Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package rsyslog for openSUSE:Factory checked 
in at 2026-07-29 18:58:36
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/rsyslog (Old)
 and      /work/SRC/openSUSE:Factory/.rsyslog.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "rsyslog"

Wed Jul 29 18:58:36 2026 rev:189 rq:1368306 version:8.2606.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/rsyslog/rsyslog.changes  2026-07-26 
11:28:31.542809986 +0200
+++ /work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog.changes        
2026-07-29 18:59:44.910678404 +0200
@@ -1,0 +2,1150 @@
+Mon Jul 27 12:53:09 UTC 2026 - Thomas Blume <[email protected]>
+- dropped separate tarball for rsyslog-doc, now included in main sources
+  (https://www.rsyslog.com/downloads/download-v8-stable/)
+
+- upgrade to rsyslog 8.2606 (bsc#1272414 CVE-2026-61548)
+  * 2026-06-23: imtcp: add stream compression support
+  * 2026-06-23: docs: add queue-full troubleshooting
+  * 2026-06-22: mmpstrucdata: document structured-data buffer invariant
+  * 2026-06-21: doc: refine object terminator wording
+  * 2026-06-21: doc: clarify security release handling
+  * 2026-06-21: doc: clarify RainerScript semicolon use
+  * 2026-06-20: rainerscript: escape embedded NULs at C-string boundary
+  * 2026-06-20: doc: explain service sandboxing for helpers
+  * 2026-06-20: doc: address service sandboxing review
+  * 2026-06-20: Apply suggested fix to tools/pmrfc3164.c from Copilot Autofix
+  * 2026-06-19: rainerscript: fold constant comparisons
+  * 2026-06-18: doc: clarify partial config validation
+  * 2026-06-18: config: warn on constant boolean operands
+  * 2026-06-17: parser: honor parseHostnameAndTag in RFC3164 parser
+  * 2026-06-17: core: fix negated exact priority filters
+  * 2026-06-16: rainerscript: keep random result non-negative
+  * 2026-06-16: rainerscript: add cbool function
+  * 2026-06-16: pmrfc3164: honor parseHostnameAndTag at runtime
+  * 2026-06-16: msg: invalidate programname when tag changes
+  * 2026-06-16: imfile: deliver same-file monitors independently
+  * 2026-06-16: glbl: keep debug logfile notice informational
+  * 2026-06-16: doc: modernize GELF forwarding tutorial
+  * 2026-06-15: ommail: add SMTP mode test
+  * 2026-06-15: mmjsonparse: modernize test output paths
+  * 2026-06-14: parser: add optional trailing CR stripping
+  * 2026-06-14: ompgsql: accept long server hostnames
+  * 2026-06-14: dynstats: warn on duplicate bucket names
+  * 2026-06-14: action: warn on duplicate action names
+  * 2026-06-13: omfwd: use matching atomic mutex helper
+  * 2026-06-08: Merge pull request #7014 from 
rsyslog/cursor/critical-correctness-bugs-480c
+  * 2026-06-05: omazureeventhubs docs: fix underscored parameters
+  * 2026-06-04: runtime: fix YAML promotion OOM ownership
+  * 2026-06-04: omuxsock docs: correct template parameter
+  * 2026-06-04: omhttp: own Splunk profile template names
+  * 2026-06-04: mmjsonparse: reject boundary trailing data
+  * 2026-06-04: mmdblookup: preserve uint64 values
+  * 2026-06-04: mmdblookup: check uint64 fallback formatting
+  * 2026-06-04: impstats docs: fix dotted log parameters
+  * 2026-06-04: impstats docs: clarify parameter name guidance
+  * 2026-06-04: imkafka: stop workers on startup failure
+  * 2026-06-04: imkafka: refine startup stop flag handling
+  * 2026-06-04: doc: match Sphinx duplicate CLI override handling
+  * 2026-06-04: doc: keep stable git docs out of dev mode
+  * 2026-06-04: doc: format stable rst_prolog metadata
+  * 2026-06-04: doc: fix database tutorial SQL template option
+  * 2026-06-03: regexp: avoid per-thread shutdown double-free
+  * 2026-06-03: omkafka: fix NULL topic and add action name to onDestroy flush 
logs
+  * 2026-06-03: mmsnareparse: honor searchWindow in tabbed trailing scan
+  * 2026-06-03: mmsnareparse: cap tab trailing search by token
+  * 2026-06-03: imfifo: guard absent module config paths
+  * 2026-06-03: imfifo: bind instances to module config
+  * 2026-06-03: imdiag: fix stats reporting gate
+  * 2026-06-03: imdiag: avoid checked cond signal while locked
+  * 2026-06-03: docker: gate collector imtcp module
+  * 2026-06-03: docker: derive single imtcp enable switch
+  * 2026-06-03: docker: default derived imtcp switch in collector
+  * 2026-06-02: yamlconf: clean up include recursion guard
+  * 2026-06-02: tls: propagate wolfSSL send-side read retry
+  * 2026-06-02: tls: keep wolfSSL send retry local
+  * 2026-06-02: tls: bound wolfSSL send-side read retries
+  * 2026-06-02: sidecar: cap UDP burst buffer by total bytes
+  * 2026-06-02: runtime: include limits.h for INT_MAX in yamlconf
+  * 2026-06-02: runtime: guard against recursive YAML includes
+  * 2026-06-02: runtime/queue: reset sizeOnDisk after safe recovery
+  * 2026-06-02: rainerscript: accept optimizer NOP statements
+  * 2026-06-02: omkafka: fix HUP deadlock when doAction holds mut_doAction 
