Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package rsyslog for openSUSE:Factory checked in at 2026-07-29 18:58:36 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/rsyslog (Old) and /work/SRC/openSUSE:Factory/.rsyslog.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "rsyslog" Wed Jul 29 18:58:36 2026 rev:189 rq:1368306 version:8.2606.0 Changes: -------- --- /work/SRC/openSUSE:Factory/rsyslog/rsyslog.changes 2026-07-26 11:28:31.542809986 +0200 +++ /work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog.changes 2026-07-29 18:59:44.910678404 +0200 @@ -1,0 +2,1150 @@ +Mon Jul 27 12:53:09 UTC 2026 - Thomas Blume <[email protected]> +- dropped separate tarball for rsyslog-doc, now included in main sources + (https://www.rsyslog.com/downloads/download-v8-stable/) + +- upgrade to rsyslog 8.2606 (bsc#1272414 CVE-2026-61548) + * 2026-06-23: imtcp: add stream compression support + * 2026-06-23: docs: add queue-full troubleshooting + * 2026-06-22: mmpstrucdata: document structured-data buffer invariant + * 2026-06-21: doc: refine object terminator wording + * 2026-06-21: doc: clarify security release handling + * 2026-06-21: doc: clarify RainerScript semicolon use + * 2026-06-20: rainerscript: escape embedded NULs at C-string boundary + * 2026-06-20: doc: explain service sandboxing for helpers + * 2026-06-20: doc: address service sandboxing review + * 2026-06-20: Apply suggested fix to tools/pmrfc3164.c from Copilot Autofix + * 2026-06-19: rainerscript: fold constant comparisons + * 2026-06-18: doc: clarify partial config validation + * 2026-06-18: config: warn on constant boolean operands + * 2026-06-17: parser: honor parseHostnameAndTag in RFC3164 parser + * 2026-06-17: core: fix negated exact priority filters + * 2026-06-16: rainerscript: keep random result non-negative + * 2026-06-16: rainerscript: add cbool function + * 2026-06-16: pmrfc3164: honor parseHostnameAndTag at runtime + * 2026-06-16: msg: invalidate programname when tag changes + * 2026-06-16: imfile: deliver same-file monitors independently + * 2026-06-16: glbl: keep debug logfile notice informational + * 2026-06-16: doc: modernize GELF forwarding tutorial + * 2026-06-15: ommail: add SMTP mode test + * 2026-06-15: mmjsonparse: modernize test output paths + * 2026-06-14: parser: add optional trailing CR stripping + * 2026-06-14: ompgsql: accept long server hostnames + * 2026-06-14: dynstats: warn on duplicate bucket names + * 2026-06-14: action: warn on duplicate action names + * 2026-06-13: omfwd: use matching atomic mutex helper + * 2026-06-08: Merge pull request #7014 from rsyslog/cursor/critical-correctness-bugs-480c + * 2026-06-05: omazureeventhubs docs: fix underscored parameters + * 2026-06-04: runtime: fix YAML promotion OOM ownership + * 2026-06-04: omuxsock docs: correct template parameter + * 2026-06-04: omhttp: own Splunk profile template names + * 2026-06-04: mmjsonparse: reject boundary trailing data + * 2026-06-04: mmdblookup: preserve uint64 values + * 2026-06-04: mmdblookup: check uint64 fallback formatting + * 2026-06-04: impstats docs: fix dotted log parameters + * 2026-06-04: impstats docs: clarify parameter name guidance + * 2026-06-04: imkafka: stop workers on startup failure + * 2026-06-04: imkafka: refine startup stop flag handling + * 2026-06-04: doc: match Sphinx duplicate CLI override handling + * 2026-06-04: doc: keep stable git docs out of dev mode + * 2026-06-04: doc: format stable rst_prolog metadata + * 2026-06-04: doc: fix database tutorial SQL template option + * 2026-06-03: regexp: avoid per-thread shutdown double-free + * 2026-06-03: omkafka: fix NULL topic and add action name to onDestroy flush logs + * 2026-06-03: mmsnareparse: honor searchWindow in tabbed trailing scan + * 2026-06-03: mmsnareparse: cap tab trailing search by token + * 2026-06-03: imfifo: guard absent module config paths + * 2026-06-03: imfifo: bind instances to module config + * 2026-06-03: imdiag: fix stats reporting gate + * 2026-06-03: imdiag: avoid checked cond signal while locked + * 2026-06-03: docker: gate collector imtcp module + * 2026-06-03: docker: derive single imtcp enable switch + * 2026-06-03: docker: default derived imtcp switch in collector + * 2026-06-02: yamlconf: clean up include recursion guard + * 2026-06-02: tls: propagate wolfSSL send-side read retry + * 2026-06-02: tls: keep wolfSSL send retry local + * 2026-06-02: tls: bound wolfSSL send-side read retries + * 2026-06-02: sidecar: cap UDP burst buffer by total bytes + * 2026-06-02: runtime: include limits.h for INT_MAX in yamlconf + * 2026-06-02: runtime: guard against recursive YAML includes + * 2026-06-02: runtime/queue: reset sizeOnDisk after safe recovery + * 2026-06-02: rainerscript: