Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libsrtp2 for openSUSE:Factory checked in at 2026-09-23 14:34:18 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libsrtp2 (Old) and /work/SRC/openSUSE:Factory/.libsrtp2.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libsrtp2" Wed Sep 23 14:34:18 2026 rev:15 rq:1379449 version:2.8.1 Changes: -------- --- /work/SRC/openSUSE:Factory/libsrtp2/libsrtp2.changes 2026-03-14 22:22:03.168279617 +0100 +++ /work/SRC/openSUSE:Factory/.libsrtp2.new.383539/libsrtp2.changes 2026-09-23 14:35:41.156170564 +0200 @@ -1,0 +2,7 @@ +Mon Sep 21 09:25:07 UTC 2026 - Jan Engelhardt <[email protected]> + +- Update to release 2.8.1 + * Add API to require cryptex + * Treat cryptex and enc xtn hdr as an invalid combination + +------------------------------------------------------------------- Old: ---- v2.8.0.tar.gz New: ---- v2.8.1.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libsrtp2.spec ++++++ --- /var/tmp/diff_new_pack.irehmJ/_old 2026-09-23 14:35:41.789196739 +0200 +++ /var/tmp/diff_new_pack.irehmJ/_new 2026-09-23 14:35:41.790196780 +0200 @@ -18,13 +18,12 @@ Name: libsrtp2 %define lname libsrtp2-1 -Version: 2.8.0 +Version: 2.8.1 Release: 0 Summary: Secure Real-Time Transport Protocol (SRTP) library v2 License: BSD-3-Clause Group: Development/Libraries/C and C++ URL: https://github.com/cisco/libsrtp - Source: https://github.com/cisco/libsrtp/archive/v%version.tar.gz Source99: baselibs.conf Patch1: libsrtp2-test-verbose.patch @@ -77,8 +76,7 @@ %check %make_build runtest -%post -n %lname -p /sbin/ldconfig -%postun -n %lname -p /sbin/ldconfig +%ldconfig_scriptlets -n %lname %files -n %lname %_libdir/libsrtp2.so.1 ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.irehmJ/_old 2026-09-23 14:35:41.819197979 +0200 +++ /var/tmp/diff_new_pack.irehmJ/_new 2026-09-23 14:35:41.822198103 +0200 @@ -1,5 +1,5 @@ -mtime: 1773484326 -commit: 43ed08e7c4ce4c757e1e5bbd8e0d1bd35b1013fecd0bb69a76a200d1d760a28e +mtime: 1789983033 +commit: 4cc0fc3f9f861119cd5428468b3d42dc318f3258745c38a7322d9fab5e091acc url: https://src.opensuse.org/jengelh/libsrtp2 revision: master ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-21 11:30:33.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ v2.8.0.tar.gz -> v2.8.1.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/CHANGES new/libsrtp-2.8.1/CHANGES --- old/libsrtp-2.8.0/CHANGES 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/CHANGES 2026-09-21 08:50:45.000000000 +0200 @@ -1,5 +1,13 @@ Changelog +2.8.1 + +#811 - cryptex and enc xtn hdr is not a valid combination + +#806 - Fix printf format specifiers which cause issues on Windows + +#805 - Add API to require cryptex + 2.8.0 #778 - Backport cryptex to v2 branch diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/CMakeLists.txt new/libsrtp-2.8.1/CMakeLists.txt --- old/libsrtp-2.8.0/CMakeLists.txt 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/CMakeLists.txt 2026-09-21 08:50:45.000000000 +0200 @@ -1,6 +1,6 @@ cmake_minimum_required(VERSION 3.21) -project(libsrtp2 VERSION 2.8.0 LANGUAGES C) +project(libsrtp2 VERSION 2.8.1 LANGUAGES C) set(CMAKE_C_STANDARD 99) set(CMAKE_C_STANDARD_REQUIRED ON) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/configure new/libsrtp-2.8.1/configure --- old/libsrtp-2.8.0/configure 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/configure 2026-09-21 08:50:45.000000000 +0200 @@ -1,6 +1,6 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.64 for libsrtp2 2.8.0. +# Generated by GNU Autoconf 2.64 for libsrtp2 2.8.1. # # Report bugs to <https://github.com/cisco/libsrtp/issues>. # @@ -549,8 +549,8 @@ # Identity of this package. PACKAGE_NAME='libsrtp2' PACKAGE_TARNAME='libsrtp2' -PACKAGE_VERSION='2.8.0' -PACKAGE_STRING='libsrtp2 