(#7129)
+  * 2026-06-02: omhttp: avoid retry-ruleset self-stall
+  * 2026-06-02: omhiredis: fix TLS context error log
+  * 2026-06-02: mmpstrucdata: support custom SD containers
+  * 2026-06-02: mmjsonparse: fix find-json ownership and scan bounds
+  * 2026-06-02: mmjsonparse: clear JSON pointer after ownership transfer
+  * 2026-06-02: devtools: fold local review experiment into planner
+  * 2026-06-01: translate: cover script serialization (#7152)
+  * 2026-06-01: dev_env: include lcov in Ubuntu coverage images
+  * 2026-06-01: ChangeLog: update 8.2606 entries
+  * 2026-06-01: Add parse_time_localtz with documentation
+  * 2026-05-31: runtime: join final worker after shutdown wait
+  * 2026-05-31: runtime: harden raw message replacement growth
+  * 2026-05-31: runtime: fix $!all-json serialization locking
+  * 2026-05-31: ratelimit: centralize per-source enforcement
+  * 2026-05-31: parser: fix NetAddr cleanup on mask parse errors
+  * 2026-05-31: omclickhouse: report HTTP response errors
+  * 2026-05-31: omclickhouse: document SQL template option
+  * 2026-05-31: omclickhouse: clean up JSON root on OOM
+  * 2026-05-31: action: avoid committing suspended retry batches
+  * 2026-05-31: Keep transactional action queue messages on shutdown
+  * 2026-05-30: rainerscript: add tocef() and cef_ext_escape() for CEF output
+  * 2026-05-30: doc: clarify queue crash durability limits
+  * 2026-05-30: devtools: add read-only C format check
+  * 2026-05-29: tls: propagate send-side receive retry
+  * 2026-05-29: tls: preserve send-side receive retry state
+  * 2026-05-29: tls: preserve send retry without reconnect
+  * 2026-05-29: tls: keep wolfSSL send-side retry local
+  * 2026-05-29: tls: keep send-side read retries local
+  * 2026-05-29: template: apply style-check formatting
+  * 2026-05-29: style: format msg replacement tests
+  * 2026-05-29: runtime: fix msg replace helper CI failures
+  * 2026-05-29: omkafka: fix suspension not triggered on host resolution 
failure
+  * 2026-05-29: omfwd: schedule retry for deferred TCP flush
+  * 2026-05-29: omfwd: preserve connection on retryable TLS sends
+  * 2026-05-29: omfwd: avoid tcpclt leak on rebind
+  * 2026-05-29: mmsnareparse: preserve regex end-anchor semantics
+  * 2026-05-29: imudp: validate listen port formatting
+  * 2026-05-29: imudp: harden listen port file writes
+  * 2026-05-29: imptcp: simplify compression auto probe
+  * 2026-05-29: imkafka: support multiple topics in one input() instance
+  * 2026-05-29: imjournal: warn when newest entry is in the future
+  * 2026-05-29: imjournal: handle clock jumps in future probe
+  * 2026-05-29: docs: strengthen GHSA prompt guardrails
+  * 2026-05-29: add func doFunct_ParseTimeLocalTz
+  * 2026-05-29: Update doc/security/ghsa-coordination-review-template.md
+  * 2026-05-29: Fix rawmsg suffix shift on realloc
+  * 2026-05-29: Fix msg replacement and JSON set handling
+  * 2026-05-29: Apply suggested fix to tests/mmexternal-response-too-long.sh 
from Copilot Autofix
+  * 2026-05-28: tls: keep send retry state internal
+  * 2026-05-28: template: reject invalid regex match selectors
+  * 2026-05-28: template: guard NULL property rendering
+  * 2026-05-28: packaging: use ETL Vespa env defaults directly
+  * 2026-05-28: packaging: default ETL TLS envs in entrypoint
+  * 2026-05-28: omelasticsearch: apply clang-format to version probe error
+  * 2026-05-28: mmjsontransform: fix dotted conflict ownership
+  * 2026-05-28: mmexternal: fix single-instance reply handling
+  * 2026-05-28: mmexternal: fix EINTR reply handling
+  * 2026-05-28: mmdblookup: clean up failed worker creation
+  * 2026-05-28: imuxsock: handle embedded NUL datagrams safely
+  * 2026-05-28: imptcp: harden auto compression probe
+  * 2026-05-27: tls: preserve recv data during send-side reads
+  * 2026-05-27: tls: avoid recv-helper misuse in send WANT_READ
+  * 2026-05-27: tls: avoid receive retry state during send
+  * 2026-05-27: template: fix jsonftree flat fallback framing
+  * 2026-05-27: runtime: reject embedded NULs in mbedtls cert names
+  * 2026-05-27: runtime: initialize ratelimit mutex once
+  * 2026-05-27: runtime: guard per-thread regexp iterator allocation
+  * 2026-05-27: runtime: fix fromhost-port extraction before rcvFrom union swap
+  * 2026-05-27: runtime: clean up DNS props on port allocation failure
+  * 2026-05-27: runtime-format-regexp-lifecycle-guards
+  * 2026-05-27: regexp-clean-up-per-thread-entries
+  * 2026-05-27: packaging: expose Vespa HTTPS toggles
+  * 2026-05-27: packaging: enable HTTPS by default for ETL Vespa output
+  * 2026-05-27: omusrmsg: enable thread-safe action ratelimiter
+  * 2026-05-27: omotel: use getProgramName() when deriving app name
+  * 2026-05-27: omotel: avoid const cast for app name extraction
+  * 2026-05-27: ommysql: handle closed connection before commit
+  * 2026-05-27: omkafka: harden failed delivery replay paths