accept optimizer NOP statements + * 2026-06-02: omkafka: fix HUP deadlock when doAction holds mut_doAction (#7129) + * 2026-06-02: omhttp: avoid retry-ruleset self-stall + * 2026-06-02: omhiredis: fix TLS context error log + * 2026-06-02: mmpstrucdata: support custom SD containers + * 2026-06-02: mmjsonparse: fix find-json ownership and scan bounds + * 2026-06-02: mmjsonparse: clear JSON pointer after ownership transfer + * 2026-06-02: devtools: fold local review experiment into planner + * 2026-06-01: translate: cover script serialization (#7152) + * 2026-06-01: dev_env: include lcov in Ubuntu coverage images + * 2026-06-01: ChangeLog: update 8.2606 entries + * 2026-06-01: Add parse_time_localtz with documentation + * 2026-05-31: runtime: join final worker after shutdown wait + * 2026-05-31: runtime: harden raw message replacement growth + * 2026-05-31: runtime: fix $!all-json serialization locking + * 2026-05-31: ratelimit: centralize per-source enforcement + * 2026-05-31: parser: fix NetAddr cleanup on mask parse errors + * 2026-05-31: omclickhouse: report HTTP response errors + * 2026-05-31: omclickhouse: document SQL template option + * 2026-05-31: omclickhouse: clean up JSON root on OOM + * 2026-05-31: action: avoid committing suspended retry batches + * 2026-05-31: Keep transactional action queue messages on shutdown + * 2026-05-30: rainerscript: add tocef() and cef_ext_escape() for CEF output + * 2026-05-30: doc: clarify queue crash durability limits + * 2026-05-30: devtools: add read-only C format check + * 2026-05-29: tls: propagate send-side receive retry + * 2026-05-29: tls: preserve send-side receive retry state + * 2026-05-29: tls: preserve send retry without reconnect + * 2026-05-29: tls: keep wolfSSL send-side retry local + * 2026-05-29: tls: keep send-side read retries local + * 2026-05-29: template: apply style-check formatting + * 2026-05-29: style: format msg replacement tests + * 2026-05-29: runtime: fix msg replace helper CI failures + * 2026-05-29: omkafka: fix suspension not triggered on host resolution failure + * 2026-05-29: omfwd: schedule retry for deferred TCP flush + * 2026-05-29: omfwd: preserve connection on retryable TLS sends + * 2026-05-29: omfwd: avoid tcpclt leak on rebind + * 2026-05-29: mmsnareparse: preserve regex end-anchor semantics + * 2026-05-29: imudp: validate listen port formatting + * 2026-05-29: imudp: harden listen port file writes + * 2026-05-29: imptcp: simplify compression auto probe + * 2026-05-29: imkafka: support multiple topics in one input() instance + * 2026-05-29: imjournal: warn when newest entry is in the future + * 2026-05-29: imjournal: handle clock jumps in future probe + * 2026-05-29: docs: strengthen GHSA prompt guardrails + * 2026-05-29: add func doFunct_ParseTimeLocalTz + * 2026-05-29: Update doc/security/ghsa-coordination-review-template.md + * 2026-05-29: Fix rawmsg suffix shift on realloc + * 2026-05-29: Fix msg replacement and JSON set handling + * 2026-05-29: Apply suggested fix to tests/mmexternal-response-too-long.sh from Copilot Autofix + * 2026-05-28: tls: keep send retry state internal + * 2026-05-28: template: reject invalid regex match selectors + * 2026-05-28: template: guard NULL property rendering + * 2026-05-28: packaging: use ETL Vespa env defaults directly + * 2026-05-28: packaging: default ETL TLS envs in entrypoint + * 2026-05-28: omelasticsearch: apply clang-format to version probe error + * 2026-05-28: mmjsontransform: fix dotted conflict ownership + * 2026-05-28: mmexternal: fix single-instance reply handling + * 2026-05-28: mmexternal: fix EINTR reply handling + * 2026-05-28: mmdblookup: clean up failed worker creation + * 2026-05-28: imuxsock: handle embedded NUL datagrams safely + * 2026-05-28: imptcp: harden auto compression probe + * 2026-05-27: tls: preserve recv data during send-side reads + * 2026-05-27: tls: avoid recv-helper misuse in send WANT_READ + * 2026-05-27: tls: avoid receive retry state during send + * 2026-05-27: template: fix jsonftree flat fallback framing + * 2026-05-27: runtime: reject embedded NULs in mbedtls cert names + * 2026-05-27: runtime: initialize ratelimit mutex once + * 2026-05-27: runtime: guard per-thread regexp iterator allocation + * 2026-05-27: runtime: fix fromhost-port extraction before rcvFrom union swap + * 2026-05-27: runtime: clean up DNS props on port allocation failure + * 2026-05-27: runtime-format-regexp-lifecycle-guards + * 2026-05-27: regexp-clean-up-per-thread-entries + * 2026-05-27: packaging: expose Vespa HTTPS toggles + * 2026-05-27: packaging: enable HTTPS by default for ETL Vespa output + * 2026-05-27: omusrmsg: enable thread-safe action ratelimiter + * 2026-05-27: omotel: use getProgramName() when