Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package sipp for openSUSE:Factory checked in 
at 2026-10-01 16:45:39
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/sipp (Old)
 and      /work/SRC/openSUSE:Factory/.sipp.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "sipp"

Thu Oct  1 16:45:39 2026 rev:10 rq:1381716 version:3.7.9

Changes:
--------
--- /work/SRC/openSUSE:Factory/sipp/sipp.changes        2026-09-24 
23:01:51.400260531 +0200
+++ /work/SRC/openSUSE:Factory/.sipp.new.1253/sipp.changes      2026-10-01 
16:46:48.747455807 +0200
@@ -1,0 +2,14 @@
+Wed Sep 30 15:46:52 UTC 2026 - Martin Hauke <[email protected]>
+
+- Update to version 3.7.9
+  * Attribute values are XML-decoded once again, as before 3.7.8,
+    so &amp;lt; gives &lt; #1062 and #1098
+  * A memory leak in every MD5 digest, since 3.7.8 #884
+  * AKAv1-MD5 with wolfSSL lost the last byte of a padded nonce,
+    since 3.7.8 #1014
+  * Configuring without GTest failed, since 3.7.8 #891
+  * CMake takes any boolean for USE_SYSTEM_PUGIXML and
+    USE_SYSTEM_GTEST #1060
+  * Building with GCC 16: the bundled pugixml is updated to 1.16
+
+-------------------------------------------------------------------

Old:
----
  sipp-3.7.8.tar.gz

New:
----
  sipp-3.7.9.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ sipp.spec ++++++
--- /var/tmp/diff_new_pack.oC9wno/_old  2026-10-01 16:46:49.583490847 +0200
+++ /var/tmp/diff_new_pack.oC9wno/_new  2026-10-01 16:46:49.585490930 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           sipp
-Version:        3.7.8
+Version:        3.7.9
 Release:        0
 Summary:        A SIP protocol testing tool
 License:        GPL-2.0-or-later
@@ -32,7 +32,9 @@
 BuildRequires:  ncurses-devel
 BuildRequires:  pkgconfig
 BuildRequires:  pkgconfig(gsl)
+BuildRequires:  pkgconfig(gtest)
 BuildRequires:  pkgconfig(libssl)
+BuildRequires:  pkgconfig(pugixml)
 
 %description
 Sipp is a performance testing tool for the SIP protocol. Its main features are
@@ -43,9 +45,13 @@
 %prep
 %autosetup
 sed -i 's|#!%{_bindir}/env python3|#!%{_bindir}/python3|g' sipp-multi.py
+# delete bundled libraries
+rm -Rf ./third_party/
 
 %build
 %cmake \
+    -DUSE_SYSTEM_PUGIXML=1 \
+    -DUSE_SYSTEM_GTEST=1 \
     -DUSE_GSL=1 \
     -DUSE_PCAP=1 \
     -DUSE_SSL=1 \

++++++ sipp-3.7.8.tar.gz -> sipp-3.7.9.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/CHANGES.md new/sipp-3.7.9/CHANGES.md
--- old/sipp-3.7.8/CHANGES.md   2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/CHANGES.md   2026-09-30 09:12:47.000000000 +0200
@@ -1,13 +1,121 @@
-Features added in 3.7.5
-=======================
+# Changelog
 