+  * 2026-05-27: omhttp: refresh health-check headers after gzip rebuild
+  * 2026-05-27: omhttp: keep health-check headers uncompressed
+  * 2026-05-27: omelasticsearch: bound startup version probe response size
+  * 2026-05-27: mmsnareparse: skip full digit runs in event probe
+  * 2026-05-27: mmsnareparse: preserve anchored trailing regex matches
+  * 2026-05-27: mmsnareparse: cap regex input in trailing token
+  * 2026-05-27: mmsnareparse: avoid quadratic provider scans in snare probe
+  * 2026-05-27: mmjsontransform: fix child ownership on dotted merge conflicts
+  * 2026-05-27: mmjsontransform: clean up dotted insert ownership
+  * 2026-05-27: mmanon: remove assert on malformed embedded IPv4
+  * 2026-05-27: mmanon: make random suffix generation fully reachable
+  * 2026-05-27: mmanon: build random suffix from byte chunks
+  * 2026-05-27: mbedtls-refine-nul-name-checks
+  * 2026-05-27: mbedtls-apply-cert-name-style
+  * 2026-05-27: lookup: report active table reloads as pending
+  * 2026-05-27: lmsig-ksi-bound-debug-precision
+  * 2026-05-27: imptcp: serialize helper work per session
+  * 2026-05-27: imptcp: add stream:auto compression mode
+  * 2026-05-27: imfifo: implement named pipe input module (#7029)
+  * 2026-05-27: dynstats: coalesce pending persistence writes per bucket
+  * 2026-05-27: dynstats-unlock-on-task-alloc-failure
+  * 2026-05-27: docker: fix clickhouse configure flag in Debian 13 dev image
+  * 2026-05-27: doc: use literal markup for TLS parameters
+  * 2026-05-27: doc: fix shutdown.enable.ctlc spelling in rsyslogd man page
+  * 2026-05-27: doc: fix mmrfc5424addhmac sd_id parameter name
+  * 2026-05-27: doc: clarify mbedtls requires StreamDriverMode=1 for TLS
+  * 2026-05-27: configure: detect relpCltSetKeepAlive support
+  * 2026-05-26: stats: avoid notifier teardown deadlocks
+  * 2026-05-26: runtime: guard optional regexp object lifecycle in tcp server
+  * 2026-05-26: runtime: bound KSI debug record logging by length
+  * 2026-05-26: runtime: avoid regexp unload double free
+  * 2026-05-26: ratelimit: avoid double free on helper error paths
+  * 2026-05-26: perctile: reuse counter cleanup helper
+  * 2026-05-26: perctile: link buckets after initialization
+  * 2026-05-26: ossl: avoid caching OCSP responses past nextUpdate
+  * 2026-05-26: omazuredce: bound HTTP response buffering
+  * 2026-05-26: omazuredce: avoid gzip buffer underallocation
+  * 2026-05-26: omazuredce-review-followup
+  * 2026-05-26: imuxsock: enforce ratelimit.name for credentialed senders
+  * 2026-05-26: imuxsock-ratelimit-credential-followup
+  * 2026-05-26: impstats: fix double-free in remote write batching cleanup
+  * 2026-05-26: imkafka: cap split.json.records fan-out
+  * 2026-05-26: imdocker: keep stream alive on rate-limit drops
+  * 2026-05-26: imdocker: bound multiline segment compaction
+  * 2026-05-26: imdocker: apply clang-format output
+  * 2026-05-26: configure: avoid leaking -lgcrypt into global LIBS
+  * 2026-05-25: shellcheck: fix masked test assignments
+  * 2026-05-25: runtime: validate numeric hardening inputs
+  * 2026-05-25: runtime/nsd_gtls: validate IP SAN length before conversion
+  * 2026-05-25: parser: verify and fix offAfterPRI calculation
+  * 2026-05-25: omhiredis: derive TLS server name from server config
+  * 2026-05-25: omfwd: require peers for targetSrv TLS name auth
+  * 2026-05-25: omfwd: clarify targetSrv TLS auth error
+  * 2026-05-25: nsd_gtls: preserve SAN-present state for malformed IP SAN
+  * 2026-05-25: imhttp: write bound listener port to file
+  * 2026-05-25: imdtls: write bound listener port to file
+  * 2026-05-25: fix(imhiredis): default TLS peer name to configured server
+  * 2026-05-24: tools: make AIX SRC reply copy bounded
+  * 2026-05-24: statsobj: clear lock flag after prometheus unlock
+  * 2026-05-24: runtime: clamp emulated RFC5424 tag length
+  * 2026-05-24: runtime: avoid post-fork malloc in execProg
+  * 2026-05-24: runtime/statsobj: lock stats list during iteration
+  * 2026-05-24: nsd_mbedtls: reject RemoteSNI and wire interface
+  * 2026-05-24: nsd_mbedtls: fill remote port interface methods
+  * 2026-05-24: mmjsontransform: track per-insert conflicts
+  * 2026-05-24: mmjsontransform: avoid leak on policy insert conflict
+  * 2026-05-24: mmjsonparse: avoid json double-free on add failure
+  * 2026-05-24: mmexternal: avoid undrained stdout/stderr pipe in output=none 
mode
+  * 2026-05-24: mmexternal: address output pipe review findings
+  * 2026-05-24: impstats: harden overwrite temp file creation
+  * 2026-05-24: imjournal: treat rate-limit discards as non-fatal in 
readjournal
+  * 2026-05-24: gssapi: use uint32_t for token wire length
+  * 2026-05-24: gssapi: fix token length framing endianness in sender
+  * 2026-05-24: fix(tools): guard AIX SRC reply text against NULL
+  * 2026-05-23: rainerscript: fix array and numeric comparisons on JSON vars