deriving app name + * 2026-05-27: omotel: avoid const cast for app name extraction + * 2026-05-27: ommysql: handle closed connection before commit + * 2026-05-27: omkafka: harden failed delivery replay paths + * 2026-05-27: omhttp: refresh health-check headers after gzip rebuild + * 2026-05-27: omhttp: keep health-check headers uncompressed + * 2026-05-27: omelasticsearch: bound startup version probe response size + * 2026-05-27: mmsnareparse: skip full digit runs in event probe + * 2026-05-27: mmsnareparse: preserve anchored trailing regex matches + * 2026-05-27: mmsnareparse: cap regex input in trailing token + * 2026-05-27: mmsnareparse: avoid quadratic provider scans in snare probe + * 2026-05-27: mmjsontransform: fix child ownership on dotted merge conflicts + * 2026-05-27: mmjsontransform: clean up dotted insert ownership + * 2026-05-27: mmanon: remove assert on malformed embedded IPv4 + * 2026-05-27: mmanon: make random suffix generation fully reachable + * 2026-05-27: mmanon: build random suffix from byte chunks + * 2026-05-27: mbedtls-refine-nul-name-checks + * 2026-05-27: mbedtls-apply-cert-name-style + * 2026-05-27: lookup: report active table reloads as pending + * 2026-05-27: lmsig-ksi-bound-debug-precision + * 2026-05-27: imptcp: serialize helper work per session + * 2026-05-27: imptcp: add stream:auto compression mode + * 2026-05-27: imfifo: implement named pipe input module (#7029) + * 2026-05-27: dynstats: coalesce pending persistence writes per bucket + * 2026-05-27: dynstats-unlock-on-task-alloc-failure + * 2026-05-27: docker: fix clickhouse configure flag in Debian 13 dev image + * 2026-05-27: doc: use literal markup for TLS parameters + * 2026-05-27: doc: fix shutdown.enable.ctlc spelling in rsyslogd man page + * 2026-05-27: doc: fix mmrfc5424addhmac sd_id parameter name + * 2026-05-27: doc: clarify mbedtls requires StreamDriverMode=1 for TLS + * 2026-05-27: configure: detect relpCltSetKeepAlive support + * 2026-05-26: stats: avoid notifier teardown deadlocks + * 2026-05-26: runtime: guard optional regexp object lifecycle in tcp server + * 2026-05-26: runtime: bound KSI debug record logging by length + * 2026-05-26: runtime: avoid regexp unload double free + * 2026-05-26: ratelimit: avoid double free on helper error paths + * 2026-05-26: perctile: reuse counter cleanup helper + * 2026-05-26: perctile: link buckets after initialization + * 2026-05-26: ossl: avoid caching OCSP responses past nextUpdate + * 2026-05-26: omazuredce: bound HTTP response buffering + * 2026-05-26: omazuredce: avoid gzip buffer underallocation + * 2026-05-26: omazuredce-review-followup + * 2026-05-26: imuxsock: enforce ratelimit.name for credentialed senders + * 2026-05-26: imuxsock-ratelimit-credential-followup + * 2026-05-26: impstats: fix double-free in remote write batching cleanup + * 2026-05-26: imkafka: cap split.json.records fan-out + * 2026-05-26: imdocker: keep stream alive on rate-limit drops + * 2026-05-26: imdocker: bound multiline segment compaction + * 2026-05-26: imdocker: apply clang-format output + * 2026-05-26: configure: avoid leaking -lgcrypt into global LIBS + * 2026-05-25: shellcheck: fix masked test assignments + * 2026-05-25: runtime: validate numeric hardening inputs + * 2026-05-25: runtime/nsd_gtls: validate IP SAN length before conversion + * 2026-05-25: parser: verify and fix offAfterPRI calculation + * 2026-05-25: omhiredis: derive TLS server name from server config + * 2026-05-25: omfwd: require peers for targetSrv TLS name auth + * 2026-05-25: omfwd: clarify targetSrv TLS auth error + * 2026-05-25: nsd_gtls: preserve SAN-present state for malformed IP SAN + * 2026-05-25: imhttp: write bound listener port to file + * 2026-05-25: imdtls: write bound listener port to file + * 2026-05-25: fix(imhiredis): default TLS peer name to configured server + * 2026-05-24: tools: make AIX SRC reply copy bounded + * 2026-05-24: statsobj: clear lock flag after prometheus unlock + * 2026-05-24: runtime: clamp emulated RFC5424 tag length + * 2026-05-24: runtime: avoid post-fork malloc in execProg + * 2026-05-24: runtime/statsobj: lock stats list during iteration + * 2026-05-24: nsd_mbedtls: reject RemoteSNI and wire interface + * 2026-05-24: nsd_mbedtls: fill remote port interface methods + * 2026-05-24: mmjsontransform: track per-insert conflicts + * 2026-05-24: mmjsontransform: avoid leak on policy insert conflict + * 2026-05-24: mmjsonparse: avoid json double-free on add failure + * 2026-05-24: mmexternal: avoid undrained stdout/stderr pipe in output=none mode + * 2026-05-24: mmexternal: address output pipe review findings + * 2026-05-24: impstats: harden overwrite temp file creation + * 2026-05-24: imjournal: treat rate-limit discards