2.8.0' +PACKAGE_VERSION='2.8.1' +PACKAGE_STRING='libsrtp2 2.8.1' PACKAGE_BUGREPORT='https://github.com/cisco/libsrtp/issues' PACKAGE_URL='' @@ -1247,7 +1247,7 @@ # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -\`configure' configures libsrtp2 2.8.0 to adapt to many kinds of systems. +\`configure' configures libsrtp2 2.8.1 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1312,7 +1312,7 @@ if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of libsrtp2 2.8.0:";; + short | recursive ) echo "Configuration of libsrtp2 2.8.1:";; esac cat <<\_ACEOF @@ -1425,7 +1425,7 @@ test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -libsrtp2 configure 2.8.0 +libsrtp2 configure 2.8.1 generated by GNU Autoconf 2.64 Copyright (C) 2009 Free Software Foundation, Inc. @@ -1973,7 +1973,7 @@ This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by libsrtp2 $as_me 2.8.0, which was +It was created by libsrtp2 $as_me 2.8.1, which was generated by GNU Autoconf 2.64. Invocation command line was $ $0 $@ @@ -6926,7 +6926,7 @@ # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by libsrtp2 $as_me 2.8.0, which was +This file was extended by libsrtp2 $as_me 2.8.1, which was generated by GNU Autoconf 2.64. Invocation command line was CONFIG_FILES = $CONFIG_FILES @@ -6986,7 +6986,7 @@ _ACEOF cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_version="\\ -libsrtp2 config.status 2.8.0 +libsrtp2 config.status 2.8.1 configured by $0, generated by GNU Autoconf 2.64, with options \\"`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`\\" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/configure.ac new/libsrtp-2.8.1/configure.ac --- old/libsrtp-2.8.0/configure.ac 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/configure.ac 2026-09-21 08:50:45.000000000 +0200 @@ -1,5 +1,5 @@ dnl Process this file with autoconf to produce a configure script. -AC_INIT([libsrtp2],[2.8.0],[https://github.com/cisco/libsrtp/issues]) +AC_INIT([libsrtp2],[2.8.1],[https://github.com/cisco/libsrtp/issues]) dnl Must come before AC_PROG_CC EMPTY_CFLAGS="no" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/include/srtp.h new/libsrtp-2.8.1/include/srtp.h --- old/libsrtp-2.8.0/include/srtp.h 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/include/srtp.h 2026-09-21 08:50:45.000000000 +0200 @@ -1759,13 +1759,32 @@ * @param enable whether to enable sending and receiving cryptex. * * @returns srtp_err_status_ok on success, or srtp_err_status_bad_param if the - * stream or template cannot be found for the given SSRC. + * stream or template cannot be found for the given SSRC or if enabling cryptex + * would conflict with encrypted header extensions configured on the stream. */ srtp_err_status_t srtp_set_stream_use_cryptex(srtp_t session, const srtp_ssrc_t *ssrc, int enable); /** + * @brief srtp_set_stream_require_cryptex(session, ssrc, enable) + * + * Require cryptex, RFC 9335, processing for the stream identified by the given + * SSRC. For wildcard SSRC types the require cryptex setting is applied to the + * session template and any streams created from it. + * + * @param session is the SRTP session containing the stream to update. + * @param ssrc describes the SSRC to require cryptex for. + * @param enable whether to require sending and receiving cryptex. + * + * @returns srtp_err_status_ok on success, or srtp_err_status_bad_param if the + * stream or template cannot be found for the given SSRC. + */ +srtp_err_status_t srtp_set_stream_require_cryptex(srtp_t session, + const srtp_ssrc_t *ssrc, + int enable); + +/** * @} */ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/include/srtp_priv.h new/libsrtp-2.8.1/include/srtp_priv.h --- old/libsrtp-2.8.0/include/srtp_priv.h 