Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package nng for openSUSE:Factory checked in 
at 2026-09-11 18:01:54
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/nng (Old)
 and      /work/SRC/openSUSE:Factory/.nng.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "nng"

Fri Sep 11 18:01:54 2026 rev:10 rq:1376949 version:1.12.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/nng/nng.changes  2026-06-29 17:34:04.665679603 
+0200
+++ /work/SRC/openSUSE:Factory/.nng.new.1265/nng.changes        2026-09-11 
18:05:15.343676677 +0200
@@ -1,0 +2,48 @@
+Mon Aug 31 09:06:53 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 1.12.2
+  * Security fix backported from the development branch: the HTTP
+    server handed request URIs to the handlers uncanonified, so a
+    request with "../" segments - plain or percent-encoded as
+    "%2e%2e" - could escape a directory served by
+    nng_http_handler_alloc_directory() and return any file the
+    server process could read (gh#nanomsg/nng#2303).  URIs are now
+    canonified while the request line is parsed.  No CVE has been
+    assigned.  Comes with http_msg_test, a regression test
+    covering both traversal spellings.
+  * Report the correct version: v1.12.0 and v1.12.1 both shipped
+    include/nng/nng.h still declaring 1.11.0, so nng_version() and
+    the installed CMake package version were wrong and
+    find_package(nng 1.12) failed.
+  * v1.12.1 was tagged on the wrong commit and so missed that
+    bump, which is why 1.12.2 exists; the security fix itself was
+    already complete in 1.12.1.  The ABI soversion is unchanged
+    at 1.
+- Spec cleanup:
+  * Drop the obsolete Group tags.
+  * Use %autosetup, %cmake_build and %ldconfig_scriptlets.
+  * Build and run the offline part of the upstream test suite in
+    %check; the transport, protocol, nngcat and stress tests bind
+    fixed loopback ports, and some of them additionally reach out
+    to public DNS and httpbin.org, so they are not selected.
+    reconnect_test is excluded on top of that: it gives
+    listen+send+recv a hard 100 ms budget, which a slow worker
+    misses - it flipped red on half the s390x builds of an
+    unchanged tree.
+  * Require cmake >= 3.15, the minimum upstream checks for.
+  * Drop the commented-out pkgconfig entry from %files, nng does
+    not install a .pc file.
+- Split nngcat out of nng-devel into a new nng-utils subpackage:
+  nngcat is a runtime tool for sending and receiving messages over
+  Scalability Protocol sockets, not a development file, and it
+  only sat in nng-devel because the spec builds no main package.
+  * nng-devel hard-requires the matching nng-utils, so an existing
+    nng-devel install keeps the binary across the upgrade and the
+    build root matches a system install - a Recommends is not
+    pulled into the build environment.  nng-utils can also be
+    installed on its own, without the headers.
+  * The upstream nngcat.1 man page is still not built:
+    NNG_ENABLE_DOC is all or nothing, needs asciidoctor and
+    renders all 325 manual pages plus an HTML copy of each.
+
+-------------------------------------------------------------------

Old:
----
  nng-1.12.0.tar.gz

New:
----
  nng-1.12.2.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ nng.spec ++++++
--- /var/tmp/diff_new_pack.c4fIwp/_old  2026-09-11 18:05:16.024705147 +0200
+++ /var/tmp/diff_new_pack.c4fIwp/_new  2026-09-11 18:05:16.026705231 +0200
@@ -19,14 +19,13 @@
 
 %define sover 1
 Name:           nng
-Version:        1.12.0
+Version:        1.12.2
 Release:        0
 Summary:        Nanomsg NG - brokerless messaging
 License:        MIT
-Group:          Development/Languages/C and C++
 URL:            https://nanomsg.github.io/nng/
 Source:         
https://github.com/nanomsg/nng/archive/v%{version}.tar.gz#/%{name}-%{version}.tar.gz
-BuildRequires:  cmake
+BuildRequires:  cmake >= 3.15
 BuildRequires:  gcc-c++
 BuildRequires:  pkgconfig
 
@@ -36,7 +35,6 @@
 
 %package -n libnng%{sover}
 Summary:        Shared library for nng
-Group:          System/Libraries
 
 %description -n libnng%{sover}
 nng (nanomsg next-generation) is a C socket library providing
@@ -44,24 +42,53 @@
 
 %package devel
 Summary:        Header files for nng
-Group:          Development/Libraries/C and C++
+# nngcat lived in -devel before the split, so -devel must keep pulling it.
+# Hard dep rather than Recommends: OBS does not install recommends into the
+# build root, so a Recommends would make it differ from a system install.
+Requires:       %{name}-utils = %{version}
 Requires:       libnng%{sover} = %{version}
 
 %description devel
 Development and header files for nng (nanomsg next-generation).
 
