Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libsrtp2 for openSUSE:Factory 
checked in at 2026-09-23 14:34:18
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libsrtp2 (Old)
 and      /work/SRC/openSUSE:Factory/.libsrtp2.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libsrtp2"

Wed Sep 23 14:34:18 2026 rev:15 rq:1379449 version:2.8.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/libsrtp2/libsrtp2.changes        2026-03-14 
22:22:03.168279617 +0100
+++ /work/SRC/openSUSE:Factory/.libsrtp2.new.383539/libsrtp2.changes    
2026-09-23 14:35:41.156170564 +0200
@@ -1,0 +2,7 @@
+Mon Sep 21 09:25:07 UTC 2026 - Jan Engelhardt <[email protected]>
+
+- Update to release 2.8.1
+  * Add API to require cryptex
+  * Treat cryptex and enc xtn hdr as an invalid combination
+
+-------------------------------------------------------------------

Old:
----
  v2.8.0.tar.gz

New:
----
  v2.8.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libsrtp2.spec ++++++
--- /var/tmp/diff_new_pack.irehmJ/_old  2026-09-23 14:35:41.789196739 +0200
+++ /var/tmp/diff_new_pack.irehmJ/_new  2026-09-23 14:35:41.790196780 +0200
@@ -18,13 +18,12 @@
 
 Name:           libsrtp2
 %define lname  libsrtp2-1
-Version:        2.8.0
+Version:        2.8.1
 Release:        0
 Summary:        Secure Real-Time Transport Protocol (SRTP) library v2
 License:        BSD-3-Clause
 Group:          Development/Libraries/C and C++
 URL:            https://github.com/cisco/libsrtp
-
 Source:         https://github.com/cisco/libsrtp/archive/v%version.tar.gz
 Source99:       baselibs.conf
 Patch1:         libsrtp2-test-verbose.patch
@@ -77,8 +76,7 @@
 %check
 %make_build runtest
 
-%post   -n %lname -p /sbin/ldconfig
-%postun -n %lname -p /sbin/ldconfig
+%ldconfig_scriptlets -n %lname
 
 %files -n %lname
 %_libdir/libsrtp2.so.1

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.irehmJ/_old  2026-09-23 14:35:41.819197979 +0200
+++ /var/tmp/diff_new_pack.irehmJ/_new  2026-09-23 14:35:41.822198103 +0200
@@ -1,5 +1,5 @@
-mtime: 1773484326
-commit: 43ed08e7c4ce4c757e1e5bbd8e0d1bd35b1013fecd0bb69a76a200d1d760a28e
+mtime: 1789983033
+commit: 4cc0fc3f9f861119cd5428468b3d42dc318f3258745c38a7322d9fab5e091acc
 url: https://src.opensuse.org/jengelh/libsrtp2
 revision: master
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-21 11:30:33.000000000 +0200
@@ -0,0 +1 @@
+.osc

++++++ v2.8.0.tar.gz -> v2.8.1.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/CHANGES new/libsrtp-2.8.1/CHANGES
--- old/libsrtp-2.8.0/CHANGES   2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/CHANGES   2026-09-21 08:50:45.000000000 +0200
@@ -1,5 +1,13 @@
 Changelog
 
+2.8.1
+
+#811 - cryptex and enc xtn hdr is not a valid combination
+
+#806 - Fix printf format specifiers which cause issues on Windows
+
+#805 - Add API to require cryptex
+
 2.8.0
 
 #778 - Backport cryptex to v2 branch
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/CMakeLists.txt 
new/libsrtp-2.8.1/CMakeLists.txt
--- old/libsrtp-2.8.0/CMakeLists.txt    2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/CMakeLists.txt    2026-09-21 08:50:45.000000000 +0200
@@ -1,6 +1,6 @@
 cmake_minimum_required(VERSION 3.21)
 