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/include/srtp_priv.h 2026-09-21 08:50:45.000000000 +0200 @@ -146,6 +146,7 @@ int *enc_xtn_hdr; int enc_xtn_hdr_count; int use_cryptex; + int require_cryptex; uint32_t pending_roc; /* The next and prev pointers are here to allow for a stream list to be diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/meson.build new/libsrtp-2.8.1/meson.build --- old/libsrtp-2.8.0/meson.build 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/meson.build 2026-09-21 08:50:45.000000000 +0200 @@ -1,4 +1,4 @@ -project('libsrtp2', 'c', version: '2.8.0', +project('libsrtp2', 'c', version: '2.8.1', meson_version: '>= 0.52.0', default_options: ['buildtype=debugoptimized']) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/srtp/srtp.c new/libsrtp-2.8.1/srtp/srtp.c --- old/libsrtp-2.8.0/srtp/srtp.c 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/srtp/srtp.c 2026-09-21 08:50:45.000000000 +0200 @@ -235,6 +235,10 @@ *inuse = 0; } + if (stream->require_cryptex && !*inuse && hdr->x == 1) { + return srtp_err_status_cryptex_err; + } + if (*inuse) { srtp_hdr_xtnd_t *xtn_hdr = srtp_get_rtp_xtn_hdr(hdr); *enc_start -= @@ -664,7 +668,8 @@ srtp_session_keys_t *session_keys = NULL; const srtp_session_keys_t *template_session_keys = NULL; - debug_print(mod_srtp, "cloning stream (SSRC: 0x%08x)", ntohl(ssrc)); + debug_print(mod_srtp, "cloning stream (SSRC: 0x%08x)", + (unsigned int)ntohl(ssrc)); /* allocate srtp stream and set str_ptr */ str = (srtp_stream_ctx_t *)srtp_crypto_alloc(sizeof(srtp_stream_ctx_t)); @@ -2782,7 +2787,7 @@ if (ctx->stream_template != NULL) { stream = ctx->stream_template; debug_print(mod_srtp, "using provisional stream (SSRC: 0x%08x)", - ntohl(hdr->ssrc)); + (unsigned int)ntohl(hdr->ssrc)); /* * set estimated packet index to sequence number from header, @@ -4547,7 +4552,7 @@ debug_print(mod_srtp, "srtcp using provisional stream (SSRC: 0x%08x)", - ntohl(hdr->ssrc)); + (unsigned int)ntohl(hdr->ssrc)); } else { /* no template stream, so we return an error */ return srtp_err_status_no_ctx; @@ -5128,6 +5133,7 @@ if (stream->session_keys[0].rtp_auth == data->template->session_keys[0].rtp_auth) { stream->use_cryptex = data->template->use_cryptex; + stream->require_cryptex = data->template->require_cryptex; } return 0; @@ -5149,6 +5155,9 @@ if (stream == NULL) { return srtp_err_status_bad_param; } + if (enable && stream->enc_xtn_hdr_count > 0) { + return srtp_err_status_bad_param; + } stream->use_cryptex = enable != 0; break; case ssrc_any_inbound: @@ -5158,6 +5167,9 @@ if (session->stream_template == NULL) { return srtp_err_status_bad_param; } + if (enable && session->stream_template->enc_xtn_hdr_count > 0) { + return srtp_err_status_bad_param; + } session->stream_template->use_cryptex = enable != 0; data.template = session->stream_template; srtp_stream_list_for_each(session->stream_list, @@ -5167,6 +5179,45 @@ default: return srtp_err_status_bad_param; } + + return srtp_err_status_ok; +} + +srtp_err_status_t srtp_set_stream_require_cryptex(srtp_t session, + const srtp_ssrc_t *ssrc, + int enable) +{ + srtp_stream_t stream; + + if (session == NULL || ssrc == NULL) { + return srtp_err_status_bad_param; + } + + switch (ssrc->type) { + case ssrc_specific: + stream = srtp_get_stream(session, htonl(ssrc->value)); + if (stream == NULL) { + return srtp_err_status_bad_param; + } + stream->require_cryptex = enable != 0; + break; + case ssrc_any_inbound: { + struct set_cryptex_from_template_data data; + + if (session->stream_template == NULL) { + return srtp_err_status_bad_param; + } + session->stream_template->require_cryptex = enable != 0; + data.template = session->stream_template; + srtp_stream_list_for_each(session->stream_list, + set_cryptex_from_template_cb, &data); + break; + } + case