+%package utils
+Summary:        Command line access to Scalability Protocols
+Requires:       libnng%{sover} = %{version}
+
+%description utils
+nngcat, a command line tool that sends and receives messages over nng
+(nanomsg next-generation) sockets.  It speaks every Scalability Protocol
+the library implements, which makes it useful for probing, testing and
+debugging applications built on nng.
+
 %prep
-%setup -q
+%autosetup
 
 %build
-%cmake
-make %{?_smp_mflags}
+%cmake \
+    -DNNG_TESTS:BOOL=ON
+%cmake_build
 
 %install
 %cmake_install
 
-%post   -n libnng%{sover} -p /sbin/ldconfig
-%postun -n libnng%{sover} -p /sbin/ldconfig
+%check
+# The %%ctest macro takes no extra flags, so drive ctest directly.  Restricted
+# to the offline unit tests: the transport, protocol, nngcat and stress tests
+# bind fixed loopback ports, and resolver_test/tcp_test/httpclient need public
+# DNS and httpbin.org, so they cannot gate a build worker.  The selected set
+# covers the URL/HTTP message parsing fixed in 1.12.1.
+# reconnect_test is excluded on top of that: test_reconnect_back_off_zero
+# gives listen+send+recv a hard 100 ms budget (NUTS_BEFORE at
+# reconnect_test.c:154), which a slow worker misses - it flipped red on half
+# the s390x builds of an unchanged source tree.
+# Offline is not the same as deterministic: aio_test keeps upper bounds of
+# 500-1000 ms (upstream itself skips two of them off GitHub macOS), so it is
+# the next candidate if s390x flakes again.
+ctest --test-dir %{__builddir} --output-on-failure --force-new-ctest-process 
-j1 \
+    -R "^nng\.(core|supplemental)\." -E "^nng\.core\.reconnect_test$"
+
+%ldconfig_scriptlets -n libnng%{sover}
 
 %files -n libnng%{sover}
 %doc README.adoc
@@ -71,8 +98,9 @@
 %files devel
 %{_includedir}/nng
 %{_libdir}/libnng.so
+%{_libdir}/cmake/nng/
+
+%files utils
+%license LICENSE.txt
 %{_bindir}/nngcat
-#%%{_libdir}/pkgconfig/nng.pc
-%dir %{_libdir}/cmake/nng
-%{_libdir}/cmake/nng/nng-*.cmake
 

++++++ nng-1.12.0.tar.gz -> nng-1.12.2.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/.github/workflows/coverage.yml 
new/nng-1.12.2/.github/workflows/coverage.yml
--- old/nng-1.12.0/.github/workflows/coverage.yml       2026-06-09 
23:32:43.000000000 +0200
+++ new/nng-1.12.2/.github/workflows/coverage.yml       2026-08-22 
22:58:48.000000000 +0200
@@ -38,7 +38,7 @@
         uses: actions/checkout@v1
 
       - name: Install mbedTLS
-        run: brew install mbedtls
+        run: brew install mbedtls@2
 
       - name: Install ninja
         run: brew install ninja
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/etc/pubrefman/go.mod 
new/nng-1.12.2/etc/pubrefman/go.mod
--- old/nng-1.12.0/etc/pubrefman/go.mod 2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/etc/pubrefman/go.mod 2026-08-22 22:58:48.000000000 +0200
@@ -1,48 +1,32 @@
 module go.nanomsg.org/nng/pubrefman
 
-go 1.21
-
-toolchain go1.22.0
+go 1.25.0
 
 require (
-       github.com/bytesparadise/libasciidoc v0.8.0
-       github.com/go-git/go-billy/v5 v5.6.1
-       github.com/go-git/go-git/v5 v5.13.1
+       github.com/go-git/go-billy/v5 v5.9.0
+       github.com/go-git/go-git/v5 v5.19.2
        github.com/google/uuid v1.3.1
        github.com/spf13/jwalterweatherman v1.1.0
 )
 