-- Enable a mixture of server-mode and client-mode operation simultaneously (by 
Matthew Briggs)
-- Support for regexp matching on response codes (by Orgad Shaneh)
-- Support RFC3339 timestamp format and timezone offset (by Costis)
+All notable changes to SIPp are documented in this file.
+
+The format is based on [Keep a 
Changelog](https://keepachangelog.com/en/1.1.0/).
+Changes that may break existing scenarios, command lines or builds are
+marked **Breaking**.
+
+## [3.7.9] - 2026-09-30
+
+### Fixed
+
+- Attribute values are XML-decoded once again, as before 3.7.8, so
+  `&amp;lt;` gives `&lt;` (#1062, #1098, by Orgad Shaneh)
+- A memory leak in every MD5 digest, since 3.7.8 (#884, by Orgad Shaneh)
+- AKAv1-MD5 with wolfSSL lost the last byte of a padded nonce, since
+  3.7.8 (#1014, by Orgad Shaneh)
+- Configuring without GTest failed, since 3.7.8 (#891, by Orgad Shaneh)
+- CMake takes any boolean for `USE_SYSTEM_PUGIXML` and
+  `USE_SYSTEM_GTEST`, such as the Fedora package's `1` (#1060, by Peter
+  Lemenkov)
+- Building with GCC 16: the bundled pugixml is updated to 1.16 (#1047,
+  by Orgad Shaneh)
+
+## [3.7.8] - 2026-09-23
+
+### Added
+
+- `-cid_type` selects a built-in Call-ID generator: `uuid`,
+  `uuid-compact`, `random` or `timestamp`. The default keeps using
+  `-cid_str` (#869, by Darwvin)
+- An interactive wizard that builds a command line when SIPp is started
+  without arguments on a terminal (#868, by Darwvin)
+- `sipp-multi.py`, a helper that starts and supervises several SIPp
+  instances described in a CSV file (#873, by Darwvin)
+- CMake `USE_SYSTEM_GTEST` builds the unit tests against a system-wide
+  GTest (#836, by Peter Lemenkov)
+- clang-format configuration and CONTRIBUTING.md (#855, by Peter Lemenkov)
+
+### Changed
+
+- **Breaking:** The scenario XML parser is now pugixml. It is bundled as
+  a git submodule (clone with `--recursive`), or taken from the system
+  with `-DUSE_SYSTEM_PUGIXML=ON`. Scenario files are no longer limited
+  to 64 KB (#858, by Peter Lemenkov)
+- Timing uses `std::chrono` (#854, by Peter Lemenkov)
+
+### Removed
+
+- **Breaking:** SIPp's bundled MD5, AKA and base64 code. Building now
+  requires OpenSSL (1.1.1 or later) or wolfSSL (#827, #828, #842, by
+  Peter Lemenkov)
+- The `-c` compression plugin option, for which no plugin was ever
+  distributed (#853, by Peter Lemenkov)
+
+### Fixed
+
+- Every call with `-t t1`, `tn`, `l1` or `ln` failed with "Unable to bind
+  TCP socket": the 3.7.0 `[local_port]` fix for TCP and TLS is reverted
+  (#830, by Orgad Shaneh)
+- The BYE of an aborted call follows the dialog's route set (#851, by
+  Daniel Donoghue)
+- SDP is found in multipart/mixed message bodies (#862, by Mark T)
+- Heap-use-after-free when a UDP retransmission fails to send (#876, by
+  Orgad Shaneh)
+- `get_header()` writes are bounded by its buffer (#881, by Peter Lemenkov)
+- Use-after-free and no-op bugs when clearing maps (#839, by Peter Lemenkov)
+- Data race in the debug files (#859, by Peter Lemenkov)
+- RTP debug dumps of several sessions (#848, by Orgad Shaneh)
+- An infinite loop in the build with the bundled gtest (#845, by Orgad
+  Shaneh)
+
+## [3.7.7] - 2025-12-30
+
+### Fixed
+
+- Const-correctness of an argument that is modified (#826, by Peter
+  Lemenkov)
+
+## [3.7.6] - 2025-12-22
+
+### Added
+
+- `%r` in `-cid_str` inserts a random number, for unique Call-IDs when
+  several instances run in parallel (#810, by Maksim Nesterov)
+- The `sipp` executable exports its symbols, so that plugins can use
+  them (#820, by Orgad Shaneh)
+
+### Changed
+
+- **Breaking:** Building requires a C++17 compiler (by Orgad Shaneh)
+- Bundled gtest updated to 1.17 (by Orgad Shaneh)
+
+### Fixed
+
+- SRTP: a buffer overrun and a missing null termination when parsing
+  received crypto lines, and mis-parsing of a long input line (#822, by
+  Orgad Shaneh)
+- The `-trace_logs` file name (by Orgad Shaneh)
+
+## [3.7.5] - 2025-08-19
 