+  * 2026-05-23: privdrop: update privilege drop comments
+  * 2026-05-23: privdrop: log capability context on drop failure
+  * 2026-05-23: omelasticsearch: guard dynamic template strings
+  * 2026-05-23: omelasticsearch: cache action template count
+  * 2026-05-23: imjournal: restore cursor after recovery reopen
+  * 2026-05-23: imjournal: recover from stale saved cursor
+  * 2026-05-23: imjournal: harden journal invalidation recovery
+  * 2026-05-23: imjournal: avoid rotation accounting during recovery
+  * 2026-05-23: docs: clarify local validation gates
+  * 2026-05-23: contrib, runtime: defensive stability and robustness hardening
+  * 2026-05-23: codex: wire local container testing hook into agent workflow
+  * 2026-05-22: shell: clean up ShellCheck findings
+  * 2026-05-22: python: clean up style and add optional checks
+  * 2026-05-22: net_ossl: document SAN-priority hard-stop on old API
+  * 2026-05-22: msg: guard MSG replacement offsets (bsc#1272414)
+  * 2026-05-22: mmexternal: support one-way helpers and response timeouts
+  * 2026-05-22: imptcp: unlink failed accepted sessions
+  * 2026-05-22: imjournal: fix double-free hazards on JSON objects
+  * 2026-05-22: imfile: add line-number metadata and soften empty checks
+  * 2026-05-22: imdocker: terminate compacted multiline buffers
+  * 2026-05-22: imbeats: harden pointer transfer in submitEvent
+  * 2026-05-22: contrib, plugins: refine pointer hand-off in imhiredis, 
mmjsonparse, mmsequence
+  * 2026-05-22: contrib, plugins: defensive pointer hand-off hardening
+  * 2026-05-22: config: warn for unmatched include globs
+  * 2026-05-22: agents: document optional local linters
+  * 2026-05-21: template: harden property rendering bounds
+  * 2026-05-21: tcpsrv: guard listener destructors against NULL references
+  * 2026-05-21: tcps_sess: secure regex memory reallocation and destructor
+  * 2026-05-21: style: format wolfSSL CRL helper
+  * 2026-05-21: ruleset: guard synchronous recursive calls
+  * 2026-05-21: rainerscript: harden string and JSON bounds
+  * 2026-05-21: pm/fm: defensively harden parsing edge cases
+  * 2026-05-21: ossl: enable wolfSSL CRL checks for DER files
+  * 2026-05-21: net_ossl: avoid CN fallback when SAN priority unsupported
+  * 2026-05-21: mmgrok: keep configured source immutable
+  * 2026-05-21: lookup: harden shutdown lifecycle
+  * 2026-05-21: imudp: harden thread lifecycles and fix stats memory leak
+  * 2026-05-21: imtcp: harden listener setup and legacy config cleanup
+  * 2026-05-21: imjournal: defensive memory safety and stability hardening
+  * 2026-05-21: docs: codify GHSA coordination workflow
+  * 2026-05-21: docs: clarify GHSA triage scope
+  * 2026-05-21: docs: add distro component package map
+  * 2026-05-21: docs: add GHSA coordination template
+  * 2026-05-21: contrib: harden buffer and parser bounds handling
+  * 2026-05-21: agent: document local CI preflight tiers
+  * 2026-05-21: Update tests/imptcp_uds_unlink.sh
+  * 2026-05-21: Apply suggested fix to tests/imptcp_uds_unlink.sh from Copilot 
Autofix
+  * 2026-05-20: ossl: bound OCSP network reads
+  * 2026-05-20: mmanon: defensively harden IP suffix parsing
+  * 2026-05-20: lookup: reject duplicate table names
+  * 2026-05-20: imptcp: harden concurrency, boundaries, and memory safety
+  * 2026-05-20: gtls: log peer IP for missing client cert
+  * 2026-05-20: config: add global maxOpenFiles setting
+  * 2026-05-20: build: fix ARMv7 warnings under Werror
+  * 2026-05-20: agents: add ChangeLog maintenance skill
+  * 2026-05-20: Update tests/imptcp-discard-truncated-msg-same-session.sh
+  * 2026-05-20: ChangeLog: update 8.2606 entries
+  * 2026-05-20: Apply suggested fix to 
tests/imptcp-discard-truncated-msg-same-session.sh from Copilot Autofix
+  * 2026-05-20: Apply suggested fix to 
doc/source/reference/templates/templates-reserved-names.rst from Copilot Autofix
+  * 2026-05-19: imptcp: discard oversize byte after truncation
+  * 2026-05-18: tcp: log pre-truncated oversize frames
+  * 2026-05-18: runtime: avoid libgcry IV shift UB
+  * 2026-05-18: grammar: read pseudo-files in backtick cat
+  * 2026-05-18: docker: add container regex noise filter
+  * 2026-05-18: doc: remove unavailable StdJSONFmt reference
+  * 2026-05-18: agents: require available container validation
+  * 2026-05-18: agents: clarify PR babysitting decisions
+  * 2026-05-18: ChangeLog: remove duplicate release blocks
+  * 2026-05-18: Apply suggested fix to 
doc/source/reference/templates/templates-reserved-names.rst from Copilot Autofix
+  * 2026-05-17: omelasticsearch: document error-file modes
+  * 2026-05-17: doc: list RFC5424 reserved template
+  * 2026-05-17: doc: clarify omfile timed flush behavior
+  * 2026-05-17: doc: clarify omfile legacy action separation
++++ 860 more lines (skipped)
++++ between /work/SRC/openSUSE:Factory/rsyslog/rsyslog.changes
++++ and /work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog.changes