-project(libsrtp2 VERSION 2.8.0 LANGUAGES C)
+project(libsrtp2 VERSION 2.8.1 LANGUAGES C)
 
 set(CMAKE_C_STANDARD 99)
 set(CMAKE_C_STANDARD_REQUIRED ON)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/configure new/libsrtp-2.8.1/configure
--- old/libsrtp-2.8.0/configure 2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/configure 2026-09-21 08:50:45.000000000 +0200
@@ -1,6 +1,6 @@
 #! /bin/sh
 # Guess values for system-dependent variables and create Makefiles.
-# Generated by GNU Autoconf 2.64 for libsrtp2 2.8.0.
+# Generated by GNU Autoconf 2.64 for libsrtp2 2.8.1.
 #
 # Report bugs to <https://github.com/cisco/libsrtp/issues>.
 #
@@ -549,8 +549,8 @@
 # Identity of this package.
 PACKAGE_NAME='libsrtp2'
 PACKAGE_TARNAME='libsrtp2'
-PACKAGE_VERSION='2.8.0'
-PACKAGE_STRING='libsrtp2 2.8.0'
+PACKAGE_VERSION='2.8.1'
+PACKAGE_STRING='libsrtp2 2.8.1'
 PACKAGE_BUGREPORT='https://github.com/cisco/libsrtp/issues'
 PACKAGE_URL=''
 
@@ -1247,7 +1247,7 @@
   # Omit some internal or obsolete options to make the list less imposing.
   # This message is too long to be a string in the A/UX 3.1 sh.
   cat <<_ACEOF
-\`configure' configures libsrtp2 2.8.0 to adapt to many kinds of systems.
+\`configure' configures libsrtp2 2.8.1 to adapt to many kinds of systems.
 
 Usage: $0 [OPTION]... [VAR=VALUE]...
 
@@ -1312,7 +1312,7 @@
 
 if test -n "$ac_init_help"; then
   case $ac_init_help in
-     short | recursive ) echo "Configuration of libsrtp2 2.8.0:";;
+     short | recursive ) echo "Configuration of libsrtp2 2.8.1:";;
    esac
   cat <<\_ACEOF
 
@@ -1425,7 +1425,7 @@
 test -n "$ac_init_help" && exit $ac_status
 if $ac_init_version; then
   cat <<\_ACEOF
-libsrtp2 configure 2.8.0
+libsrtp2 configure 2.8.1
 generated by GNU Autoconf 2.64
 
 Copyright (C) 2009 Free Software Foundation, Inc.
@@ -1973,7 +1973,7 @@
 This file contains any messages produced by compilers while
 running configure, to aid debugging if configure makes a mistake.
 
-It was created by libsrtp2 $as_me 2.8.0, which was
+It was created by libsrtp2 $as_me 2.8.1, which was
 generated by GNU Autoconf 2.64.  Invocation command line was
 
   $ $0 $@
@@ -6926,7 +6926,7 @@
 # report actual input values of CONFIG_FILES etc. instead of their
 # values after options handling.
 ac_log="
-This file was extended by libsrtp2 $as_me 2.8.0, which was
+This file was extended by libsrtp2 $as_me 2.8.1, which was
 generated by GNU Autoconf 2.64.  Invocation command line was
 
   CONFIG_FILES    = $CONFIG_FILES
@@ -6986,7 +6986,7 @@
 _ACEOF
 cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
 ac_cs_version="\\
-libsrtp2 config.status 2.8.0
+libsrtp2 config.status 2.8.1
 configured by $0, generated by GNU Autoconf 2.64,
   with options \\"`$as_echo "$ac_configure_args" | sed 's/^ //; 
s/[\\""\`\$]/\\\\&/g'`\\"
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/configure.ac 
new/libsrtp-2.8.1/configure.ac
--- old/libsrtp-2.8.0/configure.ac      2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/configure.ac      2026-09-21 08:50:45.000000000 +0200
@@ -1,5 +1,5 @@
 dnl Process this file with autoconf to produce a configure script.
-AC_INIT([libsrtp2],[2.8.0],[https://github.com/cisco/libsrtp/issues])
+AC_INIT([libsrtp2],[2.8.1],[https://github.com/cisco/libsrtp/issues])
 