as non-fatal in readjournal + * 2026-05-24: gssapi: use uint32_t for token wire length + * 2026-05-24: gssapi: fix token length framing endianness in sender + * 2026-05-24: fix(tools): guard AIX SRC reply text against NULL + * 2026-05-23: rainerscript: fix array and numeric comparisons on JSON vars + * 2026-05-23: privdrop: update privilege drop comments + * 2026-05-23: privdrop: log capability context on drop failure + * 2026-05-23: omelasticsearch: guard dynamic template strings + * 2026-05-23: omelasticsearch: cache action template count + * 2026-05-23: imjournal: restore cursor after recovery reopen + * 2026-05-23: imjournal: recover from stale saved cursor + * 2026-05-23: imjournal: harden journal invalidation recovery + * 2026-05-23: imjournal: avoid rotation accounting during recovery + * 2026-05-23: docs: clarify local validation gates + * 2026-05-23: contrib, runtime: defensive stability and robustness hardening + * 2026-05-23: codex: wire local container testing hook into agent workflow + * 2026-05-22: shell: clean up ShellCheck findings + * 2026-05-22: python: clean up style and add optional checks + * 2026-05-22: net_ossl: document SAN-priority hard-stop on old API + * 2026-05-22: msg: guard MSG replacement offsets (bsc#1272414) + * 2026-05-22: mmexternal: support one-way helpers and response timeouts + * 2026-05-22: imptcp: unlink failed accepted sessions + * 2026-05-22: imjournal: fix double-free hazards on JSON objects + * 2026-05-22: imfile: add line-number metadata and soften empty checks + * 2026-05-22: imdocker: terminate compacted multiline buffers + * 2026-05-22: imbeats: harden pointer transfer in submitEvent + * 2026-05-22: contrib, plugins: refine pointer hand-off in imhiredis, mmjsonparse, mmsequence + * 2026-05-22: contrib, plugins: defensive pointer hand-off hardening + * 2026-05-22: config: warn for unmatched include globs + * 2026-05-22: agents: document optional local linters + * 2026-05-21: template: harden property rendering bounds + * 2026-05-21: tcpsrv: guard listener destructors against NULL references + * 2026-05-21: tcps_sess: secure regex memory reallocation and destructor + * 2026-05-21: style: format wolfSSL CRL helper + * 2026-05-21: ruleset: guard synchronous recursive calls + * 2026-05-21: rainerscript: harden string and JSON bounds + * 2026-05-21: pm/fm: defensively harden parsing edge cases + * 2026-05-21: ossl: enable wolfSSL CRL checks for DER files + * 2026-05-21: net_ossl: avoid CN fallback when SAN priority unsupported + * 2026-05-21: mmgrok: keep configured source immutable + * 2026-05-21: lookup: harden shutdown lifecycle + * 2026-05-21: imudp: harden thread lifecycles and fix stats memory leak + * 2026-05-21: imtcp: harden listener setup and legacy config cleanup + * 2026-05-21: imjournal: defensive memory safety and stability hardening + * 2026-05-21: docs: codify GHSA coordination workflow + * 2026-05-21: docs: clarify GHSA triage scope + * 2026-05-21: docs: add distro component package map + * 2026-05-21: docs: add GHSA coordination template + * 2026-05-21: contrib: harden buffer and parser bounds handling + * 2026-05-21: agent: document local CI preflight tiers + * 2026-05-21: Update tests/imptcp_uds_unlink.sh + * 2026-05-21: Apply suggested fix to tests/imptcp_uds_unlink.sh from Copilot Autofix + * 2026-05-20: ossl: bound OCSP network reads + * 2026-05-20: mmanon: defensively harden IP suffix parsing + * 2026-05-20: lookup: reject duplicate table names + * 2026-05-20: imptcp: harden concurrency, boundaries, and memory safety + * 2026-05-20: gtls: log peer IP for missing client cert + * 2026-05-20: config: add global maxOpenFiles setting + * 2026-05-20: build: fix ARMv7 warnings under Werror + * 2026-05-20: agents: add ChangeLog maintenance skill + * 2026-05-20: Update tests/imptcp-discard-truncated-msg-same-session.sh + * 2026-05-20: ChangeLog: update 8.2606 entries + * 2026-05-20: Apply suggested fix to tests/imptcp-discard-truncated-msg-same-session.sh from Copilot Autofix + * 2026-05-20: Apply suggested fix to doc/source/reference/templates/templates-reserved-names.rst from Copilot Autofix + * 2026-05-19: imptcp: discard oversize byte after truncation + * 2026-05-18: tcp: log pre-truncated oversize frames + * 2026-05-18: runtime: avoid libgcry IV shift UB + * 2026-05-18: grammar: read pseudo-files in backtick cat + * 2026-05-18: docker: add container regex noise filter + * 2026-05-18: doc: remove unavailable StdJSONFmt reference + * 2026-05-18: agents: require available container validation + * 2026-05-18: agents: clarify PR babysitting decisions + * 2026-05-18: ChangeLog: remove duplicate release blocks + * 2026-05-18: Apply suggested fix to doc/source/reference/templates/templates-reserved-names.rst from Copilot Autofix + * 2026-05-17: omelasticsearch: document error-file modes + * 2026-05-17: doc: list RFC5424 reserved template + * 2026-05-17: doc: clarify omfile timed flush behavior + * 2026-05-17: doc: clarify omfile legacy action separation ++++ 860 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/rsyslog/rsyslog.changes ++++ and /work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog.changes Old: ---- rsyslog-8.2502.0.tar.gz rsyslog-doc-8.2502.0.tar.gz New: ---- rsyslog-8.2606.0.