Old:
----
  rsyslog-8.2502.0.tar.gz
  rsyslog-doc-8.2502.0.tar.gz

New:
----
  rsyslog-8.2606.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ rsyslog.spec ++++++
--- /var/tmp/diff_new_pack.sdbHn4/_old  2026-07-29 18:59:46.174721992 +0200
+++ /var/tmp/diff_new_pack.sdbHn4/_new  2026-07-29 18:59:46.174721992 +0200
@@ -24,7 +24,7 @@
 %define requires_file() %( readlink -f '%*' | LC_ALL=C xargs -r rpm -q --qf 
'Requires: %%{name} >= %%{epoch}:%%{version}\\n' -f | sed -e 's/ (none):/ /' -e 
's/ 0:/ /' | grep -v "is not")
 
 # drop this with next release when doc tarball version lines up
-%define rsyslog_major 8.2502
+%define rsyslog_major 8.2606
 %define rsyslog_patch 0
 Name:           rsyslog
 Summary:        The enhanced syslogd for Linux and Unix
@@ -72,6 +72,11 @@
 # TODO: ... doesnt have a proper configure check but wants hdfs.h
 %bcond_with     hdfs
 %bcond_with     mongodb
+%if 0%{?suse_version} && 0%{?suse_version} < 1500
+  %bcond_with     protobuf
+%else
+  %bcond_without  protobuf
+%endif
 %bcond_with     hiredis
 %bcond_with     zeromq
 
@@ -101,8 +106,19 @@
 BuildRequires:  bison
 BuildRequires:  curl-devel
 BuildRequires:  flex
+BuildRequires:  libyaml-devel
 BuildRequires:  libzstd-devel
 BuildRequires:  pkgconfig
+BuildRequires:  pkgconfig(yaml-0.1)
+%if %{with protobuf}
+%if 0%{?suse_version}
+BuildRequires:  protobuf-c
+%else
+BuildRequires:  protobuf-c-devel
+%endif
+BuildRequires:  snappy-devel
+BuildRequires:  pkgconfig(libprotobuf-c) >= 1.0.0
+%endif
 BuildRequires:  zlib-devel
 %if %{with rfc3195}
 %if %{with pkgconfig}
@@ -215,13 +231,11 @@
 Source7:        module-mysql
 Source8:        module-snmp
 Source9:        module-udpspoof
-Source14:       
https://www.rsyslog.com/files/download/rsyslog/rsyslog-doc-%{rsyslog_major}.0.tar.gz
 Source16:       journald-rsyslog.conf
 Source17:       acpid.frule
 Source18:       firewall.frule
 Source19:       NetworkManager.frule
 Source20:       rsyslog-tmpfiles.conf
-
 Patch0:         0001-imptcp-guard-regex-framing-match-at-line-start.patch
 
 # this is a dirty hack since % dir does only work for the specified directory 
and nothing above
@@ -251,8 +265,6 @@
 
 This package provides additional documentation for rsyslog.
 
-%if %{with diagtools}
-
 %package diag-tools
 Requires:       %{name} = %{version}
 Summary:        Diagnostic tools
@@ -265,14 +277,10 @@
 This package provides additional diagnostic tools (small helpers,
 usually not needed).
 
-%endif
-
-%if %{with dtls}
-
 %package module-dtls
 Requires:       %{name} = %{version}
 Requires:       rsyslog-module-ossl
-Summary:        dtls support module for rsyslog
+Summary:        DTLS support module for rsyslog
 Group:          System/Daemons
 
 %description module-dtls
@@ -282,10 +290,6 @@
 This module provides support for securely transporting syslog messages over
 the network using the Datagram Transport Layer Security (DTLS) protocol.
 
-%endif
-
-%if %{with gssapi}
-
 %package module-gssapi
 Requires:       %{name} = %{version}
 Summary:        GSS-API support module for rsyslog
@@ -298,10 +302,6 @@
 This module provides the support to receive syslog messages from the
 network protected via Kerberos 5 encryption and authentication.
 
-%endif
-
-%if %{with mysql}
-
 %package module-mysql
 Requires:       %{name} = %{version}
 Summary:        MySQL support module for rsyslog
@@ -314,10 +314,6 @@
 This package provides a module with the support for logging into MySQL
 databases.
 
-%endif
-
-%if %{with pgsql}
-
 %package module-pgsql
 Requires:       %{name} = %{version}
 Summary:        PostgreSQL support module for rsyslog
@@ -329,10 +325,6 @@
 
 This module provides the support for logging into PostgreSQL databases.
 
-%endif
-
-%if %{with dbi}
-
 %package module-dbi
 Requires:       %{name} = %{version}
 Summary:        Database support via DBI
@@ -345,10 +337,6 @@
 This package provides a module with the support for logging into DBI
 supported databases.
 
-%endif
-
-%if %{with snmp}
-
 %package module-snmp
 Requires:       %{name} = %{version}
 Summary:        SNMP support module for rsyslog
@@ -361,10 +349,6 @@
 This module provides the ability to send syslog messages as an SNMPv1 &
 v2c traps.
 
-%endif
-
-%if %{with gnutls}
-
 %package module-gtls
 Requires:       %{name} = %{version}
 Summary:        TLS encryption support module for rsyslog
@@ -376,9 +360,6 @@
 
 This module provides the ability for TLS encrypted TCP logging using
 the GnuTLS library.
-%endif
-
-%if %{with openssl}
 
 %package module-ossl
 Requires:       %{name} = %{version}
@@ -391,9 +372,6 @@
 
 This module provides the ability for TLS encrypted TCP logging using
 the OpenSSL library.
-%endif
-
-%if %{with gcrypt}
 
 %package module-gcrypt
 Requires:       %{name} = %{version}
@@ -406,16 +384,15 @@
 
 This module provides log file encryption support using libgcrypt and
 a rsgtutil utility to manage the files.
-%endif
-
-%if %{with relp}
 
 %package module-relp
 Requires:       %{name} = %{version}
 Summary:        RELP protocol support module for syslog
 Group:          System/Daemons
 
+%if %{with relp}
 %requires_file %{_libdir}/librelp.so
+%endif
 
 %description module-relp
 Rsyslog is an enhanced multi-threaded syslog daemon. See rsyslog
@@ -423,10 +400,6 @@
 
 This module provides Reliable Event Logging Protocol support.
 