 require (
        dario.cat/mergo v1.0.0 // indirect
-       github.com/Microsoft/go-winio v0.6.1 // indirect
-       github.com/ProtonMail/go-crypto v1.1.3 // indirect
-       github.com/alecthomas/chroma/v2 v2.9.1 // indirect
-       github.com/cloudflare/circl v1.3.7 // indirect
-       github.com/cyphar/filepath-securejoin v0.3.6 // indirect
-       github.com/davecgh/go-spew v1.1.1 // indirect
-       github.com/dlclark/regexp2 v1.10.0 // indirect
+       github.com/Microsoft/go-winio v0.6.2 // indirect
+       github.com/ProtonMail/go-crypto v1.1.6 // indirect
+       github.com/cloudflare/circl v1.6.3 // indirect
+       github.com/cyphar/filepath-securejoin v0.6.1 // indirect
        github.com/emirpasic/gods v1.18.1 // indirect
        github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect
-       github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 // 
indirect
-       github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // 
indirect
-       github.com/google/pprof v0.0.0-20230912144702-c363fe2c2ed8 // indirect
+       github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // 
indirect
        github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 // 
indirect
        github.com/kevinburke/ssh_config v1.2.0 // indirect
-       github.com/mna/pigeon v1.1.0 // indirect
-       github.com/onsi/ginkgo/v2 v2.12.0 // indirect
-       github.com/pjbgf/sha1cd v0.3.0 // indirect
-       github.com/pkg/errors v0.9.1 // indirect
+       github.com/klauspost/cpuid/v2 v2.3.0 // indirect
+       github.com/pjbgf/sha1cd v0.6.0 // indirect
        github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 // 
indirect
-       github.com/sirupsen/logrus v1.9.3 // indirect
-       github.com/skeema/knownhosts v1.3.0 // indirect
+       github.com/skeema/knownhosts v1.3.1 // indirect
        github.com/xanzy/ssh-agent v0.3.3 // indirect
-       golang.org/x/crypto v0.31.0 // indirect
-       golang.org/x/mod v0.17.0 // indirect
-       golang.org/x/net v0.33.0 // indirect
-       golang.org/x/sync v0.10.0 // indirect
-       golang.org/x/sys v0.28.0 // indirect
-       golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d // indirect
-       google.golang.org/protobuf v1.36.1 // indirect
+       golang.org/x/crypto v0.53.0 // indirect
+       golang.org/x/net v0.56.0 // indirect
+       golang.org/x/sys v0.46.0 // indirect
        gopkg.in/warnings.v0 v0.1.2 // indirect
-       gopkg.in/yaml.v2 v2.4.0 // indirect
 )
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/etc/pubrefman/go.sum 
new/nng-1.12.2/etc/pubrefman/go.sum
--- old/nng-1.12.0/etc/pubrefman/go.sum 2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/etc/pubrefman/go.sum 2026-08-22 22:58:48.000000000 +0200
@@ -1,67 +1,47 @@
 dario.cat/mergo v1.0.0 h1:AGCNq9Evsj31mOgNPcLyXc+4PNABt905YmuqPYYpBWk=
 dario.cat/mergo v1.0.0/go.mod h1:uNxQE+84aUszobStD9th8a29P2fMDhsBdgRYvZOxGmk=
-github.com/DataDog/gostackparse v0.5.0 
h1:jb72P6GFHPHz2W0onsN51cS3FkaMDcjb0QzgxxA4gDk=
-github.com/DataDog/gostackparse v0.5.0/go.mod 
h1:lTfqcJKqS9KnXQGnyQMCugq3u1FP6UZMfWR0aitKFMM=
 github.com/Microsoft/go-winio v0.5.2/go.mod 
h1:WpS1mjBmmwHBEWmogvA2mj8546UReBk4v8QkMxJ6pZY=
-github.com/Microsoft/go-winio v0.6.1 
h1:9/kr64B9VUZrLm5YYwbGtUJnMgqWVOdUAXu6Migciow=
-github.com/Microsoft/go-winio v0.6.1/go.mod 
h1:LRdKpFKfdobln8UmuiYcKPot9D2v6svN5+sAH+4kjUM=
-github.com/ProtonMail/go-crypto v1.1.3 
h1:nRBOetoydLeUb4nHajyO2bKqMLfWQ/ZPwkXqXxPxCFk=
-github.com/ProtonMail/go-crypto v1.1.3/go.mod 
h1:rA3QumHc/FZ8pAHreoekgiAbzpNsfQAosU5td4SnOrE=
-github.com/alecthomas/assert/v2 v2.2.1 
h1:XivOgYcduV98QCahG8T5XTezV5bylXe+lBxLG2K2ink=
-github.com/alecthomas/assert/v2 v2.2.1/go.mod 
h1:pXcQ2Asjp247dahGEmsZ6ru0UVwnkhktn7S0bBDLxvQ=
-github.com/alecthomas/chroma/v2 v2.9.1 
h1:0O3lTQh9FxazJ4BYE/MOi/vDGuHn7B+6Bu902N2UZvU=
-github.com/alecthomas/chroma/v2 v2.9.1/go.mod 
h1:4TQu7gdfuPjSh76j78ietmqh9LiurGF0EpseFXdKMBw=
-github.com/alecthomas/repr v0.2.0 
h1:HAzS41CIzNW5syS8Mf9UwXhNH1J9aix/BvDRf1Ml2Yk=
-github.com/alecthomas/repr v0.2.0/go.mod 
h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4=
+github.com/Microsoft/go-winio v0.6.2 
h1:F2VQgta7ecxGYO8k3ZZz3RS8fVIXVxONVUPlNERoyfY=
+github.com/Microsoft/go-winio v0.6.2/go.mod 
h1:yd8OoFMLzJbo9gZq8j5qaps8bJ9aShtEA8Ipt1oGCvU=
+github.com/ProtonMail/go-crypto v1.1.6 
h1:ZcV+Ropw6Qn0AX9brlQLAUXfqLBc7Bl+f/DmNxpLfdw=
+github.com/ProtonMail/go-crypto v1.1.6/go.mod 
h1:rA3QumHc/FZ8pAHreoekgiAbzpNsfQAosU5td4SnOrE=
 github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be 
h1:9AeTilPcZAjCFIImctFaOjnTIavg87rW78vTPkQqLI8=
 github.com/anmitsu/go-shlex v0.0.0-20200514113438-38f4b401e2be/go.mod 
h1:ySMOLuWl6zY27l47sB3qLNK6tF2fkHG55UZxx8oIVo4=
 github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 
h1:0CwZNZbxp69SHPdPJAN/hZIm0C4OItdklCFmMRWYpio=
 github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod 
h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs=
-github.com/bytesparadise/libasciidoc v0.8.0 
h1:iWAlYR7gm4Aes3NSvuGQyzRavatQpUBAJZyU9uMmwm0=
-github.com/bytesparadise/libasciidoc v0.8.0/go.mod 
h1:Q2ZeBQ1fko5+NTUTs8rGu9gjTtbVaD6Qxg37GOPYdN4=
-github.com/cloudflare/circl v1.3.7 
h1:qlCDlTPz2n9fu58M0Nh1J/JzcFpfgkFHHX3O35r5vcU=
-github.com/cloudflare/circl v1.3.7/go.mod 
h1:sRTcRWXGLrKw6yIGJ+l7amYJFfAXbZG0kBSc8r4zxgA=
-github.com/cyphar/filepath-securejoin v0.3.6 
h1:4d9N5ykBnSp5Xn2JkhocYDkOpURL/18CYMpo6xB9uWM=