 dnl Must come before AC_PROG_CC
 EMPTY_CFLAGS="no"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/include/srtp.h 
new/libsrtp-2.8.1/include/srtp.h
--- old/libsrtp-2.8.0/include/srtp.h    2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/include/srtp.h    2026-09-21 08:50:45.000000000 +0200
@@ -1759,13 +1759,32 @@
  * @param enable whether to enable sending and receiving cryptex.
  *
  * @returns srtp_err_status_ok on success, or srtp_err_status_bad_param if the
- * stream or template cannot be found for the given SSRC.
+ * stream or template cannot be found for the given SSRC or if enabling cryptex
+ * would conflict with encrypted header extensions configured on the stream.
  */
 srtp_err_status_t srtp_set_stream_use_cryptex(srtp_t session,
                                               const srtp_ssrc_t *ssrc,
                                               int enable);
 
 /**
+ * @brief srtp_set_stream_require_cryptex(session, ssrc, enable)
+ *
+ * Require cryptex, RFC 9335, processing for the stream identified by the given
+ * SSRC. For wildcard SSRC types the require cryptex setting is applied to the
+ * session template and any streams created from it.
+ *
+ * @param session is the SRTP session containing the stream to update.
+ * @param ssrc describes the SSRC to require cryptex for.
+ * @param enable whether to require sending and receiving cryptex.
+ *
+ * @returns srtp_err_status_ok on success, or srtp_err_status_bad_param if the
+ * stream or template cannot be found for the given SSRC.
+ */
+srtp_err_status_t srtp_set_stream_require_cryptex(srtp_t session,
+                                                  const srtp_ssrc_t *ssrc,
+                                                  int enable);
+
+/**
  * @}
  */
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/include/srtp_priv.h 
new/libsrtp-2.8.1/include/srtp_priv.h
--- old/libsrtp-2.8.0/include/srtp_priv.h       2026-03-14 10:49:34.000000000 
+0100
+++ new/libsrtp-2.8.1/include/srtp_priv.h       2026-09-21 08:50:45.000000000 
+0200
@@ -146,6 +146,7 @@
     int *enc_xtn_hdr;
     int enc_xtn_hdr_count;
     int use_cryptex;
+    int require_cryptex;
     uint32_t pending_roc;
     /*
     The next and prev pointers are here to allow for a stream list to be
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/meson.build 
new/libsrtp-2.8.1/meson.build
--- old/libsrtp-2.8.0/meson.build       2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/meson.build       2026-09-21 08:50:45.000000000 +0200
@@ -1,4 +1,4 @@
-project('libsrtp2', 'c', version: '2.8.0',
+project('libsrtp2', 'c', version: '2.8.1',
   meson_version: '>= 0.52.0',
   default_options: ['buildtype=debugoptimized'])
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/srtp/srtp.c 
new/libsrtp-2.8.1/srtp/srtp.c
--- old/libsrtp-2.8.0/srtp/srtp.c       2026-03-14 10:49:34.000000000 +0100
+++ new/libsrtp-2.8.1/srtp/srtp.c       2026-09-21 08:50:45.000000000 +0200
@@ -235,6 +235,10 @@
         *inuse = 0;
     }
 
+    if (stream->require_cryptex && !*inuse && hdr->x == 1) {
+        return srtp_err_status_cryptex_err;
+    }
+
     if (*inuse) {
         srtp_hdr_xtnd_t *xtn_hdr = srtp_get_rtp_xtn_hdr(hdr);
         *enc_start -=
@@ -664,7 +668,8 @@
     srtp_session_keys_t *session_keys = NULL;
     const srtp_session_keys_t *template_session_keys = NULL;
 
-    debug_print(mod_srtp, "cloning stream (SSRC: 0x%08x)", ntohl(ssrc));
+    debug_print(mod_srtp, "cloning stream (SSRC: 0x%08x)",
+                (unsigned int)ntohl(ssrc));
 
     /* allocate srtp stream and set str_ptr */
     str = (srtp_stream_ctx_t *)srtp_crypto_alloc(sizeof(srtp_stream_ctx_t));
@@ -2782,7 +2787,7 @@
         if (ctx->stream_template != NULL) {
             stream = ctx->stream_template;
             debug_print(mod_srtp, "using provisional stream (SSRC: 0x%08x)",
-                        ntohl(hdr->ssrc));
+                        (unsigned int)ntohl(hdr->ssrc));
 