-%endif
-
-%if %{with mmnormalize}
-
 %package module-mmnormalize
 Requires:       %{name} = %{version}
 Summary:        Contains the mmnormalize support module for syslog
@@ -438,10 +411,6 @@
 
 This module provides log normalizing support.
 
-%endif
-
-%if %{with udpspoof}
-
 %package module-udpspoof
 Requires:       %{name} = %{version}
 Summary:        UDP spoof support module for syslog
@@ -453,10 +422,6 @@
 
 This module provides a UDP forwarder that allows changing the sender address.
 
-%endif
-
-%if %{with elasticsearch}
-
 %package module-elasticsearch
 Requires:       %{name} = %{version}
 Summary:        ElasticSearch output module for syslog
@@ -468,10 +433,6 @@
 
 This module provides support to output to an ElasticSearch database.
 
-%endif
-
-%if %{with omhttpfs}
-
 %package module-omhttpfs
 Requires:       %{name} = %{version}
 Summary:        HDFS via HTTP output module for syslog
@@ -483,10 +444,6 @@
 
 This module provides support to output to HDFS via HTTP.
 
-%endif
-
-%if %{with hdfs}
-
 %package module-hdfs
 Requires:       %{name} = %{version}
 Summary:        HDFS output module for syslog
@@ -498,10 +455,6 @@
 
 This module provides support to output to an HDFS database.
 
-%endif
-
-%if %{with mongodb}
-
 %package module-mongodb
 Requires:       %{name} = %{version}
 Summary:        MongoDB output module for syslog
@@ -513,10 +466,6 @@
 
 This module provides support to output to a MongoDB database.
 
-%endif
-
-%if %{with hiredis}
-
 %package module-hiredis
 Requires:       %{name} = %{version}
 Summary:        Redis output module for syslog
@@ -528,10 +477,6 @@
 
 This module provides support to output to a Redis database.
 
-%endif
-
-%if %{with zeromq}
-
 %package module-zeromq
 Requires:       %{name} = %{version}
 Summary:        ZeroMQ support module for syslog
@@ -543,10 +488,6 @@
 
 This module provides support for ZeroMQ.
 
-%endif
-
-%if %{with kafka}
-
 %package module-kafka
 Requires:       %{name} = %{version}
 Summary:        Kafka support module for syslog
@@ -558,9 +499,6 @@
 
 This module provides support for Kafka.
 
-%endif
-
-%if %{with omamqp1}
 %package module-omamqp1
 Requires:       %{name} = %{version}
 Summary:        AMQP support module for syslog
@@ -571,9 +509,7 @@
 package.
 
 This module provides support for AMQP.
-%endif
 
-%if %{with tcl}
 %package module-omtcl
 Requires:       %{name} = %{version}
 Summary:        TCL output module for rsyslog
@@ -584,7 +520,6 @@
 package.
 
 This module provides an output module for TCL.
-%endif
 
 %package devel
 Requires:       glibc-devel
@@ -611,7 +546,7 @@
 developing the rsyslog logging daemon.
 
 %prep
-%autosetup -p1 -a 14
+%autosetup -p1
 #
 for file in rsyslog-service-prepare; do
        sed \
@@ -621,7 +556,7 @@
 done
 
 %build
-export CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing -W -Wall -I../grammar 
-I../../grammar"
+export CFLAGS="%{optflags} -fno-strict-aliasing -W -Wall -I../grammar 
-I../../grammar"
 # needs java
 #        --enable-gui            \
 
@@ -753,10 +688,10 @@
        --enable-usertools      \
        --disable-static
 
-make %{?_smp_mflags:%{_smp_mflags}} V=1
+%make_build V=1
 
 %install
-make install DESTDIR="%{buildroot}"  V=1
+%make_install V=1
 #
 rm -f %{buildroot}%{rsyslog_module_dir_nodeps}/*.la
 #
@@ -814,10 +749,10 @@
 fi
 %if 0%{?suse_version} < 1550
        install -d -m0755 %{buildroot}/sbin
-       ln -sf %{_sbindir}/rsyslogd $RPM_BUILD_ROOT/sbin/rsyslogd
+       ln -sf %{_sbindir}/rsyslogd %{buildroot}/sbin/rsyslogd
 %endif
 # it is simply broken (bnc#890228)
-rm -f $RPM_BUILD_ROOT%{_sbindir}/zpipe
+rm -f %{buildroot}/%{_sbindir}/zpipe
 #
 install -m755 rsyslog-service-prepare %{buildroot}%{_sbindir}/
 ln -svf service %buildroot/%{_sbindir}/rc%{name}
@@ -850,7 +785,7 @@
 find ChangeLog README AUTHORS \
        \( -type d -exec install -m755 -d   %{buildroot}%{rsyslogdocdir}/\{\} 
\; \) \
      -o \( -type f -exec install -m644 \{\} %{buildroot}%{rsyslogdocdir}/\{\} 
\; \)
-cp -av build/* %{buildroot}%{rsyslogdocdir}/html/
+cp -av doc/source/* %{buildroot}%{rsyslogdocdir}/html/
 #
 %if %{with mysql}
 install -m644 plugins/ommysql/createDB.sql \
@@ -936,85 +871,26 @@
 # to switch when installing it and there is a provider conflict.
 /usr/bin/systemctl -f enable rsyslog.service >/dev/null 2>&1 || :
 