-Bugs fixed in 3.7.5
-===================
+### Added
 
+- Enable a mixture of server-mode and client-mode operation simultaneously (by 
Matthew Briggs)
+- Support for regexp matching on response codes (by Petr Cisar)
+- Support RFC3339 timestamp format and timezone offset (by Costis)
+- Send the SNI in the TLS client hello (#754, by Jean-Christophe Grondin)
+- Replay raw IP pcap files (#763, by Jérôme Poulin)
+- Seed the random generator with the host name and PID too, so that
+  instances started together differ (#738, by FalacerSelene)
+- A Debian-based Dockerfile (#759, by Orgad Shaneh)
+
+### Fixed
+
+- Out-of-bounds read on invalid XML (#747, by Orgad Shaneh)
+- `<nop>` overrides the last action result only if it is a failure
+  (#766, by Tolga)
 - Fix RTPCHECK functionality regressions (by Jeannot Langlois)
 - Fix SRTPCheck testing on unlimited number of calls (by Michal Hajek)
 - Use random SSRC for SRTP instead of hardcoded value (by Orgad Shaneh)
@@ -18,37 +126,71 @@
 - Mark aborted calls as failed (by Orgad Shaneh)
 - Various stability and build fixes (by Orgad Shaneh, Jaco Kroon, Michal Hajek)
 
-BREAKING(!) changes in 3.7.3
-============================
+## [3.7.4] - 2024-09-10
+
+### Fixed
+
+- Build with wolfSSL (by Orgad Shaneh)
+- Docker: update Alpine to 3.20 and fix the version resolving (#749, by
+  Orgad Shaneh)
+
+## [3.7.3] - 2024-08-07
+
+### Added
+
+- SHA-256 Digest authentication (RFC 8760) (#676, by Marat Gareev)
+- TLS 1.3 (#695, by Orgad Shaneh)
+- `-bind_to_device` option (#630, by Ivan Gankevich)
+- Comfort noise (audio/CN) media support (#687, by Rafael Vargas)
+- TLS verification without a CRL file (#663, by Ivan Ribakov)
+- Random SSRC for RTP streams (#599, by Stefan Mititelu)
+- `hide` and `display` attributes (#718, by Michael Stovenour)
+- A define to use local IP hints (#598, by Stefan Mititelu)
+- pcap file paths that start with `~` (#607, by Rajesh Singh)
 
-- Remove support for variables in PCAP filenames, originally introduced in 
3.7.0. See #673
-    
-Bugs fixed in 3.7.3
-===================
+### Changed
+
+- Bundled gtest updated to 1.14.0; building requires C++14 and CMake 3.5
+  (#649, #651, by Orgad Shaneh)
+
+### Removed
+
+- **Breaking:** Remove support for variables in PCAP filenames, originally 
introduced in 3.7.0. See #673
+
+### Fixed
 
 - Recovered `-mp` and `[auto_media_port]` to maintain backwards compatibility 
(by Orgad Shaneh)
 - Fix crash when using PCAP play with more than one call (by Pete O'Neill)
 - Fix pager on macOS by trying less and more too (by Walter Doekes)
+- `[next_url]` could return garbage (#724, by Michael Stovenour)
+- rtp_stream failed to bind on macOS, and CRLF in injection files (#729,
+  by Zac He)
+- rtpstream local port allocation (#734, by viktike), and the next RTP
+  port was always reset to the minimum (#635, by Stefan Mititelu)
+- The RTP playback thread blocked on `select()` (#690, by Shona McNeill)
+
+## [3.7.2] - 2023-11-16
 
-Bugs fixed in 3.7.2
-===================
+### Fixed
 
 - Remove excessive log
 
-Bugs fixed in 3.7.1
-=======================
+## [3.7.1] - 2023-05-19
+
+### Fixed
 
 - Correctly open the control socket
 - The SIPp binary can now be built even when the `gtest` checkout is missing
 - rtpstream files are now also found next to the scenario. If it is not found 
there, it will be treated as a relative path as usual.
 