-github.com/cyphar/filepath-securejoin v0.3.6/go.mod 
h1:Sdj7gXlvMcPZsbhwhQ33GguGLDGQL7h7bg04C/+u9jI=
+github.com/cloudflare/circl v1.6.3 
h1:9GPOhQGF9MCYUeXyMYlqTR6a5gTrgR/fBLXvUgtVcg8=
+github.com/cloudflare/circl v1.6.3/go.mod 
h1:2eXP6Qfat4O/Yhh8BznvKnJ+uzEoTQ6jVKJRn81BiS4=
+github.com/cyphar/filepath-securejoin v0.6.1 
h1:5CeZ1jPXEiYt3+Z6zqprSAgSWiggmpVyciv8syjIpVE=
+github.com/cyphar/filepath-securejoin v0.6.1/go.mod 
h1:A8hd4EnAeyujCJRrICiOWqjS1AX0a9kM5XL+NwKoYSc=
 github.com/davecgh/go-spew v1.1.0/go.mod 
h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
 github.com/davecgh/go-spew v1.1.1 
h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
 github.com/davecgh/go-spew v1.1.1/go.mod 
h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
-github.com/dlclark/regexp2 v1.10.0 
h1:+/GIL799phkJqYW+3YbOd8LCcbHzT0Pbo8zl70MHsq0=
-github.com/dlclark/regexp2 v1.10.0/go.mod 
h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
-github.com/elazarl/goproxy v1.2.3 
h1:xwIyKHbaP5yfT6O9KIeYJR5549MXRQkoQMRXGztz8YQ=
-github.com/elazarl/goproxy v1.2.3/go.mod 
h1:YfEbZtqP4AetfO6d40vWchF3znWX7C7Vd6ZMfdL8z64=
+github.com/elazarl/goproxy v1.7.2 
h1:Y2o6urb7Eule09PjlhQRGNsqRfPmYI3KKQLFpCAV3+o=
+github.com/elazarl/goproxy v1.7.2/go.mod 
h1:82vkLNir0ALaW14Rc399OTTjyNREgmdL2cVoIbS6XaE=
 github.com/emirpasic/gods v1.18.1 
h1:FXtiHYKDGKCW2KzwZKx0iC0PQmdlorYgdFG9jPXJ1Bc=
 github.com/emirpasic/gods v1.18.1/go.mod 
h1:8tpGGwCnJ5H4r6BWwaV6OrWmMoPhUl5jm/FMNAnJvWQ=
-github.com/felixge/fgtrace v0.1.0 
h1:cuMLI5NoBg/9IxIVmJzsxA3Aoz5eIKRca6WE1U2C1zc=
-github.com/felixge/fgtrace v0.1.0/go.mod 
h1:VYPh/jE5zczuRiQge0AtcpNmcLhV/epE/wpfVYQALlU=
 github.com/gliderlabs/ssh v0.3.8 
h1:a4YXD1V7xMF9g5nTkdfnja3Sxy1PVDCj1Zg4Wb8vY6c=
 github.com/gliderlabs/ssh v0.3.8/go.mod 
h1:xYoytBv1sV0aL3CavoDuJIQNURXkkfPA/wxQ1pL1fAU=
 github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 
h1:+zs/tPmkDkHx3U66DAb0lQFJrpS6731Oaa12ikc+DiI=
 github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376/go.mod 
h1:an3vInlBmSxCcxctByoQdvwPiA7DTK7jaaFDBTtu0ic=
-github.com/go-git/go-billy/v5 v5.6.1 
h1:u+dcrgaguSSkbjzHwelEjc0Yj300NUevrrPphk/SoRA=
-github.com/go-git/go-billy/v5 v5.6.1/go.mod 
h1:0AsLr1z2+Uksi4NlElmMblP5rPcDZNRCD8ujZCRR2BE=
+github.com/go-git/go-billy/v5 v5.9.0 
h1:jItGXszUDRtR/AlferWPTMN4j38BQ88XnXKbilmmBPA=
+github.com/go-git/go-billy/v5 v5.9.0/go.mod 
h1:jCnQMLj9eUgGU7+ludSTYoZL/GGmii14RxKFj7ROgHw=
 github.com/go-git/go-git-fixtures/v4 v4.3.2-0.20231010084843-55a94097c399 
h1:eMje31YglSBqCdIqdhKBW8lokaMrL3uTkpGYlE2OOT4=
 github.com/go-git/go-git-fixtures/v4 
v4.3.2-0.20231010084843-55a94097c399/go.mod 
h1:1OCfN199q1Jm3HZlxleg+Dw/mwps2Wbk9frAWm+4FII=
-github.com/go-git/go-git/v5 v5.13.1 
h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=
-github.com/go-git/go-git/v5 v5.13.1/go.mod 
h1:qryJB4cSBoq3FRoBRf5A77joojuBcmPJ0qu3XXXVixc=
-github.com/go-logr/logr v1.2.4 h1:g01GSCwiDw2xSZfjJ2/T9M+S6pFdcNtFYsp+Y43HYDQ=
-github.com/go-logr/logr v1.2.4/go.mod 
h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
-github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572 
h1:tfuBGBXKqDEevZMzYi5KSi8KkcZtzBcTgAUUtapy0OI=
-github.com/go-task/slim-sprig v0.0.0-20230315185526-52ccab3ef572/go.mod 
h1:9Pwr4B2jHnOSGXyyzV8ROjYa2ojvAY6HCGYYfMoC3Ls=
-github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 
h1:oI5xCqsCo564l8iNU+DwB5epxmsaqB+rhGL0m5jtYqE=
-github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da/go.mod 
h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
-github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI=
-github.com/google/go-cmp v0.6.0/go.mod 
h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
-github.com/google/pprof v0.0.0-20230912144702-c363fe2c2ed8 
h1:gpptm606MZYGaMHMsB4Srmb6EbW/IVHnt04rcMXnkBQ=
-github.com/google/pprof v0.0.0-20230912144702-c363fe2c2ed8/go.mod 
h1:czg5+yv1E0ZGTi6S6vVK1mke0fV+FaUhNGcd6VRS9Ik=
+github.com/go-git/go-git/v5 v5.19.2 
h1:wkfn7vOlUBu8ivAWKBWisTiwJK4jYHzTF8Ndv1LyGqY=
+github.com/go-git/go-git/v5 v5.19.2/go.mod 
h1:QqCBE1EFN5ddFmrliLQ3/ntRCUjZU3EJuwuB/jWEHjk=
+github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 
h1:f+oWsMOmNPc8JmEHVZIycC7hBoQxHH9pNKQORJNozsQ=
+github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8/go.mod 
h1:wcDNUvekVysuuOpQKo3191zZyTpiI6se1N1ULghS0sw=
+github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
+github.com/google/go-cmp v0.7.0/go.mod 
h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
 github.com/google/uuid v1.3.1 h1:KjJaJ9iWZ3jOFZIf1Lqf4laDRCasjl0BCmnEGxkdLb4=
 github.com/google/uuid v1.3.1/go.mod 
h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
-github.com/hexops/gotextdiff v1.0.3 
h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUqJM=
-github.com/hexops/gotextdiff v1.0.3/go.mod 
h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg=
 github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99 
h1:BQSFePA1RWJOlocH6Fxy8MmwDt+yVQYULKfN0RoTN8A=
 github.com/jbenet/go-context v0.0.0-20150711004518-d14ea06fba99/go.mod 
h1:1lJo3i6rXxKeerYnT8Nvf0QmHCRC1n8sfWVwXF2Frvo=
 github.com/kevinburke/ssh_config v1.2.0 
h1:x584FjTGwHzMwvHx18PXxbBVzfnxogHaAReU4gf13a4=
 github.com/kevinburke/ssh_config v1.2.0/go.mod 
h1:CT57kijsi8u/K/BOFA39wgDQJ9CxiF4nAY/ojJ6r6mM=
+github.com/klauspost/cpuid/v2 v2.3.0 
h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y=
+github.com/klauspost/cpuid/v2 v2.3.0/go.mod 