-%if %{with gssapi}
 %post_for_mark_daemon_restart module-gssapi
-%endif
-
-%if %{with mysql}
 %post_for_mark_daemon_restart module-mysql
-%endif
-
-%if %{with pgsql}
 %post_for_mark_daemon_restart module-pgsql
-%endif
-
-%if %{with dbi}
 %post_for_mark_daemon_restart module-dbi
-%endif
-
-%if %{with snmp}
 %post_for_mark_daemon_restart module-snmp
-%endif
-
-%if %{with gnutls}
 %post_for_mark_daemon_restart module-gtls
-%endif
-
-%if %{with openssl}
 %post_for_mark_daemon_restart module-ossl
-%endif
-
-%if %{with relp}
 %post_for_mark_daemon_restart module-relp
-%endif
-
-%if %{with mmnormalize}
 %post_for_mark_daemon_restart module-mmnormalize
-%endif
-
-%if %{with udpspoof}
 %post_for_mark_daemon_restart module-udpspoof
-%endif
-
-%if %{with elasticsearch}
 %post_for_mark_daemon_restart module-elasticsearch
-%endif
-
-%if %{with omhttpfs}
 %post_for_mark_daemon_restart module-omhttpfs
-%endif
-
-%if %{with hdfs}
 %post_for_mark_daemon_restart module-hdfs
-%endif
-
-%if %{with mongodb}
 %post_for_mark_daemon_restart module-mongodb
-%endif
-
-%if %{with hiredis}
 %post_for_mark_daemon_restart module-hiredis
-%endif
-
-%if %{with zeromq}
 %post_for_mark_daemon_restart module-zeromq
-%endif
-
-%if %{with kafka}
 %post_for_mark_daemon_restart module-kafka
-%endif
-
-%if %{with omamqp1}
 %post_for_mark_daemon_restart module-omamqp1
-%endif
-
-%if %{with gcrypt}
 %post_for_mark_daemon_restart module-gcrypt
-%endif
-
-%if %{with tcl}
 %post_for_mark_daemon_restart module-omtcl
-%endif
 
 %if 0%{?suse_version} < 1600
 %posttrans
@@ -1026,8 +902,7 @@
 #
 # stop the rsyslogd daemon when it is running
 #
-%{service_del_preun syslog.socket}
-%{service_del_preun rsyslog.service}
+%{service_del_preun syslog.socket rsyslog.service}
 
 %postun
 #
@@ -1040,7 +915,6 @@
 %{service_del_postun rsyslog.service}
 
 %files
-%defattr(-,root,root)
 %dir %{_sysconfdir}/rsyslog.d
 %config(noreplace) %attr(600,root,root) %{_sysconfdir}/rsyslog.conf
 %config(noreplace) %attr(600,root,root) %{_sysconfdir}/rsyslog.d/remote.conf
@@ -1119,14 +993,12 @@
 %{_tmpfilesdir}/rsyslog.conf
 
 %files doc
-%defattr(-,root,root)
 %dir %{rsyslogdocdir}/
 %doc %{rsyslogdocdir}/html/
 
 %if %{with diagtools}
 
 %files diag-tools
-%defattr(-,root,root)
 %{_sbindir}/msggen
 %{_sbindir}/rsyslog_diag_hostname
 %{rsyslog_module_dir_nodeps}/imdiag.so
@@ -1135,7 +1007,6 @@
 %if %{with gssapi}
 
 %files module-gssapi
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omgssapi.so
 %{rsyslog_module_dir_withdeps}/imgssapi.so
 %{rsyslog_module_dir_withdeps}/lmgssutil.so
@@ -1144,7 +1015,6 @@
 %if %{with mysql}
 
 %files module-mysql
-%defattr(-,root,root)
 %doc %{rsyslogdocdir}/mysql-createDB.sql
 %{rsyslog_module_dir_withdeps}/ommysql.so
 %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-mysql
@@ -1153,7 +1023,6 @@
 %if %{with pgsql}
 
 %files module-pgsql
-%defattr(-,root,root)
 %doc %{rsyslogdocdir}/pgsql-createDB.sql
 %{rsyslog_module_dir_withdeps}/ompgsql.so
 %endif
@@ -1161,14 +1030,12 @@
 %if %{with dbi}
 
 %files module-dbi
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omlibdbi.so
 %endif
 
 %if %{with snmp}
 
 %files module-snmp
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omsnmp.so
 %{rsyslog_module_dir_nodeps}/mmsnmptrapd.so
 %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-snmp
@@ -1177,21 +1044,18 @@
 %if %{with gnutls}
 
 %files module-gtls
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/lmnsd_gtls.so
 %endif
 
 %if %{with openssl}
 
 %files module-ossl
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/lmnsd_ossl.so
 %endif
 
 %if %{with relp}
 
 %files module-relp
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/imrelp.so
 %{rsyslog_module_dir_withdeps}/omrelp.so
 %endif
@@ -1199,16 +1063,15 @@
 %if %{with mmnormalize}
 
 %files module-mmnormalize
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/mmnormalize.so
 %{rsyslog_module_dir_withdeps}/mmjsonparse.so
+%{rsyslog_module_dir_withdeps}/mmleefparse.so
 %{rsyslog_module_dir_withdeps}/mmaudit.so
 %endif
 
 %if %{with udpspoof}
 
 %files module-udpspoof
-%defattr(-,root,root)
 %{rsyslog_module_dir_nodeps}/omudpspoof.so
 %config %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-udpspoof
 %endif
@@ -1216,42 +1079,36 @@
 %if %{with elasticsearch}
 
 %files module-elasticsearch
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omelasticsearch.so
 %endif
 
 %if %{with omhttpfs}
 
 %files module-omhttpfs
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omhttpfs.so
 %endif
 
 %if %{with hdfs}
 
 %files module-hdfs
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omhdfs.so
 %endif
 
 %if %{with mongodb}
 
 %files module-mongodb
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/ommongodb.so
 %endif
 
 %if %{with hiredis}
 
 %files module-hiredis
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omhiredis.so
 %endif
 
 %if %{with zeromq}
 
 %files module-zeromq
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/imzmq3.so
 %{rsyslog_module_dir_withdeps}/omzmq3.so
 %endif
@@ -1259,34 +1116,29 @@
 %if %{with kafka}
 
