+      <withJansi>true</withJansi> continue to work for
+      compatibility, but new setups should use JansiConsoleAppender
+      instead.
+    + ConsoleAppender no longer treats the process console as an
+      exclusive resource: stopping it does not close System.out /
+      System.err. JansiConsoleAppender pairs each
+      AnsiConsole.systemInstall() with systemUninstall() on stop,
+      so repeated start/stop cycles do not leave Jansi installed or
+      tear down streams shared with the rest of the JVM.
+    + Invocation throttling helpers were reworked:
+      SimpleInvocationGate is renamed FixedIntervalInvocationGate,
+      and BatchedFixedIntervalInvocationGate allows a short burst
+      of invocations before applying a fixed lull. The sanitisation
+      warning above uses the batched gate.
+    + The JPMS module-info for logback-core now exports the
+      ch.qos.logback.core.property package, which had been missing
+      from the module descriptor.
+  * Changes of version 1.6.2
+    + Configuration analysis now detects contradictory caller-data
+      inclusion instructions. For example, an AsyncAppender,
+      SocketAppender or SMTPAppender with includeCallerData left at
+      the default false is incompatible with a layout or encoder
+      pattern that uses a caller-data converter such as %C, %M, %L,
+      %F, %l or %caller. At runtime those converters would print
+      question marks and still incur extraction cost on a worker
+      thread. Logback now emits a configuration-time warning when
+      such instructions disagree. See
+      codes.html#callerContradiction for details. This issue was
+      reported in issues/1059 by leeychee. The initial analysis was
+      contributed by seonwoo_jung.
+    + Caller-contradiction analysis can be turned off by setting
+      the logback.skipCallerContradictionAnalysis variable to true,
+      either as a system property
+      (-Dlogback.skipCallerContradictionAnalysis=true) or as a
+      property in the configuration file:
+      <property name="logback.skipCallerContradictionAnalysis"
+      value="true"/>
+    + SimpleSocketServer and SimpleSSLSocketServer now require an
+      explicit client IP whitelist. On the command line, pass one
+      or more allowed addresses (single IPs or CIDR ranges) after
+      the configuration file. An empty whitelist means no clients
+      are accepted. When embedding the server programmatically,
+      register allowed addresses with
+      addAllowedClientAddress(String) or
+      setAllowedClientAddresses(Collection) before clients connect.
+      See the documentation on restricting client access.
+    + Added ThrowableProxyVOBuilder for assembling a
+      ThrowableProxyVO field by field, with a corresponding
+      ThrowableProxyVO.builder() entry point.
+    + Dependency analysis handlers now run their postHandle method
+      after child models have been processed, so checks that depend
+      on nested appenders (such as caller-contradiction analysis)
+      see a complete picture.
+    + Updated several dependencies, including Angus Mail to 2.0.4
+      and Jetty (test) to 12.1.12.
+  * Changes of version 1.6.1
+    + In TimeBasedRollingPolicy, when the file option is set, the
+      intermediate file renamed before asynchronous compression now
+      receives the target archive name without the compression
+      suffix (e.g. `.gz`, `.zip`, `.xz`). Previously it used a
+      nanotime-based `.tmp` suffix. This makes the file easier to
+      identify if compression fails during rollover.
+    + On GZ, ZIP, or XZ compression failure, the original
+      (uncompressed) log file is no longer deleted. Compression
+      strategies now delete the source file only after successful
+      compression and emit a warning that the original was left
+      intact.
+    + ConsoleAppender with <withJansi> now probes JLine's
+      org.jline.jansi.AnsiConsole first and falls back to the
+      legacy FuseSource org.fusesource.jansi.AnsiConsole class.
+      This keeps ANSI coloring working after Jansi moved under the
+      JLine project. The optional org.jline:jansi-core artifact is
+      declared as a dependency alongside the existing FuseSource
+      jansi dependency. A preferredJansiClassName property was
+      added for tests.
+    + LayoutWrappingEncoder now reports an error at start() when no
+      layout is set and guards encode() against a null layout.
+      Previously, a missing layout (for example after an ignored
+      <if>/<then>/<else> branch) allowed the encoder to start and
+      then fail with a NullPointerException on every event,
+      resulting in silent log loss.
+    + FileCollisionAnalyser now detects file collisions involving
+      nested appenders of SiftingAppender. When the nested file or
+      fileNamePattern does not textually reference the
+      discriminator key (e.g. ${userId}), a warning is issued at
+      configuration time naming the appender, the key, and the
+      shared target. This closes a gap where statically declared
+      file appenders were checked but sifted nested appenders were
+      not.
+    + More defensive handling in SyslogOutputStream and
+      SyslogAppenderBase: the close() method now ensures that
+      resources are closed, writes and flushes check that the
+      underlying resources are in a valid state and fallback to
+      no-op otherwise.
+- Added patch:
+  * jline-3.30.x.patch
+    + modify the imported module to correspond to jline3 3.30.x
+      module name of jansi-core artifact.
+
+-------------------------------------------------------------------

