Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package cacti for openSUSE:Factory checked 
in at 2026-09-18 22:05:20
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/cacti (Old)
 and      /work/SRC/openSUSE:Factory/.cacti.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "cacti"

Fri Sep 18 22:05:20 2026 rev:61 rq:1378671 version:1.2.31+git128.263b4c1c

Changes:
--------
--- /work/SRC/openSUSE:Factory/cacti/cacti.changes      2026-08-05 
17:50:20.213926262 +0200
+++ /work/SRC/openSUSE:Factory/.cacti.new.383539/cacti.changes  2026-09-18 
22:05:53.989987358 +0200
@@ -1,0 +2,122 @@
+Thu Sep 17 14:15:36 UTC 2026 - Joel Baltazor <[email protected]>
+
+- Adjusted _service file to look at release/ tags and ignore the rel* warning
+- Update cacti-config-dist.patch to apply cleanly and build
+- Update cacti.spec to ignore export-plural-rules and csrf-secret.php
+- Update to version 1.2.31+git128.263b4c1c:
+  * fix(installer): tolerate a microtime string with no fractional part (1.2.x 
backport) (#8029)
+  * fix enum test ' and " (#8027)
+  * fix: Unable to remove data queries due to new request hardening (#8028)
+  * fix(auth): backport session and remember-cookie lifecycle hardening (#7990)
+  * ci: Remove platform as it causes conflicts during ci (#8018)
+  * fix(csrf): backport tokenized POST item actions (#7992)
+  * 1.2.x: Propagate reconnected database handles (#7998)
+  * security: reject LDAP logins that skip a domain bind (#8008)
+  * 1.2.x: Clarify missing SNMP notification receivers (#7997)
+  * fix(realtime): preserve inline graph size (#7996)
+  * fix(functions): preserve observed child exit codes (#7989)
+  * fix(csv): backport aligned sample windows to 1.2 (#7988)
+  * security: harden CLI process and temporary-file handling (#7972)
+  * fix: harden Boost lifecycle, PHP 8.5 graph CF, and UI initialization 
(#7963)
+  * [1.2.x] Preserve layout after plugin dependency errors (#7962)
+  * Fixing Issues When Boost Redirect is Enabled (#8015)
+  * security(poller): validate PID bounds and process ownership (#7955)
+  * Revert "deps(deps): bump phpseclib/phpseclib in the composer-1-2-x group 
(#8005)" (#8017)
+  * fix: Installer in batch through false positive fail (#8016)
+  * Update translation files
+  * Translated using Weblate (Swedish)
+  * fix(cli): normalize aliases, help, and error statuses (#7907)
+  * deps(deps): bump phpseclib/phpseclib in the composer-1-2-x group (#8005)
+  * fix(automation): use server timezone for schedules (#7995)
+  * Backport graph filter, automation OS, and lm-sensors fixes (#7983)
+  * ci(csp): fail closed on empty Pest runs (#7994)
+  * Fix SNMP uptime selection on 1.2.x (#7982)
+  * 1.2.x: Close detached select menus on scroll (#7999)
+  * fix: report missing session cookie failures (#7871)
+  * build: declare the PHP 8.1 floor 1.2.31 already shipped (#7938)
+  * fix: commit transactions on MySQL as well as MariaDB (#7930)
+  * test: refresh the 1.2.x security baselines (#7924)
+  * security(cli): keep database credentials off the command line (#7910)
+  * issue: update bundled jQuery UI to 1.14.2 and Tablesorter to 2.31.3 (#7887)
+  * security: update bundled DOMPurify to 3.4.14 (#7912)
+  * QA: Preparing for Cacti release (#7870)
+  * fix: prevent cookie domain login loops (#7869)
+  * fix: poller overrun cleanup and CSV export row cap (#7862)
+  * security: verify package signatures against trusted keys only (#7863)
+  * security: 1.2.x hardening batch (clog filenames, dsstats/aggregate 
escaping, auth) (#7847)
+  * security: substitute query data before escaping graph titles and labels 
(#7845)
+  * security: stop trusting Host for HTTPS redirects (#7832)
+  * fix: allow graph tree sidebar to shrink (#7836)
+  * issue#7809: stop reading a missing source key on output-only data query 
fields (#7834)
+  * ci(deps): bump docker/setup-buildx-action (#7827)
+  * fix: remove obsolete PHP compatibility branches (#7820)
+  * hardening: constrain user_admin sort_column, escape sites LIKE wildcards, 
unpredictable package temp dir (#7821)
+  * fix(database): restore qualified table metadata lookup (#7826)
+  * hardening: confine external link content includes (#7817)
+  * fix(user_admin): validate group filter as an integer (#7813)
+  * fix(html_tree): escape data query index in graph tree title (#7814)
+  * hardening: trim vendored runtime surface (#7805)