h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQeu1XKlok6oO0=
 github.com/kr/pretty v0.1.0/go.mod 
h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
 github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
 github.com/kr/pretty v0.3.1/go.mod 
h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
@@ -69,78 +49,53 @@
 github.com/kr/text v0.1.0/go.mod 
h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
 github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
 github.com/kr/text v0.2.0/go.mod 
h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
-github.com/mna/pigeon v1.1.0 h1:EjlvVbkGnNGemf8OrjeJX0nH8orujY/HkJgzJtd7kxc=
-github.com/mna/pigeon v1.1.0/go.mod 
h1:rkFeDZ0gc+YbnrXPw0q2RlI0QRuKBBPu67fgYIyGRNg=
-github.com/onsi/ginkgo/v2 v2.12.0 
h1:UIVDowFPwpg6yMUpPjGkYvf06K3RAiJXUhCxEwQVHRI=
-github.com/onsi/ginkgo/v2 v2.12.0/go.mod 
h1:ZNEzXISYlqpb8S36iN71ifqLi3vVD1rVJGvWRCJOUpQ=
 github.com/onsi/gomega v1.34.1 h1:EUMJIKUjM8sKjYbtxQI9A4z2o+rruxnzNvpknOXie6k=
 github.com/onsi/gomega v1.34.1/go.mod 
h1:kU1QgUvBDLXBJq618Xvm2LUX6rSAfRaFRTcdOeDLwwY=
-github.com/pjbgf/sha1cd v0.3.0 h1:4D5XXmUUBUl/xQ6IjCkEAbqXskkq/4O7LmGn0AqMDs4=
-github.com/pjbgf/sha1cd v0.3.0/go.mod 
h1:nZ1rrWOcGJ5uZgEEVL1VUM9iRQiZvWdbZjkKyFzPPsI=
+github.com/pjbgf/sha1cd v0.6.0 h1:3WJ8Wz8gvDz29quX1OcEmkAlUg9diU4GxJHqs0/XiwU=
+github.com/pjbgf/sha1cd v0.6.0/go.mod 
h1:lhpGlyHLpQZoxMv8HcgXvZEhcGs0PG/vsZnEJ7H0iCM=
 github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
 github.com/pkg/errors v0.9.1/go.mod 
h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
 github.com/pmezard/go-difflib v1.0.0 
h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
 github.com/pmezard/go-difflib v1.0.0/go.mod 
h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
-github.com/rogpeppe/go-internal v1.12.0 
h1:exVL4IDcn6na9z1rAb56Vxr+CgyK3nn3O+epU5NdKM8=
-github.com/rogpeppe/go-internal v1.12.0/go.mod 
h1:E+RYuTGaKKdloAfM02xzb0FW3Paa99yedzYV+kq4uf4=
+github.com/rogpeppe/go-internal v1.14.1 
h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
+github.com/rogpeppe/go-internal v1.14.1/go.mod 
h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
 github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 
h1:n661drycOFuPLCN3Uc8sB6B/s6Z4t2xvBgU1htSHuq8=
 github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3/go.mod 
h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4=
 github.com/sirupsen/logrus v1.7.0/go.mod 
h1:yWOB1SBYBC5VeMP7gHvWumXLIWorT60ONWic61uBYv0=
-github.com/sirupsen/logrus v1.9.3 
h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ=
-github.com/sirupsen/logrus v1.9.3/go.mod 
h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ=
-github.com/skeema/knownhosts v1.3.0 
h1:AM+y0rI04VksttfwjkSTNQorvGqmwATnvnAHpSgc0LY=
-github.com/skeema/knownhosts v1.3.0/go.mod 
h1:sPINvnADmT/qYH1kfv+ePMmOBTH6Tbl7b5LvTDjFK7M=
+github.com/skeema/knownhosts v1.3.1 
h1:X2osQ+RAjK76shCbvhHHHVl3ZlgDm8apHEHFqRjnBY8=
+github.com/skeema/knownhosts v1.3.1/go.mod 
h1:r7KTdC8l4uxWRyK2TpQZ/1o5HaSzh06ePQNxPwTcfiY=
 github.com/spf13/jwalterweatherman v1.1.0 
h1:ue6voC5bR5F8YxI5S67j9i582FU4Qvo2bmqnqMYADFk=
 github.com/spf13/jwalterweatherman v1.1.0/go.mod 
h1:aNWZUN0dPAAO/Ljvb5BEdw96iTZ0EXowPYD95IqWIGo=
-github.com/spf13/pflag v1.0.5 h1:iy+VFUOCP1a+8yFto/drg2CJ5u0yRoB7fZw3DKv/JXA=
-github.com/spf13/pflag v1.0.5/go.mod 
h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
 github.com/stretchr/objx v0.1.0/go.mod 
h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
 github.com/stretchr/testify v1.2.2/go.mod 
h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
 github.com/stretchr/testify v1.4.0/go.mod 
h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
-github.com/stretchr/testify v1.6.1/go.mod 
h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
-github.com/stretchr/testify v1.7.0/go.mod 
h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
-github.com/stretchr/testify v1.10.0 
h1:Xv5erBjTwe/5IxqUQTdXv5kgmIvbHo3QQyRwhJsOfJA=
-github.com/stretchr/testify v1.10.0/go.mod 
h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY=
+github.com/stretchr/testify v1.11.1 
h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
+github.com/stretchr/testify v1.11.1/go.mod 
h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
 github.com/xanzy/ssh-agent v0.3.3 
h1:+/15pJfg/RsTxqYcX6fHqOXZwwMP+2VyYWJeWM2qQFM=
 github.com/xanzy/ssh-agent v0.3.3/go.mod 
h1:6dzNDKs0J9rVPHPhaGCukekBHKqfl+L3KghI1Bc68Uw=
-golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod 
h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
 golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod 
h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
-golang.org/x/crypto v0.31.0 h1:ihbySMvVjLAeSH1IbfcRTkD/iNscyz8rGzjF/E5hV6U=
-golang.org/x/crypto v0.31.0/go.mod 
h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
-golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56 
h1:2dVuKD2vS7b0QIHQbpyTISPd0LeHDbnYEryqj5Q1ug8=
-golang.org/x/exp v0.0.0-20240719175910-8a7402abbf56/go.mod 
h1:M4RDyNAINzryxdtnbRXRL/OHtkFuWGRjvuhBJpk2IlY=
-golang.org/x/mod v0.17.0 h1:zY54UmvipHiNd+pm+m0x9KhZ9hl1/7QNMyxXbc6ICqA=
-golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
-golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod 
h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
+golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
+golang.org/x/crypto v0.53.0/go.mod 