-Features added in 3.7.0
-===========================
+## [3.7.0] - 2023-04-02
+
+### Added
 
 - RTPstream can now handle .wav files with a WAV header (by Orgad Shaneh)
 
-Bugs fixed in 3.7.0
-=======================
+### Fixed
+
 - RTPCHECK stability fixes (by Jeannot Langlois)
 - Support CRLF-format injection files (by Orgad Shaneh)
 - Fix to [next_url] when a display name is present in the contact (by enneig)
@@ -68,10 +210,11 @@
 - Cygwin, FreeBSD and Hurd build fixes (by Orgad Shaneh, kadabusha and 
Zopolis4)
 - Static build fixes (by  Aaron Meriwether)
 
-Features added in 3.7.0~rc1
-===========================
+## [3.7.0-rc1] - 2021-10-26
+
+### Added
 
-* B2BUA Media Gateway RTP/SRTP bit pattern testing -- see
+- B2BUA Media Gateway RTP/SRTP bit pattern testing -- see
   `docs/rtpcheck_xml_syntax_reference.pdf`. Command line examples:
     ```
     # UAS (RTP)
@@ -93,115 +236,82 @@
       127.0.0.3:5060
     ```
   By Jeannot Langlois.
-* Removed `-mp` in favor of `-min_rtp_port` and `-max_rtp_port`. Also
-  removed `[auto_media_port]`. There are way too many (conflicting)
-  options to specify ports here.
-* URL encode/decode `<action>` for scenarios (by Jérôme Poulin).
-* Variables in the rtpstream/pcap filenames (by Orgad Shaneh).
-* WolfSSL/WolfCrypt library support (as alternative to OpenSSL, by
+- URL encode/decode `<action>` for scenarios (by Jérôme Poulin).
+- Variables in the rtpstream/pcap filenames (by Orgad Shaneh).
+- WolfSSL/WolfCrypt library support (as alternative to OpenSSL, by
   Thomas Uhle).
 
+### Removed
+
+- Removed `-mp` in favor of `-min_rtp_port` and `-max_rtp_port`. Also
+  removed `[auto_media_port]`. There are way too many (conflicting)
+  options to specify ports here.
 
-Bugs fixed in 3.7.0~rc1
-=======================
+### Fixed
 
-* Documentation updates. Code cleanups. Build fixes. (By Walter Doekes,
+- Documentation updates. Code cleanups. Build fixes. (By Walter Doekes,
   Thomas Uhle, ChanderG, Lin Sun, Markus Goetzl, Rob Day, Stefan
   Mititelu, Orgad Shaneh, Karn Saheb).
-* Fix socket/tcp refcount/order issue (by Orgad Shaneh).
-* Fix timezone in [date] on FreeBSD (by kadabusha).
-* Track auto-answered messages as a visible counter rather than an error
+- Fix socket/tcp refcount/order issue (by Orgad Shaneh).
+- Fix timezone in [date] on FreeBSD (by kadabusha).
+- Track auto-answered messages as a visible counter rather than an error
   log (by Rob Day).
-* Unconditionally show index in scenario screen (by Rob Day).
+- Unconditionally show index in scenario screen (by Rob Day).
+
+## [3.6.2-rc1] - 2021-10-25
 
+### Removed
 
-Bugs fixed in 3.6.2
-===================
+- Remove RTP\_STREAM define. The code is always included. (By Orgad Shaneh.)
 