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ rsyslog.spec ++++++ --- /var/tmp/diff_new_pack.sdbHn4/_old 2026-07-29 18:59:46.174721992 +0200 +++ /var/tmp/diff_new_pack.sdbHn4/_new 2026-07-29 18:59:46.174721992 +0200 @@ -24,7 +24,7 @@ %define requires_file() %( readlink -f '%*' | LC_ALL=C xargs -r rpm -q --qf 'Requires: %%{name} >= %%{epoch}:%%{version}\\n' -f | sed -e 's/ (none):/ /' -e 's/ 0:/ /' | grep -v "is not") # drop this with next release when doc tarball version lines up -%define rsyslog_major 8.2502 +%define rsyslog_major 8.2606 %define rsyslog_patch 0 Name: rsyslog Summary: The enhanced syslogd for Linux and Unix @@ -72,6 +72,11 @@ # TODO: ... doesnt have a proper configure check but wants hdfs.h %bcond_with hdfs %bcond_with mongodb +%if 0%{?suse_version} && 0%{?suse_version} < 1500 + %bcond_with protobuf +%else + %bcond_without protobuf +%endif %bcond_with hiredis %bcond_with zeromq @@ -101,8 +106,19 @@ BuildRequires: bison BuildRequires: curl-devel BuildRequires: flex +BuildRequires: libyaml-devel BuildRequires: libzstd-devel BuildRequires: pkgconfig +BuildRequires: pkgconfig(yaml-0.1) +%if %{with protobuf} +%if 0%{?suse_version} +BuildRequires: protobuf-c +%else +BuildRequires: protobuf-c-devel +%endif +BuildRequires: snappy-devel +BuildRequires: pkgconfig(libprotobuf-c) >= 1.0.0 +%endif BuildRequires: zlib-devel %if %{with rfc3195} %if %{with pkgconfig} @@ -215,13 +231,11 @@ Source7: module-mysql Source8: module-snmp Source9: module-udpspoof -Source14: https://www.rsyslog.com/files/download/rsyslog/rsyslog-doc-%{rsyslog_major}.0.tar.gz Source16: journald-rsyslog.conf Source17: acpid.frule Source18: firewall.frule Source19: NetworkManager.frule Source20: rsyslog-tmpfiles.conf - Patch0: 0001-imptcp-guard-regex-framing-match-at-line-start.patch # this is a dirty hack since % dir does only work for the specified directory and nothing above @@ -251,8 +265,6 @@ This package provides additional documentation for rsyslog. -%if %{with diagtools} - %package diag-tools Requires: %{name} = %{version} Summary: Diagnostic tools @@ -265,14 +277,10 @@ This package provides additional diagnostic tools (small helpers, usually not needed). -%endif - -%if %{with dtls} - %package module-dtls Requires: %{name} = %{version} Requires: rsyslog-module-ossl -Summary: dtls support module for rsyslog +Summary: DTLS support module for rsyslog Group: System/Daemons %description module-dtls @@ -282,10 +290,6 @@ This module provides support for securely transporting syslog messages over the network using the Datagram Transport Layer Security (DTLS) protocol. -%endif - -%if %{with gssapi} - %package module-gssapi Requires: %{name} = %{version} Summary: GSS-API support module for rsyslog @@ -298,10 +302,6 @@ This module provides the support to receive syslog messages from the network protected via Kerberos 5 encryption and authentication. -%endif - -%if %{with mysql} - %package module-mysql Requires: %{name} = %{version} Summary: MySQL support module for rsyslog @@ -314,10 +314,6 @@ This package provides a module with the support for logging into MySQL databases. -%endif - -%if %{with pgsql} - %package module-pgsql Requires: %{name} = %{version} Summary: PostgreSQL support module for rsyslog @@ -329,10 +325,6 @@ This module provides the support for logging into PostgreSQL databases. -%endif - -%if %{with dbi} - %package module-dbi Requires: %{name} = %{version} Summary: Database support via DBI @@ -345,10 +337,6 @@ This package provides a module with the support for logging into DBI supported databases. -%endif - -%if %{with snmp} - %package module-snmp Requires: %{name} = %{version} Summary: SNMP support module for rsyslog @@ -361,10 +349,6 @@ This module provides the ability to send syslog messages as an SNMPv1 & v2c traps. -%endif - -%if %{with gnutls} - %package module-gtls Requires: %{name} = %{version} Summary: TLS encryption support module for rsyslog @@ -376,9 +360,6 @@ This module provides the ability for TLS encrypted TCP logging using the GnuTLS library. -%endif - -%if %{with openssl} %package module-ossl Requires: %{name} = %{version} @@ -391,9 +372,6 @@ This module provides the ability for TLS encrypted TCP logging using the OpenSSL