ssrc_any_outbound: + // Requiring cryptex is not possible for outbound SSRCs, fall through. + default: + return srtp_err_status_bad_param; + } return srtp_err_status_ok; } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libsrtp-2.8.0/test/srtp_driver.c new/libsrtp-2.8.1/test/srtp_driver.c --- old/libsrtp-2.8.0/test/srtp_driver.c 2026-03-14 10:49:34.000000000 +0100 +++ new/libsrtp-2.8.1/test/srtp_driver.c 2026-09-21 08:50:45.000000000 +0200 @@ -115,6 +115,10 @@ srtp_err_status_t srtp_test_cryptex_disable(void); +srtp_err_status_t srtp_test_require_cryptex(void); + +srtp_err_status_t srtp_test_cryptex_and_enc_xtn_hdr_invalid(void); + double srtp_bits_per_second(int msg_len_octets, const srtp_policy_t *policy); double srtp_rejections_per_second(int msg_len_octets, @@ -684,6 +688,22 @@ printf("failed\n"); exit(1); } + + printf("testing require_cryptex()..."); + if (srtp_test_require_cryptex() == srtp_err_status_ok) { + printf("passed\n"); + } else { + printf("failed\n"); + exit(1); + } + + printf("testing cryptex_and_enc_xtn_hdr_invalid()..."); + if (srtp_test_cryptex_and_enc_xtn_hdr_invalid() == srtp_err_status_ok) { + printf("passed\n"); + } else { + printf("failed\n"); + exit(1); + } } if (do_stream_list) { @@ -2706,6 +2726,83 @@ return srtp_err_status_ok; } + +srtp_err_status_t srtp_test_require_cryptex(void) +{ + srtp_policy_t policy; + memset(&policy, 0, sizeof(policy)); + srtp_crypto_policy_set_rtp_default(&policy.rtp); + srtp_crypto_policy_set_rtcp_default(&policy.rtcp); + policy.ssrc.type = ssrc_any_outbound; + policy.ssrc.value = 0xcafebabe; + policy.key = test_key; + policy.window_size = 128; + policy.allow_repeat_tx = 0; + policy.next = NULL; + + srtp_t srtp_snd, srtp_recv; + CHECK_OK(srtp_create(&srtp_snd, &policy)); + CHECK_OK(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 0)); + /* + * requiring cryptex is not defined for the outbound wildcard ssrc. + */ + CHECK_RETURN(srtp_set_stream_require_cryptex(srtp_snd, &policy.ssrc, 1), + srtp_err_status_bad_param); + policy.ssrc.type = ssrc_any_inbound; + CHECK_OK(srtp_create(&srtp_recv, &policy)); + CHECK_OK(srtp_set_stream_require_cryptex(srtp_recv, &policy.ssrc, 1)); + + int packet_len; + srtp_hdr_t *packet = + srtp_create_test_packet_ext_hdr(100, policy.ssrc.value, &packet_len); + + CHECK_OK(srtp_protect(srtp_snd, packet, &packet_len)); + + CHECK_RETURN(srtp_unprotect(srtp_recv, packet, &packet_len), + srtp_err_status_cryptex_err); + + CHECK_OK(srtp_dealloc(srtp_snd)); + CHECK_OK(srtp_dealloc(srtp_recv)); + free(packet); + + return srtp_err_status_ok; +} + +srtp_err_status_t srtp_test_cryptex_and_enc_xtn_hdr_invalid(void) +{ + int headers[] = { 1 }; + + srtp_policy_t policy; + memset(&policy, 0, sizeof(policy)); + srtp_crypto_policy_set_rtp_default(&policy.rtp); + srtp_crypto_policy_set_rtcp_default(&policy.rtcp); + policy.ssrc.type = ssrc_specific; + policy.ssrc.value = 0xcafebabe; + policy.key = test_key; + policy.window_size = 128; + policy.allow_repeat_tx = 0; + policy.enc_xtn_hdr = headers; + policy.enc_xtn_hdr_count = sizeof(headers) / sizeof(headers[0]); + policy.next = NULL; + + srtp_t srtp_snd; + CHECK_OK(srtp_create(&srtp_snd, &policy)); + CHECK_RETURN(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 1), + srtp_err_status_bad_param); + /* disabling is still allowed */ + CHECK_OK(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 0)); + CHECK_OK(srtp_dealloc(srtp_snd)); + + policy.ssrc.type = ssrc_any_outbound; + srtp_t srtp_snd_wildcard; + CHECK_OK(srtp_create(&srtp_snd_wildcard, &policy)); + CHECK_RETURN( + srtp_set_stream_use_cryptex(srtp_snd_wildcard, &policy.ssrc, 1), + srtp_err_status_bad_param); + CHECK_OK(srtp_dealloc(srtp_snd_wildcard)); + + return srtp_err_status_ok; +} #ifdef GCM /*
