Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package logback for openSUSE:Factory checked in at 2026-10-02 23:04:45 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/logback (Old) and /work/SRC/openSUSE:Factory/.logback.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "logback" Fri Oct 2 23:04:45 2026 rev:19 rq:1382084 version:1.6.5 Changes: -------- --- /work/SRC/openSUSE:Factory/logback/logback.changes 2026-07-24 22:05:51.806800356 +0200 +++ /work/SRC/openSUSE:Factory/.logback.new.1631729/logback.changes 2026-10-02 23:05:57.347850740 +0200 @@ -1,0 +2,188 @@ +Thu Oct 1 18:53:03 UTC 2026 - Fridrich Strba <[email protected]> + +- Upgrade to upstream version 1.6.5 + * Changes of version 1.6.5 + + Fixed a vulnerability closely related to CVE-2026-19880 + (bsc#1284020). The fix made in version 1.6.3, which strips + forward and backward slashes from MDC values, was not + sufficient. An MDC value could still contain relative path + components such as .., variable references such as /, or + characters that are special in file name patterns and email + addresses. + MDCBasedDiscriminator, used by SiftingAppender, now rejects + MDC values instead of stripping characters from them. An MDC + value is rejected if it is empty, if it is longer than 64 + characters, if it contains the sequence .., or if it contains + any of the following characters: / \ $ { } [ ] ( ) | ? * + % , + @. When an MDC value is rejected, the discriminator returns + the value of its DefaultValue property. A warning is emitted + for each rejected value. These warnings are rate-limited. + + When compression is enabled, TimeBasedRollingPolicy and + SizeAndTimeBasedRollingPolicy now also remove old log files + that were never compressed, for example because the + application was not running at rollover time. Previously, such + files were ignored by maxHistory and accumulated indefinitely. + + SimpleInvocationGate, deprecated in version 1.6.3, is now + marked for removal. Use FixedIntervalInvocationGate instead. + * Changes of version 1.6.4 + + Variable substitution is again applied to the scan attribute + of the <configuration> element. The scanning refactoring in + version 1.5.27 had dropped substitution, so values such as + ${logback.scan.enabled:-true} were no longer resolved. As + before version 1.5.27, an unrecognized non-empty value turns + scanning on. The same substitution now applies to the scan + attribute of <propertiesConfigurator>. + + OutputStreamAppender and FileAppender now handle stateful + encoders. The Encoder interface has a new default method + called isStateful(), which returns false. An encoder that + keeps state between calls to encode() can return true. For + such encoders, the appender holds its write lock while + encoding and while writing, so the output of concurrent + appends cannot interleave. Stateless encoders still encode + outside the lock, so their performance does not change. + Existing encoders need no changes. + + Several race conditions in OutputStreamAppender and + FileAppender were fixed. The appender is now marked started + and the encoder header is written while the same lock is + held, so a concurrent append can no longer write an event + before the header. After acquiring the lock, the appender + checks again whether it has been stopped, so no event is + written after the footer. In prudent mode, FileAppender now + encodes and writes each event while holding the lock. + + Fixed a data race on the logger count in LoggerContext. + Loggers are created under the lock of their parent logger, so + loggers with different parents could be created at the same + time and increments of the shared counter could be lost. As a + result, LoggerContext.size() could return a value lower than + the actual number of loggers. The counter is now an + AtomicInteger. + + TimeBasedRollingPolicy now supports half-day periods. Date + patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, + used to be detected as daily and rolled over only at + midnight. They now roll over at both 00:00 and 12:00. This + issue was reported in issues/976 by shakthifuture. + + If org.jline.jansi.AnsiConsole cannot be found on the class + path, JansiConsoleAppender now emits warnings that explain + how to add org.jline:jansi-core and then writes to the plain + console stream. See codes.html#missingJlineJansi. + + The unused + ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was + removed. LogbackMDCAdapter remains the default MDC adapter. + * Changes of version 1.6.3 + + In relation to CVE-2026-19880 (bsc#1284020), + MDCBasedDiscriminator (used by SiftingAppender) now