-* Fix crash when abusing authentication method (#503, by Markus).
-* Fix crash when trying to change an unset ooc scenario (#463, by
+### Fixed
+
+- Fix crash when abusing authentication method (#503, by Markus).
+- Fix crash when trying to change an unset ooc scenario (#463, by
   @jquinn60137).
-* Fix various build issues with CMake and/or missing version.h and/or
+- Fix various build issues with CMake and/or missing version.h and/or
   compiler warnings. By Walter Doekes, by Silver Chan, Thomas Uhle,
   Orgad Shaneh.
-* Remove RTP\_STREAM define. The code is always included. (By Orgad Shaneh.)
-* Various minor documentation fixes. By Walter Doekes, kadabusha, Thomas
+- Various minor documentation fixes. By Walter Doekes, kadabusha, Thomas
   Uhle, Alexander Traud.
 
+## [3.6.1] - 2020-09-16
 
-BREAKING(!) changes in 3.6.1
-============================
+### Changed
 
-* CMake is now used as build environment: autoconf and friends are gone
+- **Breaking:** CMake is now used as build environment: autoconf and friends 
are gone
   (#430, by Rob Day (@rkday)). See `build.sh` for CMake invocations.
   For a full build, do:
     ```
     cmake . -DUSE_GSL=1 -DUSE_PCAP=1 -DUSE_SSL=1 -DUSE_SCTP=1
     make -j4
     ```
+- Make it easier to deal with large SIP packets by adding an optional
+  `-DSIPP_MAX_MSG_SIZE=262144` to the `cmake` command (#422, by Cody Herzog
+  (@codyherzog)).
 
+### Fixed
 
-Bugs fixed in 3.6.1
-===================
-
-* Consistently unescape XML attributes when loading scenario (#458, by
+- Consistently unescape XML attributes when loading scenario (#458, by
   Steve Frécinaux (@nud)).
-* Fix buffer overflow in screen output (#479, reported by @brettowe).
-* Fix nonce count in auth headers (#421, by Cody Herzog (@codyherzog)).
-* Fix parser warning when trying to access 0-byte SDP body (by Lin Sun
+- Fix buffer overflow in screen output (#479, reported by @brettowe).
+- Fix nonce count in auth headers (#421, by Cody Herzog (@codyherzog)).
+- Fix parser warning when trying to access 0-byte SDP body (by Lin Sun
   (@sunlin7)).
-* Fix pcapplay on FreeBSD (#434, by Rob Day (@rkday)).
-* Improve build validation (#424, by Stanislav Litvinenko (@dolk13)), a
+- Fix pcapplay on FreeBSD (#434, by Rob Day (@rkday)).
+- Improve build validation (#424, by Stanislav Litvinenko (@dolk13)), a
   few compiler fixes, a few ncurses fixes (including #436, reported by
   @TamerL), build cleanup after CMake (#443, #442, by Orgad Shaneh
   (@orgads)) and libtinfo linker issues (Jeannot Langlois
   (@jeannotlanglois)).
-* Improve provided sipp.dtd file (#425, by David M. Lee (@leedm777)),
+- Improve provided sipp.dtd file (#425, by David M. Lee (@leedm777)),
   and XML fixes by Rob Day.
-* Make it easier to deal with large SIP packets by adding an optional
-  `-DSIPP_MAX_MSG_SIZE=262144` to the `cmake` command (#422, by Cody Herzog
-  (@codyherzog)).
-
-
-BREAKING(!) changes in 3.6.0
-============================
-
-* Automatic filenames (trace files, error files, etc..) are now created in
-  the current working directory instead of in the directory of the scenario
-  file. (Issue #399, reported by @sergey-safarov.)
-* Only validates SSL certificate if CA-file is separately specified!
-  (PR #335, by Patrick Wildt @bluerise.)
-* Angle brackets `<` and `>` need to be escaped inside XML attributes.
-  See #414. So, not `regexp="<(sip:.*)>"` but `regexp="&lt;(sip:.*)&gt;"`.
-
-
-Bugs fixed in 3.6.0
-===================
-
-* Fix `[routes]` header in UAS scenario's. (Issue #262, reported by
-  Stefan Mititelu (@smititelu).)
-* last\_Keyword does not search in SIP body anymore (#207, reported by Zoltan).
 