Old:
----
  logback-1.6.0.tar.xz

New:
----
  jline-3.30.x.patch
  logback-1.6.5.tar.xz

----------(New B)----------
  New:- Added patch:
  * jline-3.30.x.patch
    + modify the imported module to correspond to jline3 3.30.x
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ logback.spec ++++++
--- /var/tmp/diff_new_pack.KTD1Y7/_old  2026-10-02 23:05:58.592902786 +0200
+++ /var/tmp/diff_new_pack.KTD1Y7/_new  2026-10-02 23:05:58.593902827 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           logback
-Version:        1.6.0
+Version:        1.6.5
 Release:        0
 Summary:        A Java logging library
 License:        EPL-1.0 OR LGPL-2.1-or-later
@@ -25,6 +25,7 @@
 URL:            https://logback.qos.ch/
 Source0:        %{name}-%{version}.tar.xz
 Patch0:         filtering.patch
+Patch10:        jline-3.30.x.patch
 BuildRequires:  fdupes
 BuildRequires:  java-devel >= 11
 BuildRequires:  maven-local
@@ -35,6 +36,7 @@
 BuildRequires:  mvn(org.apache.felix:maven-bundle-plugin)
 BuildRequires:  mvn(org.apache.maven.plugins:maven-javadoc-plugin)
 BuildRequires:  mvn(org.fusesource.jansi:jansi)
+BuildRequires:  mvn(org.jline:jansi-core)
 BuildRequires:  mvn(org.slf4j:slf4j-api)
 BuildRequires:  mvn(org.slf4j:slf4j-ext)
 BuildRequires:  mvn(org.tukaani:xz)
@@ -79,7 +81,11 @@
 logback-examples module.
 
 %prep
-%autosetup -p1
+%setup -q
+%patch -P 0 -p1
+%if %{?pkg_vcmp:%pkg_vcmp jline3-jansi-core < 4}%{!?pkg_vcmp:0}
+%patch -P 10 -p1
+%endif
 
 chmod -x README.md LICENSE.txt
 find . -type f -exec chmod -x {} \;

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.KTD1Y7/_old  2026-10-02 23:05:58.662905712 +0200
+++ /var/tmp/diff_new_pack.KTD1Y7/_new  2026-10-02 23:05:58.667905921 +0200
@@ -1,6 +1,6 @@
-mtime: 1784861960
-commit: fa298c35a1bd53df2ff8a11fbf5454b82ba575fac1a3eca8ef57c834422352a5
+mtime: 1790940378
+commit: 630bedad76379d92f75801fc98ed543ab292d246590ce2ddeb66dd065fe15744
 url: https://src.opensuse.org/java-packages/logback
-revision: fa298c35a1bd53df2ff8a11fbf5454b82ba575fac1a3eca8ef57c834422352a5
+revision: 630bedad76379d92f75801fc98ed543ab292d246590ce2ddeb66dd065fe15744
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.KTD1Y7/_old  2026-10-02 23:05:58.724908304 +0200
+++ /var/tmp/diff_new_pack.KTD1Y7/_new  2026-10-02 23:05:58.735908763 +0200
@@ -2,7 +2,7 @@
        <service name="tar_scm" mode="disabled">
                <param name="scm">git</param>
                <param name="url">https://github.com/qos-ch/logback.git</param>
-               <param name="revision">v_1.6.0</param>
+               <param name="revision">v_1.6.5</param>
                <param name="match-tag">v_*</param>
                <param name="versionformat">@PARENT_TAG@</param>
                <param name="versionrewrite-pattern">v_(.*)</param>

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-10-02 13:26:18.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ jline-3.30.x.patch ++++++
diff --git a/logback-core/src/main/java/module-info.java 
b/logback-core/src/main/java/module-info.java
index 181dcb950..022bc6ae3 100644
--- a/logback-core/src/main/java/module-info.java
+++ b/logback-core/src/main/java/module-info.java
@@ -16,7 +16,7 @@ module ch.qos.logback.core {
     requires static org.fusesource.jansi;
 
     // optionally require jline.jansi
-    requires static org.jline.jansi.core;
+    requires static org.jansi.core;
 
     // optionally require tukaani
     requires static org.tukaani.xz;

++++++ logback-1.6.0.tar.xz -> logback-1.6.5.tar.xz ++++++
++++ 8427 lines of diff (skipped)

Reply via email to