 /*
  * set estimated packet index to sequence number from header,
@@ -4547,7 +4552,7 @@
 
             debug_print(mod_srtp,
                         "srtcp using provisional stream (SSRC: 0x%08x)",
-                        ntohl(hdr->ssrc));
+                        (unsigned int)ntohl(hdr->ssrc));
         } else {
             /* no template stream, so we return an error */
             return srtp_err_status_no_ctx;
@@ -5128,6 +5133,7 @@
     if (stream->session_keys[0].rtp_auth ==
         data->template->session_keys[0].rtp_auth) {
         stream->use_cryptex = data->template->use_cryptex;
+        stream->require_cryptex = data->template->require_cryptex;
     }
 
     return 0;
@@ -5149,6 +5155,9 @@
         if (stream == NULL) {
             return srtp_err_status_bad_param;
         }
+        if (enable && stream->enc_xtn_hdr_count > 0) {
+            return srtp_err_status_bad_param;
+        }
         stream->use_cryptex = enable != 0;
         break;
     case ssrc_any_inbound:
@@ -5158,6 +5167,9 @@
         if (session->stream_template == NULL) {
             return srtp_err_status_bad_param;
         }
+        if (enable && session->stream_template->enc_xtn_hdr_count > 0) {
+            return srtp_err_status_bad_param;
+        }
         session->stream_template->use_cryptex = enable != 0;
         data.template = session->stream_template;
         srtp_stream_list_for_each(session->stream_list,
@@ -5167,6 +5179,45 @@
     default:
         return srtp_err_status_bad_param;
     }
+
+    return srtp_err_status_ok;
+}
+
+srtp_err_status_t srtp_set_stream_require_cryptex(srtp_t session,
+                                                  const srtp_ssrc_t *ssrc,
+                                                  int enable)
+{
+    srtp_stream_t stream;
+
+    if (session == NULL || ssrc == NULL) {
+        return srtp_err_status_bad_param;
+    }
+
+    switch (ssrc->type) {
+    case ssrc_specific:
+        stream = srtp_get_stream(session, htonl(ssrc->value));
+        if (stream == NULL) {
+            return srtp_err_status_bad_param;
+        }
+        stream->require_cryptex = enable != 0;
+        break;
+    case ssrc_any_inbound: {
+        struct set_cryptex_from_template_data data;
+
+        if (session->stream_template == NULL) {
+            return srtp_err_status_bad_param;
+        }
+        session->stream_template->require_cryptex = enable != 0;
+        data.template = session->stream_template;
+        srtp_stream_list_for_each(session->stream_list,
+                                  set_cryptex_from_template_cb, &data);
+        break;
+    }
+    case ssrc_any_outbound:
+        // Requiring cryptex is not possible for outbound SSRCs, fall through.
+    default:
+        return srtp_err_status_bad_param;
+    }
 
     return srtp_err_status_ok;
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libsrtp-2.8.0/test/srtp_driver.c 
new/libsrtp-2.8.1/test/srtp_driver.c
--- old/libsrtp-2.8.0/test/srtp_driver.c        2026-03-14 10:49:34.000000000 
+0100
+++ new/libsrtp-2.8.1/test/srtp_driver.c        2026-09-21 08:50:45.000000000 
+0200
@@ -115,6 +115,10 @@
 
 srtp_err_status_t srtp_test_cryptex_disable(void);
 