library. -%endif - -%if %{with gcrypt} %package module-gcrypt Requires: %{name} = %{version} @@ -406,16 +384,15 @@ This module provides log file encryption support using libgcrypt and a rsgtutil utility to manage the files. -%endif - -%if %{with relp} %package module-relp Requires: %{name} = %{version} Summary: RELP protocol support module for syslog Group: System/Daemons +%if %{with relp} %requires_file %{_libdir}/librelp.so +%endif %description module-relp Rsyslog is an enhanced multi-threaded syslog daemon. See rsyslog @@ -423,10 +400,6 @@ This module provides Reliable Event Logging Protocol support. -%endif - -%if %{with mmnormalize} - %package module-mmnormalize Requires: %{name} = %{version} Summary: Contains the mmnormalize support module for syslog @@ -438,10 +411,6 @@ This module provides log normalizing support. -%endif - -%if %{with udpspoof} - %package module-udpspoof Requires: %{name} = %{version} Summary: UDP spoof support module for syslog @@ -453,10 +422,6 @@ This module provides a UDP forwarder that allows changing the sender address. -%endif - -%if %{with elasticsearch} - %package module-elasticsearch Requires: %{name} = %{version} Summary: ElasticSearch output module for syslog @@ -468,10 +433,6 @@ This module provides support to output to an ElasticSearch database. -%endif - -%if %{with omhttpfs} - %package module-omhttpfs Requires: %{name} = %{version} Summary: HDFS via HTTP output module for syslog @@ -483,10 +444,6 @@ This module provides support to output to HDFS via HTTP. -%endif - -%if %{with hdfs} - %package module-hdfs Requires: %{name} = %{version} Summary: HDFS output module for syslog @@ -498,10 +455,6 @@ This module provides support to output to an HDFS database. -%endif - -%if %{with mongodb} - %package module-mongodb Requires: %{name} = %{version} Summary: MongoDB output module for syslog @@ -513,10 +466,6 @@ This module provides support to output to a MongoDB database. -%endif - -%if %{with hiredis} - %package module-hiredis Requires: %{name} = %{version} Summary: Redis output module for syslog @@ -528,10 +477,6 @@ This module provides support to output to a Redis database. -%endif - -%if %{with zeromq} - %package module-zeromq Requires: %{name} = %{version} Summary: ZeroMQ support module for syslog @@ -543,10 +488,6 @@ This module provides support for ZeroMQ. -%endif - -%if %{with kafka} - %package module-kafka Requires: %{name} = %{version} Summary: Kafka support module for syslog @@ -558,9 +499,6 @@ This module provides support for Kafka. -%endif - -%if %{with omamqp1} %package module-omamqp1 Requires: %{name} = %{version} Summary: AMQP support module for syslog @@ -571,9 +509,7 @@ package. This module provides support for AMQP. -%endif -%if %{with tcl} %package module-omtcl Requires: %{name} = %{version} Summary: TCL output module for rsyslog @@ -584,7 +520,6 @@ package. This module provides an output module for TCL. -%endif %package devel Requires: glibc-devel @@ -611,7 +546,7 @@ developing the rsyslog logging daemon. %prep -%autosetup -p1 -a 14 +%autosetup -p1 # for file in rsyslog-service-prepare; do sed \ @@ -621,7 +556,7 @@ done %build -export CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing -W -Wall -I../grammar -I../../grammar" +export CFLAGS="%{optflags} -fno-strict-aliasing -W -Wall -I../grammar -I../../grammar" # needs java # --enable-gui \ @@ -753,10 +688,10 @@ --enable-usertools \ --disable-static -make %{?_smp_mflags:%{_smp_mflags}} V=1 +%make_build V=1 %install -make install DESTDIR="%{buildroot}" V=1 +%make_install V=1 # rm -f %{buildroot}%{rsyslog_module_dir_nodeps}/*.la # @@ -814,10 +749,10 @@ fi %if 0%{?suse_version} < 1550 install -d -m0755 %{buildroot}/sbin - ln -sf %{_sbindir}/rsyslogd $RPM_BUILD_ROOT/sbin/rsyslogd + ln -sf %{_sbindir}/rsyslogd %{buildroot}/sbin/rsyslogd %endif # it is simply broken (bnc#890228) -rm -f $RPM_BUILD_ROOT%{_sbindir}/zpipe +rm -f %{buildroot}/%{_sbindir}/zpipe # install -m755 rsyslog-service-prepare %{buildroot}%{_sbindir}/ ln -svf service %buildroot/%{_sbindir}/rc%{name} @@ -850,7 +785,7 @@ find ChangeLog README AUTHORS \ \( -type d -exec install -m755 -d %{buildroot}%{rsyslogdocdir}/\{\} \; \) \ -o \( -type f -exec install -m644 \{\} %{buildroot}%{rsyslogdocdir}/\{\} \; \) -cp -av build/* %{buildroot}%{rsyslogdocdir}/html/ +cp -av doc/source/* %{buildroot}%{rsyslogdocdir}/html/ # %if %{with mysql} install -m644 plugins/ommysql/createDB.sql \ @@ -936,85 +871,26 @@ # to switch when installing it and there is a provider conflict. /usr/bin/systemctl -f enable rsyslog.service >/dev/null 2>&1 || : -%if %{with gssapi} %post_for_mark_daemon_restart module-gssapi -%endif - -%if %{with mysql} %post_for_mark_daemon_restart module-mysql -%endif - -%if %{with