h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
+golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f 
h1:W3F4c+6OLc6H2lb//N1q4WpJkhzJCK5J6kUi1NTVXfM=
+golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f/go.mod 
h1:J1xhfL/vlindoeF/aINzNzt2Bket5bjo9sdOYzOsU80=
 golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2/go.mod 
h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
-golang.org/x/net v0.33.0 h1:74SYHlV8BIgHIFC/LrYkOGIwL19eTYXQ5wc6TBuO36I=
-golang.org/x/net v0.33.0/go.mod h1:HXLR5J+9DxmrqMwG9qjGCxZ+zKXxBru04zlTvWlWuN4=
-golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod 
h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
-golang.org/x/sync v0.10.0 h1:3NQrjDixjgGwUOCaF8w2+VYHv0Ve/vGYSbdkTa98gmQ=
-golang.org/x/sync v0.10.0/go.mod 
h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
-golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod 
h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
+golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
+golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
 golang.org/x/sys v0.0.0-20191026070338-33540a1f6037/go.mod 
h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
 golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod 
h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
 golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod 
h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
 golang.org/x/sys v0.0.0-20210423082822-04245dca01da/go.mod 
h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
 golang.org/x/sys v0.0.0-20210615035016-665e8c7367d1/go.mod 
h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod 
h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
-golang.org/x/sys v0.28.0 h1:Fksou7UEQUWlKvIdsqzJmUmCX3cZuD2+P3XyyzwMhlA=
-golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
+golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
+golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
 golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod 
h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
-golang.org/x/term v0.27.0 h1:WP60Sv1nlK1T6SupCHbXzSaN0b9wUmsPoRS9b61A23Q=
-golang.org/x/term v0.27.0/go.mod 
h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
-golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
+golang.org/x/term v0.44.0 h1:0rLvDRCtNj0gZkyIXhCyOb2OAzEhLVqc4B+hrsBhrmc=
+golang.org/x/term v0.44.0/go.mod 
h1:7ze4MdzUzLXpSAoFP1H0bOI9aXDqveSvatT5vKcFh2Y=
 golang.org/x/text v0.3.6/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
-golang.org/x/text v0.21.0 h1:zyQAAkrwaneQ066sspRyJaG9VNi/YJ1NfzcGB3hZ/qo=
-golang.org/x/text v0.21.0/go.mod 
h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ=
+golang.org/x/text v0.39.0 h1:UbZz4pLOvn600D6Oh6GGEI6VAmndrEBLv8/6BEXzyus=
+golang.org/x/text v0.39.0/go.mod 
h1:3UwRclnC2g0TU9x8PZiyfOajCd1zaUNHF9cvqcQZ+ZM=
 golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod 
h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
-golang.org/x/tools v0.0.0-20190830223141-573d9926052a/go.mod 
h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
-golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d 
h1:vU5i/LfpvrRCpgM/VPfJLg5KjxD3E+hfT1SH+d9zLwg=
-golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d/go.mod 
h1:aiJjzUbINMkxbQROHiO6hDPo2LHcIPhhQsa9DLh0yGk=
-golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod 
h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
-google.golang.org/protobuf v1.36.1 
h1:yBPeRvTftaleIgM3PZ/WBIZ7XM/eEYAaEyCwvyjq/gk=
-google.golang.org/protobuf v1.36.1/go.mod 
h1:9fA7Ob0pmnwhb644+1+CVWFRbNajQ6iRojtC/QF5bRE=
 gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod 
h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
 gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod 
h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
 gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c 
h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk=
@@ -148,8 +103,6 @@
 gopkg.in/warnings.v0 v0.1.2 h1:wFXVbFY8DY5/xOe1ECiWdKCzZlxgshcYVNkBHstARME=
 gopkg.in/warnings.v0 v0.1.2/go.mod 
h1:jksf8JmL6Qr/oQM2OXTHunEvvTAsrWBLb6OOjuVWRNI=
 gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
-gopkg.in/yaml.v2 v2.4.0 h1:D8xgwECY7CYvx+Y2n4sBz93Jn9JRvxdiyyo8CTfuKaY=
 gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ=
-gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod 
h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
 gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
 gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/include/nng/nng.h 
new/nng-1.12.2/include/nng/nng.h
--- old/nng-1.12.0/include/nng/nng.h    2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/include/nng/nng.h    2026-08-22 22:58:48.000000000 +0200
@@ -57,8 +57,8 @@
 // We use SemVer, and these versions are about the API, and
 // may not necessarily match the ABI versions.
 #define NNG_MAJOR_VERSION 1
-#define NNG_MINOR_VERSION 11
-#define NNG_PATCH_VERSION 0
+#define NNG_MINOR_VERSION 12
+#define NNG_PATCH_VERSION 2
 // if non-empty (i.e. "pre"), this is a pre-release
 #define NNG_RELEASE_SUFFIX ""
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/src/core/url.c 
new/nng-1.12.2/src/core/url.c
--- old/nng-1.12.0/src/core/url.c       2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/src/core/url.c       2026-08-22 22:58:48.000000000 +0200
@@ -116,8 +116,8 @@
        return (len);
 }
 