strips + forward and backward slashes (/, \) from MDC values before + they are used as discriminating keys. This prevents path + segments from escaping into destinations controlled by an + attacker. When sanitisation actually changes a value, a + warning is emitted; the warning is rate-limited (a small + batch, then a lull of about ten minutes). + + Colour console support is split out into a dedicated + JansiConsoleAppender + (ch.qos.logback.core.JansiConsoleAppender). It wraps stdout + or stderr with Jansi so ANSI escape sequences (for example + coloured patterns) render correctly on terminals that need + it, notably Windows. Prefer this class over the older path + described next. + + The withJansi property on ConsoleAppender is deprecated. + Existing configurations that still set + <withJansi>true</withJansi> continue to work for + compatibility, but new setups should use JansiConsoleAppender + instead. + + ConsoleAppender no longer treats the process console as an + exclusive resource: stopping it does not close System.out / + System.err. JansiConsoleAppender pairs each + AnsiConsole.systemInstall() with systemUninstall() on stop, + so repeated start/stop cycles do not leave Jansi installed or + tear down streams shared with the rest of the JVM. + + Invocation throttling helpers were reworked: + SimpleInvocationGate is renamed FixedIntervalInvocationGate, + and BatchedFixedIntervalInvocationGate allows a short burst + of invocations before applying a fixed lull. The sanitisation + warning above uses the batched gate. + + The JPMS module-info for logback-core now exports the + ch.qos.logback.core.property package, which had been missing + from the module descriptor. + * Changes of version 1.6.2 + + Configuration analysis now detects contradictory caller-data + inclusion instructions. For example, an AsyncAppender, + SocketAppender or SMTPAppender with includeCallerData left at + the default false is incompatible with a layout or encoder + pattern that uses a caller-data converter such as %C, %M, %L, + %F, %l or %caller. At runtime those converters would print + question marks and still incur extraction cost on a worker + thread. Logback now emits a configuration-time warning when + such instructions disagree. See + codes.html#callerContradiction for details. This issue was + reported in issues/1059 by leeychee. The initial analysis was + contributed by seonwoo_jung. + + Caller-contradiction analysis can be turned off by setting + the logback.skipCallerContradictionAnalysis variable to true, + either as a system property + (-Dlogback.skipCallerContradictionAnalysis=true) or as a + property in the configuration file: + <property name="logback.skipCallerContradictionAnalysis" + value="true"/> + + SimpleSocketServer and SimpleSSLSocketServer now require an + explicit client IP whitelist. On the command line, pass one + or more allowed addresses (single IPs or CIDR ranges) after + the configuration file. An empty whitelist means no clients + are accepted. When embedding the server programmatically, + register allowed addresses with + addAllowedClientAddress(String) or + setAllowedClientAddresses(Collection) before clients connect. + See the documentation on restricting client access. + + Added ThrowableProxyVOBuilder for assembling a + ThrowableProxyVO field by field, with a corresponding + ThrowableProxyVO.builder() entry point. + + Dependency analysis handlers now run their postHandle method + after child models have been processed, so checks that depend + on nested appenders (such as caller-contradiction analysis) + see a complete picture. + + Updated several dependencies, including Angus Mail to 2.0.4 + and Jetty (test) to 12.1.12. + * Changes of version 1.6.1 + + In TimeBasedRollingPolicy, when the file option is set, the + intermediate file renamed before asynchronous compression now + receives the target archive name without the compression + suffix (e.g. `.gz`, `.zip`, `.xz`). Previously it used a + nanotime-based `.tmp` suffix. This makes the file easier to + identify if compression fails during rollover. + + On GZ, ZIP, or XZ compression failure, the original + (uncompressed) log file is no longer deleted. Compression + strategies now delete the source file only after successful + compression and emit a warning that the original was left + intact. + + ConsoleAppender with <withJansi> now probes JLine's + org.jline.jansi.AnsiConsole first and falls back to the + legacy FuseSource org.fusesource.jansi.AnsiConsole class. + This keeps ANSI coloring working after Jansi moved under the + JLine project. The optional org.jline:jansi-core artifact