 %files module-kafka
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/imkafka.so
 %{rsyslog_module_dir_withdeps}/omkafka.so
 %endif
 
 %if %{with omamqp1}
 %files module-omamqp1
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omamqp1.so
 %endif
 
 %if %{with gcrypt}
 
 %files module-gcrypt
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/lmcry_gcry.so
 %{_bindir}/rscryutil
 %endif
 
 %if %{with tcl}
 %files module-omtcl
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/omtcl.so*
 %endif
 
 %if %{with dtls}
 %files module-dtls
-%defattr(-,root,root)
 %{rsyslog_module_dir_withdeps}/imdtls.so
 %{rsyslog_module_dir_withdeps}/omdtls.so
 %endif

++++++ 0001-imptcp-guard-regex-framing-match-at-line-start.patch ++++++
--- /var/tmp/diff_new_pack.sdbHn4/_old  2026-07-29 18:59:46.202722958 +0200
+++ /var/tmp/diff_new_pack.sdbHn4/_new  2026-07-29 18:59:46.206723095 +0200
@@ -1,49 +1,50 @@
-From 9ef6c7c11f2555f4766b822983f8f49f44df0349 Mon Sep 17 00:00:00 2001
-From: Rainer Gerhards <[email protected]>
-Date: Mon, 20 Jul 2026 17:19:28 +0200
-Subject: [PATCH] imptcp: guard regex framing match at line start
-
-Why
-A regex match at the beginning of the receive buffer can form a
-negative message length after oversize-frame recovery.
-
-Impact
-Regex-framed imptcp listeners reject that invalid transition instead
-of submitting a negative message length.
-
-Before/After
-Before: a match with a zero line offset submitted an invalid length.
-After: only a match following an existing line can submit a frame.
-
-Technical Overview
-Mirror the line-offset guard used by the shared imtcp parser.
-Leave existing regex framing and oversize recovery behavior unchanged.
-
-Security advisory:
-https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
-
-Reported-by: Raphael Eikenberg (@eikendev)
-With the help of AI-Agents: Codex
-
-(cherry picked from commit 07b3c40a5a78c79ed9109251f842ca7e955dd586)
----
- plugins/imptcp/imptcp.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/plugins/imptcp/imptcp.c b/plugins/imptcp/imptcp.c
-index 9223f20d0..16d2c327b 100644
---- a/plugins/imptcp/imptcp.c
-+++ b/plugins/imptcp/imptcp.c
-@@ -1054,7 +1054,7 @@ processDataRcvd_regexFraming(ptcpsess_t *const 
__restrict__ pThis,
-               pThis->iCurrLine = pThis->iMsg;
-       } else {
-               const int isMatch = !regexec(&inst->start_preg, 
(char*)pThis->pMsg+pThis->iCurrLine, 0, NULL, 0);
--              if(isMatch) {
-+              if (pThis->iCurrLine > 0 && isMatch) {
-                       DBGPRINTF("regex match (%d), framing line: %s\n", 
pThis->iCurrLine, pThis->pMsg);
-                       strcpy((char*)pThis->pMsg_save, (char*) 
pThis->pMsg+pThis->iCurrLine);
-                       pThis->iMsg = pThis->iCurrLine - 1;
--- 
-2.55.0
-
+From ccfdbe2613ef571655da48de0f753d7f43dc3b0f Mon Sep 17 00:00:00 2001
+From: Rainer Gerhards <[email protected]>
+Date: Mon, 20 Jul 2026 17:19:28 +0200
+Subject: [PATCH] imptcp: guard regex framing match at line start
+
+Why
+A regex match at the beginning of the receive buffer can form a
+negative message length after oversize-frame recovery.
+
+Impact
+Regex-framed imptcp listeners reject that invalid transition instead
+of submitting a negative message length.
+
+Before/After
+Before: a match with a zero line offset submitted an invalid length.
+After: only a match following an existing line can submit a frame.
+
+Technical Overview
+Mirror the line-offset guard used by the shared imtcp parser.
+Leave existing regex framing and oversize recovery behavior unchanged.
+
+Security advisory:
+https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
+
+Reported-by: Raphael Eikenberg (@eikendev)
+With the help of AI-Agents: Codex
+
+(cherry picked from commit 07b3c40a5a78c79ed9109251f842ca7e955dd586)
+(cherry picked from commit 9ef6c7c11f2555f4766b822983f8f49f44df0349)
+---
+ plugins/imptcp/imptcp.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/plugins/imptcp/imptcp.c b/plugins/imptcp/imptcp.c
+index 91aa55157..d291979dd 100644
+--- a/plugins/imptcp/imptcp.c
++++ b/plugins/imptcp/imptcp.c
+@@ -1050,7 +1050,7 @@ static rsRetVal ATTR_NONNULL() 
processDataRcvd_regexFraming(ptcpsess_t *const __
+         pThis->iCurrLine = pThis->iMsg;
+     } else {
+         const int isMatch = !regexec(&inst->start_preg, (char *)pThis->pMsg + 
pThis->iCurrLine, 0, NULL, 0);
+-        if (isMatch) {
++        if (pThis->iCurrLine > 0 && isMatch) {
+             DBGPRINTF("regex match (%d), framing line: %s\n", 
pThis->iCurrLine, pThis->pMsg);
+             memmove(pThis->pMsg_save, pThis->pMsg + pThis->iCurrLine, 
ustrlen(pThis->pMsg + pThis->iCurrLine) + 1);
+             pThis->iMsg = pThis->iCurrLine - 1;
+-- 
+2.55.0
+
 

++++++ rsyslog-8.2502.0.tar.gz -> rsyslog-8.2606.0.tar.gz ++++++
/work/SRC/openSUSE:Factory/rsyslog/rsyslog-8.2502.0.tar.gz 
/work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog-8.2606.0.tar.gz differ: 
char 12, line 1

Reply via email to