-static int
-url_canonify_uri(char **outp, const char *in)
+int
+nni_url_canonify_uri(char **outp, const char *in)
 {
        char *  out;
        size_t  src, dst, len;
@@ -399,7 +399,7 @@
        url->u_host[len] = '\0';
        s += len;
 
-       if ((rv = url_canonify_uri(&url->u_requri, s)) != 0) {
+       if ((rv = nni_url_canonify_uri(&url->u_requri, s)) != 0) {
                goto error;
        }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/src/core/url.h 
new/nng-1.12.2/src/core/url.h
--- old/nng-1.12.0/src/core/url.h       2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/src/core/url.h       2026-08-22 22:58:48.000000000 +0200
@@ -16,6 +16,7 @@
 extern int         nni_url_parse(nni_url **, const char *path);
 extern void        nni_url_free(nni_url *);
 extern int         nni_url_clone(nni_url **, const nni_url *);
+extern int         nni_url_canonify_uri(char **, const char *);
 extern const char *nni_url_default_port(const char *);
 extern int         nni_url_asprintf(char **, const nni_url *);
 extern int         nni_url_asprintf_port(char **, const nni_url *, int);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/src/supplemental/http/CMakeLists.txt 
new/nng-1.12.2/src/supplemental/http/CMakeLists.txt
--- old/nng-1.12.0/src/supplemental/http/CMakeLists.txt 2026-06-09 
23:32:43.000000000 +0200
+++ new/nng-1.12.2/src/supplemental/http/CMakeLists.txt 2026-08-22 
22:58:48.000000000 +0200
@@ -26,3 +26,5 @@
         http_public.c
         http_schemes.c
         http_server.c)
+
+nng_test_if(NNG_SUPP_HTTP http_msg_test)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/src/supplemental/http/http_msg.c 
new/nng-1.12.2/src/supplemental/http/http_msg.c
--- old/nng-1.12.0/src/supplemental/http/http_msg.c     2026-06-09 
23:32:43.000000000 +0200
+++ new/nng-1.12.2/src/supplemental/http/http_msg.c     2026-08-22 
22:58:48.000000000 +0200
@@ -770,6 +770,7 @@
        char *method;
        char *uri;
        char *version;
+       char *canon_uri;
 