pgsql} %post_for_mark_daemon_restart module-pgsql -%endif - -%if %{with dbi} %post_for_mark_daemon_restart module-dbi -%endif - -%if %{with snmp} %post_for_mark_daemon_restart module-snmp -%endif - -%if %{with gnutls} %post_for_mark_daemon_restart module-gtls -%endif - -%if %{with openssl} %post_for_mark_daemon_restart module-ossl -%endif - -%if %{with relp} %post_for_mark_daemon_restart module-relp -%endif - -%if %{with mmnormalize} %post_for_mark_daemon_restart module-mmnormalize -%endif - -%if %{with udpspoof} %post_for_mark_daemon_restart module-udpspoof -%endif - -%if %{with elasticsearch} %post_for_mark_daemon_restart module-elasticsearch -%endif - -%if %{with omhttpfs} %post_for_mark_daemon_restart module-omhttpfs -%endif - -%if %{with hdfs} %post_for_mark_daemon_restart module-hdfs -%endif - -%if %{with mongodb} %post_for_mark_daemon_restart module-mongodb -%endif - -%if %{with hiredis} %post_for_mark_daemon_restart module-hiredis -%endif - -%if %{with zeromq} %post_for_mark_daemon_restart module-zeromq -%endif - -%if %{with kafka} %post_for_mark_daemon_restart module-kafka -%endif - -%if %{with omamqp1} %post_for_mark_daemon_restart module-omamqp1 -%endif - -%if %{with gcrypt} %post_for_mark_daemon_restart module-gcrypt -%endif - -%if %{with tcl} %post_for_mark_daemon_restart module-omtcl -%endif %if 0%{?suse_version} < 1600 %posttrans @@ -1026,8 +902,7 @@ # # stop the rsyslogd daemon when it is running # -%{service_del_preun syslog.socket} -%{service_del_preun rsyslog.service} +%{service_del_preun syslog.socket rsyslog.service} %postun # @@ -1040,7 +915,6 @@ %{service_del_postun rsyslog.service} %files -%defattr(-,root,root) %dir %{_sysconfdir}/rsyslog.d %config(noreplace) %attr(600,root,root) %{_sysconfdir}/rsyslog.conf %config(noreplace) %attr(600,root,root) %{_sysconfdir}/rsyslog.d/remote.conf @@ -1119,14 +993,12 @@ %{_tmpfilesdir}/rsyslog.conf %files doc -%defattr(-,root,root) %dir %{rsyslogdocdir}/ %doc %{rsyslogdocdir}/html/ %if %{with diagtools} %files diag-tools -%defattr(-,root,root) %{_sbindir}/msggen %{_sbindir}/rsyslog_diag_hostname %{rsyslog_module_dir_nodeps}/imdiag.so @@ -1135,7 +1007,6 @@ %if %{with gssapi} %files module-gssapi -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omgssapi.so %{rsyslog_module_dir_withdeps}/imgssapi.so %{rsyslog_module_dir_withdeps}/lmgssutil.so @@ -1144,7 +1015,6 @@ %if %{with mysql} %files module-mysql -%defattr(-,root,root) %doc %{rsyslogdocdir}/mysql-createDB.sql %{rsyslog_module_dir_withdeps}/ommysql.so %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-mysql @@ -1153,7 +1023,6 @@ %if %{with pgsql} %files module-pgsql -%defattr(-,root,root) %doc %{rsyslogdocdir}/pgsql-createDB.sql %{rsyslog_module_dir_withdeps}/ompgsql.so %endif @@ -1161,14 +1030,12 @@ %if %{with dbi} %files module-dbi -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omlibdbi.so %endif %if %{with snmp} %files module-snmp -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omsnmp.so %{rsyslog_module_dir_nodeps}/mmsnmptrapd.so %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-snmp @@ -1177,21 +1044,18 @@ %if %{with gnutls} %files module-gtls -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/lmnsd_gtls.so %endif %if %{with openssl} %files module-ossl -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/lmnsd_ossl.so %endif %if %{with relp} %files module-relp -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/imrelp.so %{rsyslog_module_dir_withdeps}/omrelp.so %endif @@ -1199,16 +1063,15 @@ %if %{with mmnormalize} %files module-mmnormalize -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/mmnormalize.so %{rsyslog_module_dir_withdeps}/mmjsonparse.so +%{rsyslog_module_dir_withdeps}/mmleefparse.so %{rsyslog_module_dir_withdeps}/mmaudit.so %endif %if %{with udpspoof} %files module-udpspoof -%defattr(-,root,root) %{rsyslog_module_dir_nodeps}/omudpspoof.so %config %{APPARMOR_PROFILE_PATH}/rsyslog.d/module-udpspoof %endif @@ -1216,42 +1079,36 @@ %if %{with elasticsearch} %files module-elasticsearch -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omelasticsearch.so %endif %if %{with omhttpfs} %files module-omhttpfs -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omhttpfs.so %endif %if %{with hdfs} %files module-hdfs -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omhdfs.so %endif %if %{with mongodb} %files module-mongodb -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/ommongodb.so %endif %if %{with hiredis} %files module-hiredis -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omhiredis.so %endif %if %{with zeromq} %files module-zeromq -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/imzmq3.so %{rsyslog_module_dir_withdeps}/omzmq3.so %endif @@ -1259,34 +1116,29 @@ %if %{with kafka} %files module-kafka -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/imkafka.so %{rsyslog_module_dir_withdeps}/omkafka.so %endif %if %{with omamqp1} %files module-omamqp1 -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omamqp1.so %endif %if %{with gcrypt} %files module-gcrypt -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/lmcry_gcry.so %{_bindir}/rscryutil %endif %if %{with tcl} %files module-omtcl -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/omtcl.so* %endif %if %{with dtls} %files module-dtls -%defattr(-,root,root) %{rsyslog_module_dir_withdeps}/imdtls.so %{rsyslog_module_dir_withdeps}/omdtls.so %endif ++++++ 0001-imptcp-guard-regex-framing-match-at-line-start.patch ++++++ --- /var/tmp/diff_new_pack.sdbHn4/_old 2026-07-29 18:59:46.202722958 +0200 +++ /var/tmp/diff_new_pack.sdbHn4/_new 2026-07-29 18:59:46.206723095 +0200 @@ -1,49 +1,50 @@ -From 9ef6c7c11f2555f4766b822983f8f49f44df0349 Mon Sep 17 00:00:00 2001 -From: Rainer Gerhards <[email protected]> -Date: Mon, 20 Jul 2026 17:19:28 +0200 -Subject: [PATCH] imptcp: guard regex framing match at line start - -Why -A regex match at the beginning of the receive buffer can form a -negative message length after oversize-frame recovery. - -Impact -Regex-framed imptcp listeners reject that invalid transition instead -of submitting a negative message length. - -Before/After -Before: a match with a zero line offset submitted an invalid length. -After: only a match following an existing line can submit a frame. - -Technical Overview -Mirror the line-offset guard used by the shared imtcp parser. -Leave existing regex framing and oversize recovery behavior unchanged. - -Security advisory: -https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 - -Reported-by: Raphael Eikenberg (@eikendev) -With the help of AI-Agents: Codex - -(cherry picked from commit 07b3c40a5a78c79ed9109251f842ca7e955dd586) ---- - plugins/imptcp/imptcp.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/plugins/imptcp/imptcp.c b/plugins/imptcp/imptcp.c -index 9223f20d0..16d2c327b 100644 ---- a/plugins/imptcp/imptcp.c -+++ b/plugins/imptcp/imptcp.c -@@ -1054,7 +1054,7 @@ processDataRcvd_regexFraming(ptcpsess_t *const __restrict__ pThis, - pThis->iCurrLine = pThis->iMsg; - } else { - const int isMatch = !regexec(&inst->start_preg, (char*)pThis->pMsg+pThis->iCurrLine, 0, NULL, 0); -- if(isMatch) { -+ if (pThis->iCurrLine > 0 && isMatch) { - DBGPRINTF("regex match (%d), framing line: %s\n", pThis->iCurrLine, pThis->pMsg); - strcpy((char*)pThis->pMsg_save, (char*) pThis->pMsg+pThis->iCurrLine); - pThis->iMsg = pThis->iCurrLine - 1; --- -2.55.0 - +From ccfdbe2613ef571655da48de0f753d7f43dc3b0f Mon Sep 17 00:00:00 2001 +From: Rainer Gerhards <[email protected]> +Date: Mon, 20 Jul 2026 17:19:28 +0200 +Subject: [PATCH] imptcp: guard regex framing match at line start + +Why +A regex match at the beginning of the receive buffer can form a +negative message length after oversize-frame recovery. + +Impact +Regex-framed imptcp listeners reject that invalid transition instead +of submitting a negative message length. + +Before/After +Before: a match with a zero line offset submitted an invalid length. +After: only a match following an existing line can submit a frame. + +Technical Overview +Mirror the line-offset guard used by the shared imtcp parser. +Leave existing regex framing and oversize recovery behavior unchanged. + +Security advisory: +https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 + +Reported-by: Raphael Eikenberg (@eikendev) +With the help of AI-Agents: Codex + +(cherry picked from commit 07b3c40a5a78c79ed9109251f842ca7e955dd586) +(cherry picked from commit 9ef6c7c11f2555f4766b822983f8f49f44df0349) +--- + plugins/imptcp/imptcp.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/plugins/imptcp/imptcp.c b/plugins/imptcp/imptcp.c +index 91aa55157..d291979dd 100644 +--- a/plugins/imptcp/imptcp.c ++++ b/plugins/imptcp/imptcp.c +@@ -1050,7 +1050,7 @@ static rsRetVal ATTR_NONNULL() processDataRcvd_regexFraming(ptcpsess_t *const __ + pThis->iCurrLine = pThis->iMsg; + } else { + const int isMatch = !regexec(&inst->start_preg, (char *)pThis->pMsg + pThis->iCurrLine, 0, NULL, 0); +- if (isMatch) { ++ if (pThis->iCurrLine > 0 && isMatch) { + DBGPRINTF("regex match (%d), framing line: %s\n", pThis->iCurrLine, pThis->pMsg); + memmove(pThis->pMsg_save, pThis->pMsg + pThis->iCurrLine, ustrlen(pThis->pMsg + pThis->iCurrLine) + 1); + pThis->iMsg = pThis->iCurrLine - 1; +-- +2.55.0 + ++++++ rsyslog-8.2502.0.tar.gz -> rsyslog-8.2606.0.tar.gz ++++++ /work/SRC/openSUSE:Factory/rsyslog/rsyslog-8.2502.0.tar.gz /work/SRC/openSUSE:Factory/.rsyslog.new.2004/rsyslog-8.2606.0.tar.gz differ: char 12, line 1