is + declared as a dependency alongside the existing FuseSource + jansi dependency. A preferredJansiClassName property was + added for tests. + + LayoutWrappingEncoder now reports an error at start() when no + layout is set and guards encode() against a null layout. + Previously, a missing layout (for example after an ignored + <if>/<then>/<else> branch) allowed the encoder to start and + then fail with a NullPointerException on every event, + resulting in silent log loss. + + FileCollisionAnalyser now detects file collisions involving + nested appenders of SiftingAppender. When the nested file or + fileNamePattern does not textually reference the + discriminator key (e.g. ${userId}), a warning is issued at + configuration time naming the appender, the key, and the + shared target. This closes a gap where statically declared + file appenders were checked but sifted nested appenders were + not. + + More defensive handling in SyslogOutputStream and + SyslogAppenderBase: the close() method now ensures that + resources are closed, writes and flushes check that the + underlying resources are in a valid state and fallback to + no-op otherwise. +- Added patch: + * jline-3.30.x.patch + + modify the imported module to correspond to jline3 3.30.x + module name of jansi-core artifact. + +------------------------------------------------------------------- Old: ---- logback-1.6.0.tar.xz New: ---- jline-3.30.x.patch logback-1.6.5.tar.xz ----------(New B)---------- New:- Added patch: * jline-3.30.x.patch + modify the imported module to correspond to jline3 3.30.x ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ logback.spec ++++++ --- /var/tmp/diff_new_pack.KTD1Y7/_old 2026-10-02 23:05:58.592902786 +0200 +++ /var/tmp/diff_new_pack.KTD1Y7/_new 2026-10-02 23:05:58.593902827 +0200 @@ -17,7 +17,7 @@ Name: logback -Version: 1.6.0 +Version: 1.6.5 Release: 0 Summary: A Java logging library License: EPL-1.0 OR LGPL-2.1-or-later @@ -25,6 +25,7 @@ URL: https://logback.qos.ch/ Source0: %{name}-%{version}.tar.xz Patch0: filtering.patch +Patch10: jline-3.30.x.patch BuildRequires: fdupes BuildRequires: java-devel >= 11 BuildRequires: maven-local @@ -35,6 +36,7 @@ BuildRequires: mvn(org.apache.felix:maven-bundle-plugin) BuildRequires: mvn(org.apache.maven.plugins:maven-javadoc-plugin) BuildRequires: mvn(org.fusesource.jansi:jansi) +BuildRequires: mvn(org.jline:jansi-core) BuildRequires: mvn(org.slf4j:slf4j-api) BuildRequires: mvn(org.slf4j:slf4j-ext) BuildRequires: mvn(org.tukaani:xz) @@ -79,7 +81,11 @@ logback-examples module. %prep -%autosetup -p1 +%setup -q +%patch -P 0 -p1 +%if %{?pkg_vcmp:%pkg_vcmp jline3-jansi-core < 4}%{!?pkg_vcmp:0} +%patch -P 10 -p1 +%endif chmod -x README.md LICENSE.txt find . -type f -exec chmod -x {} \; ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.KTD1Y7/_old 2026-10-02 23:05:58.662905712 +0200 +++ /var/tmp/diff_new_pack.KTD1Y7/_new 2026-10-02 23:05:58.667905921 +0200 @@ -1,6 +1,6 @@ -mtime: 1784861960 -commit: fa298c35a1bd53df2ff8a11fbf5454b82ba575fac1a3eca8ef57c834422352a5 +mtime: 1790940378 +commit: 630bedad76379d92f75801fc98ed543ab292d246590ce2ddeb66dd065fe15744 url: https://src.opensuse.org/java-packages/logback -revision: fa298c35a1bd53df2ff8a11fbf5454b82ba575fac1a3eca8ef57c834422352a5 +revision: 630bedad76379d92f75801fc98ed543ab292d246590ce2ddeb66dd065fe15744 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj ++++++ _service ++++++ --- /var/tmp/diff_new_pack.KTD1Y7/_old 2026-10-02 23:05:58.724908304 +0200 +++ /var/tmp/diff_new_pack.KTD1Y7/_new 2026-10-02 23:05:58.735908763 +0200 @@ -2,7 +2,7 @@ <service name="tar_scm" mode="disabled"> <param name="scm">git</param> <param name="url">https://github.com/qos-ch/logback.git</param> - <param name="revision">v_1.6.0</param> + <param name="revision">v_1.6.5</param> <param name="match-tag">v_*</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v_(.*)</param> ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-10-02 13:26:18.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ jline-3.30.x.patch ++++++ diff --git a/logback-core/src/main/java/module-info.java b/logback-core/src/main/java/module-info.java index 181dcb950..022bc6ae3 100644 --- a/logback-core/src/main/java/module-info.java +++ b/logback-core/src/main/java/module-info.java @@ -16,7 +16,7 @@ module ch.qos.logback.core { requires static org.fusesource.jansi; // optionally require jline.jansi - requires static org.jline.jansi.core; + requires static org.jansi.core; // optionally require tukaani requires static org.tukaani.xz; ++++++ logback-1.6.0.tar.xz -> logback-1.6.5.tar.xz ++++++ ++++ 8427 lines of diff (skipped)