+srtp_err_status_t srtp_test_require_cryptex(void);
+
+srtp_err_status_t srtp_test_cryptex_and_enc_xtn_hdr_invalid(void);
+
 double srtp_bits_per_second(int msg_len_octets, const srtp_policy_t *policy);
 
 double srtp_rejections_per_second(int msg_len_octets,
@@ -684,6 +688,22 @@
             printf("failed\n");
             exit(1);
         }
+
+        printf("testing require_cryptex()...");
+        if (srtp_test_require_cryptex() == srtp_err_status_ok) {
+            printf("passed\n");
+        } else {
+            printf("failed\n");
+            exit(1);
+        }
+
+        printf("testing cryptex_and_enc_xtn_hdr_invalid()...");
+        if (srtp_test_cryptex_and_enc_xtn_hdr_invalid() == srtp_err_status_ok) 
{
+            printf("passed\n");
+        } else {
+            printf("failed\n");
+            exit(1);
+        }
     }
 
     if (do_stream_list) {
@@ -2706,6 +2726,83 @@
 
     return srtp_err_status_ok;
 }
+
+srtp_err_status_t srtp_test_require_cryptex(void)
+{
+    srtp_policy_t policy;
+    memset(&policy, 0, sizeof(policy));
+    srtp_crypto_policy_set_rtp_default(&policy.rtp);
+    srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
+    policy.ssrc.type = ssrc_any_outbound;
+    policy.ssrc.value = 0xcafebabe;
+    policy.key = test_key;
+    policy.window_size = 128;
+    policy.allow_repeat_tx = 0;
+    policy.next = NULL;
+
+    srtp_t srtp_snd, srtp_recv;
+    CHECK_OK(srtp_create(&srtp_snd, &policy));
+    CHECK_OK(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 0));
+    /*
+     * requiring cryptex is not defined for the outbound wildcard ssrc.
+     */
+    CHECK_RETURN(srtp_set_stream_require_cryptex(srtp_snd, &policy.ssrc, 1),
+                 srtp_err_status_bad_param);
+    policy.ssrc.type = ssrc_any_inbound;
+    CHECK_OK(srtp_create(&srtp_recv, &policy));
+    CHECK_OK(srtp_set_stream_require_cryptex(srtp_recv, &policy.ssrc, 1));
+
+    int packet_len;
+    srtp_hdr_t *packet =
+        srtp_create_test_packet_ext_hdr(100, policy.ssrc.value, &packet_len);
+
+    CHECK_OK(srtp_protect(srtp_snd, packet, &packet_len));
+
+    CHECK_RETURN(srtp_unprotect(srtp_recv, packet, &packet_len),
+                 srtp_err_status_cryptex_err);
+
+    CHECK_OK(srtp_dealloc(srtp_snd));
+    CHECK_OK(srtp_dealloc(srtp_recv));
+    free(packet);
+
+    return srtp_err_status_ok;
+}
+
+srtp_err_status_t srtp_test_cryptex_and_enc_xtn_hdr_invalid(void)
+{
+    int headers[] = { 1 };
+
+    srtp_policy_t policy;
+    memset(&policy, 0, sizeof(policy));
+    srtp_crypto_policy_set_rtp_default(&policy.rtp);
+    srtp_crypto_policy_set_rtcp_default(&policy.rtcp);
+    policy.ssrc.type = ssrc_specific;
+    policy.ssrc.value = 0xcafebabe;
+    policy.key = test_key;
+    policy.window_size = 128;
+    policy.allow_repeat_tx = 0;
+    policy.enc_xtn_hdr = headers;
+    policy.enc_xtn_hdr_count = sizeof(headers) / sizeof(headers[0]);
+    policy.next = NULL;
+
+    srtp_t srtp_snd;
+    CHECK_OK(srtp_create(&srtp_snd, &policy));
+    CHECK_RETURN(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 1),
+                 srtp_err_status_bad_param);
+    /* disabling is still allowed */
+    CHECK_OK(srtp_set_stream_use_cryptex(srtp_snd, &policy.ssrc, 0));
+    CHECK_OK(srtp_dealloc(srtp_snd));
+
+    policy.ssrc.type = ssrc_any_outbound;
+    srtp_t srtp_snd_wildcard;
+    CHECK_OK(srtp_create(&srtp_snd_wildcard, &policy));
+    CHECK_RETURN(
+        srtp_set_stream_use_cryptex(srtp_snd_wildcard, &policy.ssrc, 1),
+        srtp_err_status_bad_param);
+    CHECK_OK(srtp_dealloc(srtp_snd_wildcard));
+
+    return srtp_err_status_ok;
+}
 
 #ifdef GCM
 /*

Reply via email to