        method = line;
        if ((uri = strchr(method, ' ')) == NULL) {
@@ -784,11 +785,16 @@
        *version = '\0';
        version++;
 
+       if ((rv = nni_url_canonify_uri(&canon_uri, uri)) != 0) {
+               return (rv);
+       }
        if (((rv = nni_http_req_set_method(req, method)) != 0) ||
-           ((rv = nni_http_req_set_uri(req, uri)) != 0) ||
+           ((rv = nni_http_req_set_uri(req, canon_uri)) != 0) ||
            ((rv = nni_http_req_set_version(req, version)) != 0)) {
+               nni_strfree(canon_uri);
                return (rv);
        }
+       nni_strfree(canon_uri);
        req->parsed = true;
        return (0);
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/src/supplemental/http/http_msg_test.c 
new/nng-1.12.2/src/supplemental/http/http_msg_test.c
--- old/nng-1.12.0/src/supplemental/http/http_msg_test.c        1970-01-01 
01:00:00.000000000 +0100
+++ new/nng-1.12.2/src/supplemental/http/http_msg_test.c        2026-08-22 
22:58:48.000000000 +0200
@@ -0,0 +1,39 @@
+//
+// Copyright 2026 Staysail Systems, Inc. <[email protected]>
+//
+// This software is supplied under the terms of the MIT License, a
+// copy of which should be located in the distribution where this
+// file was obtained (LICENSE.txt).  A copy of the license may also be
+// found online at https://opensource.org/licenses/MIT.
+//
+
+#include "core/nng_impl.h"
+#include "http_api.h"
+
+#include <nuts.h>
+#include <string.h>
+
+static void
+test_http_req_canonify_uri(void)
+{
+       nni_http_req *req;
+       char          plain[] = "GET /../../outside.txt HTTP/1.1\r\n\r\n";
+       char          encoded[] =
+           "GET /%2e%2e/%2E%2e/outside.txt HTTP/1.1\r\n\r\n";
+       size_t        len;
+
+       NUTS_PASS(nni_http_req_alloc(&req, NULL));
+       NUTS_PASS(nni_http_req_parse(req, plain, strlen(plain), &len));
+       NUTS_MATCH(nni_http_req_get_uri(req), "/outside.txt");
+       nni_http_req_free(req);
+
+       NUTS_PASS(nni_http_req_alloc(&req, NULL));
+       NUTS_PASS(nni_http_req_parse(req, encoded, strlen(encoded), &len));
+       NUTS_MATCH(nni_http_req_get_uri(req), "/outside.txt");
+       nni_http_req_free(req);
+}
+
+NUTS_TESTS = {
+       { "http request URI canonicalization", test_http_req_canonify_uri },
+       { NULL, NULL },
+};
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nng-1.12.0/tests/httpclient.c 
new/nng-1.12.2/tests/httpclient.c
--- old/nng-1.12.0/tests/httpclient.c   2026-06-09 23:32:43.000000000 +0200
+++ new/nng-1.12.2/tests/httpclient.c   2026-08-22 22:58:48.000000000 +0200
@@ -76,7 +76,6 @@
                        So(nng_http_res_get_status(res) == 200);
 
                        Convey("The message contents are correct", {
-                               uint8_t     digest[20];
                                void       *data;
                                const char *cstr;
                                size_t      sz;
@@ -129,7 +128,6 @@
                        nng_http_res *res;
                        void         *data;
                        size_t        len;
-                       uint8_t       digest[20];
 
                        So(nng_http_req_alloc(&req, url) == 0);
                        So(nng_http_res_alloc(&res) == 0);
@@ -151,7 +149,6 @@
                        nng_http_res  *res2;
                        void          *data;
                        size_t         len;
-                       uint8_t        digest[20];
                        nng_http_conn *conn = NULL;
 
                        So(nng_http_req_alloc(&req, url) == 0);

Reply via email to