+  * fix: restore RRDproxy crypto with phpseclib 3 (#7804)
+  * security(csrf): harden secret and request handoffs (#7803)
+  * Build self-contained 1.2.x release artifacts from Composer lock (#7802)
+  * fix(composer): keep extension diagnostics in installer (#7811)
+  * docs: add missing 1.2.x changelog entries (#7789)
+  * fix: url encode the base64 regex filter before it reaches the query string 
(#7777)
+  * ci: stabilize PPA and apt refresh on 1.2.x (#7763)
+  * ci: restore PHP 8.1 integration coverage (#7756)
+  * [1.2.x] Harden Boost data handoffs and graph cache writes (#7728)
+  * update changelog (#7753)
+  * ci(deps): bump the github-actions-1-2-x group with 7 updates (#7748)
+  * Make 1.2 dependency builds reproducible (#7747)
+  * deps(deps): update paragonie/constant_time_encoding requirement (#7738)
+  * security: restrict graph input fields across handoffs (1.2.x) (#7692)
+  * ci(security): compare the 1.2.x baselines on a line-agnostic signature 
(#7724)
+  * Bind the MIB column names in MibCache::select() (#7708)
+  * Make the CSP report size limit reachable and stop the counters piling up 
(#7704)
+  * security: enforce strict-bool package signature check in import_package 
(GHSA-274c-97hj-pv2v) (#7675)
+  * 1.2.x - fix log entry (two spaces) "fields which is NOT  okay" (#7727)
+  * Guard three divisors that PHP 8 makes fatal (#7699)
+  * Document the PHP baseline accurately on 1.2.x (#7698)
+  * security: reject path traversal in package file writes 
(GHSA-vp35-4h28-r883) (#7671)
+  * fix(functions): take cacti_exec exit code from proc_close (#7668)
+  * chore(deps): update phpseclib to 3.0.56 (#7734)
+  * refactor(tests): reorganize unit tests into domain category folders (#7731)
+  * fix(poller): launch cactid without a shell (#7602)
+  * fix(installer): propagate background installation failures (#7630)
+  * fix(installer): reject incomplete selection payloads (#7628)
+  * fix(snmp): log the reason a session read failed (#7606)
+  * feat(logging): emit structured security events for validation failures 
(#7604)
+  * fix(auth): expire persistent auth tokens when permissions change (#7600)
+  * fix(automation): bind host template ID filters as prepared parameters 
(#7598)
+  * ci(security): require advisory changelog references (#7596)
+  * Fail closed on incomplete installer schemas (#7625)
+  * fix(installer): restore select-all controls on 1.2.x (#7624)
+  * docs(config): expose HTMLPurifier cache path (#7595)
+  * fix(session): guard request URI reads on 1.2.x (#7593)
+  * fix(csp): honor alternate frame ancestors (#7591)
+  * fix(security): harden advisory command and DDL sinks (#7235)
+  * fix: #7510 - Fix system MIB collection interval lock (#7559)
+  * test: restore missing helper source and skip orphaned unit tests (#7547)
+  * fix(data query): walk output_format fields with the bulk walk size (#7556)
+  * test: pin draw_edit_form change handler binding (#7553) (#7554)
+  * fix(html): keep the HTMLPurifier definition cache out of the library tree 
(#7555)
+  * fix: backport VDEF xport safeguards (#7508)
+  * fix: monthly automation schedules corrupt next_start to 1970 and run every 
cycle (#7428)
+  * fix: stop tracking the generated CSRF secret so each install gets its own 
(#7415)
+  * fix: #5679 attempt SNMP in Ping-OR-SNMP availability when ping fails 
(#7417)
+  * fix: update host status by id instead of hostname (#7416)
+  * fix: guard process registration against pid reuse (#7414)
+  * fix(scripts): correct SNMP disk counter wrap math (1.2.x) (#7413)
+  * fix: correct octet carry in automation_get_next_host for wide ranges 
(#7410)
+  * fix: remove inert Automatically Trust Signer control from package import 
(#7430)
+  * test: add regression coverage for #7407 and #7408 fixes (#7496)
+  * fix(database): commit transaction check uses the passed connection (#7409)
+  * hardening: guard system PIDs in timeout_kill_registered_processes (#7400)
+  * fix: backport remote agent timeout options (#7507)
+  * fix: correct unsigned reconstruction for negative disk sizes in 
ss_host_disk (#7408)
+  * fix: timeout_kill_registered_processes never matched any row (#7407)
+  * fix: #7070 align percentile rank with observed export samples (#7406)
+  * fix variable (#7402)
+  * ci(security): refresh 1.2.x sink inventory baseline (#7495)
+
+-------------------------------------------------------------------

Old:
----
  cacti-1.2.31+git14.396480d3.obscpio

New:
----
  cacti-1.2.31+git128.263b4c1c.obscpio
  cacti-1.2.31+git128.263b4c1c.tar

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ cacti.spec ++++++
--- /var/tmp/diff_new_pack.D0y8ag/_old  2026-09-18 22:05:56.954111584 +0200
+++ /var/tmp/diff_new_pack.D0y8ag/_new  2026-09-18 22:05:56.956111667 +0200
@@ -21,7 +21,7 @@
 %define cacti_dir %{datadir}/cacti
 
 Name:           cacti
-Version:        1.2.31+git14.396480d3
+Version:        1.2.31+git128.263b4c1c
 %global base_version %(echo %{version} | sed 's/+[^+]*//')
 %global next_base_version %(echo %{base_version} | awk -F. -v OFS=. '{$NF++; 
print}')
 Release:        0
@@ -97,7 +97,9 @@
 
 # fix env interpreter lines
 sed -i 's|%{_bindir}/env perl|%{_bindir}/perl|g' $(find * -name "*.pl")
-sed -i 's|%{_bindir}/env php|%{_bindir}/php|g' 
include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules
+if [ -f include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules ]; 
then
+  sed -i 's|%{_bindir}/env php|%{_bindir}/php|g' 
include/vendor/cldr-to-gettext-plural-rules/bin/export-plural-rules
+fi
 sed -i 's|%{_bindir}/env bash|%{_bindir}/bash|g' $(find * -name "*.sh")
 sed -i 's|/usr/local/spine/bin/spine|%{_bindir}/spine|' install/functions.php
 
@@ -203,7 +205,7 @@
 %doc quickstart.txt
 %attr(-,%{apache_user},%{apache_group}) %dir %{_localstatedir}/lib/%{name}
 %attr(-,%{apache_user},%{apache_group}) %dir %{_localstatedir}/log/%{name}
-%attr(-,%{apache_user},%{apache_group}) 
%{cacti_dir}/include/vendor/csrf/csrf-secret.php
+#%%attr(-,%{apache_user},%{apache_group}) 
%{cacti_dir}/include/vendor/csrf/csrf-secret.php
 %attr(-,%{apache_user},%{apache_group}) %{cacti_dir}/log
 %{cacti_dir}/log
 %config(noreplace) %{cacti_dir}/include/config.php

++++++ _service ++++++
--- /var/tmp/diff_new_pack.D0y8ag/_old  2026-09-18 22:05:57.007113805 +0200
+++ /var/tmp/diff_new_pack.D0y8ag/_new  2026-09-18 22:05:57.012114015 +0200
@@ -4,6 +4,8 @@
     <param name="scm">git</param>
     <param name="exclude">.git</param>
     <param name="revision">1.2.x</param>
+    <!-- Forces Git to only look at release/ tags and ignore the rel* warning 
tag -->
+    <param name="match-tag">release/*</param>
     <param name="versionformat">@PARENT_TAG@+git@TAG_OFFSET@.%h</param>
     <!-- Removes "release/" from the beginning of the version string -->
     <param name="versionrewrite-pattern">release/(.*)</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.D0y8ag/_old  2026-09-18 22:05:57.038115104 +0200
+++ /var/tmp/diff_new_pack.D0y8ag/_new  2026-09-18 22:05:57.044115356 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param name="url">https://github.com/Cacti/cacti.git</param>
-              <param 
name="changesrevision">396480d3fc2027c68ffe872bf5e3356cf34eefd6</param></service></servicedata>
+              <param 
name="changesrevision">263b4c1caee8c11bd9ca30c9429fd8cc3ba2d2b7</param></service></servicedata>
 (No newline at EOF)
 

++++++ cacti-1.2.31+git14.396480d3.obscpio -> 
cacti-1.2.31+git128.263b4c1c.obscpio ++++++
++++ 133476 lines of diff (skipped)

++++++ cacti-config-dist.patch ++++++
--- /var/tmp/diff_new_pack.D0y8ag/_old  2026-09-18 22:06:00.167246246 +0200
+++ /var/tmp/diff_new_pack.D0y8ag/_new  2026-09-18 22:06:00.179246749 +0200
@@ -1,7 +1,7 @@
-Index: cacti-1.2.23/include/config.php.dist
+Index: cacti-1.2.31/include/config.php.dist
 ===================================================================
---- cacti-1.2.23.orig/include/config.php.dist
-+++ cacti-1.2.23/include/config.php.dist
+--- cacti-1.2.31.orig/include/config.php.dist
++++ cacti-1.2.31/include/config.php.dist
 @@ -45,17 +45,17 @@ $database_persist  = false;
   * must remain commented out.
   */
@@ -46,7 +46,7 @@
 +//$cacti_session_name = 'Cacti';
  
  /**
-  * Default Cookie domain - The cookie domain to be used for Cacti
+  * Optional cookie domain. This must match the browser-visible host or one of
 @@ -88,7 +88,7 @@ $cacti_session_name = 'Cacti';
   * Save sessions to a database for load balancing
   */

++++++ cacti.obsinfo ++++++
--- /var/tmp/diff_new_pack.D0y8ag/_old  2026-09-18 22:06:00.290251401 +0200
+++ /var/tmp/diff_new_pack.D0y8ag/_new  2026-09-18 22:06:00.295251610 +0200
@@ -1,5 +1,5 @@
 name: cacti
-version: 1.2.31+git14.396480d3
-mtime: 1784942578
-commit: 396480d3fc2027c68ffe872bf5e3356cf34eefd6
+version: 1.2.31+git128.263b4c1c
+mtime: 1789516109
+commit: 263b4c1caee8c11bd9ca30c9429fd8cc3ba2d2b7
 

Reply via email to