+## [3.6.0] - 2019-06-18
 
-Changes in 3.6.0
-================
+### Added
 
-* Added PAGER by default to the extremely large sipp help output.
-* Removed unused RTPStream code concerning video streams. Also
-  consolidated the rtpstream audio port usage to reuse the global
-  `[media_port]` instead of the `[rtpstream_audio_port]`.
-  Also the `-min_rtp_port` and `-max_rtp_port` options have been
-  removed. Advantages: cleaner code, fewer scenario variables.
-  Drawbacks: possible ICMP port unreachable messages for RCTP and video.
-  Also, no easy way to discern different streams if you want to bombard
-  a single UAS with multiple RTP streams. (Issue #192, reported by
-  @atsakiridis.)
-
-
-Features added in 3.6.0
-=======================
-
-* Add `play_dtmf` code originally from
+- Add `play_dtmf` code originally from
   https://sourceforge.net/p/sipp/patches/50/ (Dmitry Kunilov), then
   pull #82 (@horacimacias) and then #141 (@vodik). Compile with
   pcap-play support, and use it by adding `<exec play_dtmf="1234*#"/>`
@@ -217,94 +327,119 @@
     and must be between 50 and 2000.
   - Instead of digits a `[field...]` keyword is also accepted.
   - Make sure you add enough `<pause/>` after `play_dtmf`.
-* Add `rtp_echo` action (pull #259 by Snom Technology). Compile with
+- Add `rtp_echo` action (pull #259 by Snom Technology). Compile with
   `--with-rtpstream` and use it by adding `<rtp_echo value="0">` to stop
   the RTP echo enabled via `-rtp_echo`. RTP echo can be restarted via
   `<rtp_echo value="1">` action. Usage example in 
`regress/github-#0259/uas.xml`
-* Added the required constants for G722 (payload 9) and iLBC at 30ms per frame
+- Added the required constants for G722 (payload 9) and iLBC at 30ms per frame
   to rtp\_stream media actions. (PR #366, by Jasper Hafkenscheid @hafkensite.)
-* Add quick and dirty detection of invalid XML (issue #322).
-* Clarify that `-infindex` should takes a basename only (issue #395, reported
+- Add quick and dirty detection of invalid XML (issue #322).
+- Added PAGER by default to the extremely large sipp help output.
+
+### Changed
+
+- **Breaking:** Automatic filenames (trace files, error files, etc..) are now 
created in
+  the current working directory instead of in the directory of the scenario
+  file. (Issue #399, reported by @sergey-safarov.)
+- **Breaking:** Only validates SSL certificate if CA-file is separately 
specified!
+  (PR #335, by Patrick Wildt @bluerise.)
+- **Breaking:** Angle brackets `<` and `>` need to be escaped inside XML 
attributes.
+  See #414. So, not `regexp="<(sip:.*)>"` but `regexp="&lt;(sip:.*)&gt;"`.
+- Clarify that `-infindex` should takes a basename only (issue #395, reported
   by @sergey-safarov).
 
+### Removed
 
-Bugs fixed in 3.5.3
-===================
+- Removed unused RTPStream code concerning video streams. Also
+  consolidated the rtpstream audio port usage to reuse the global
+  `[media_port]` instead of the `[rtpstream_audio_port]`.
+  Also the `-min_rtp_port` and `-max_rtp_port` options have been
+  removed. Advantages: cleaner code, fewer scenario variables.
+  Drawbacks: possible ICMP port unreachable messages for RCTP and video.
+  Also, no easy way to discern different streams if you want to bombard
+  a single UAS with multiple RTP streams. (Issue #192, reported by
+  @atsakiridis.)
 
-* Fix `[routes]` header in UAS scenario's. (Issue #262, reported by
+### Fixed
+
+- Fix `[routes]` header in UAS scenario's. (Issue #262, reported by
+  Stefan Mititelu (@smititelu).)
+- last\_Keyword does not search in SIP body anymore (#207, reported by Zoltan).
+
+## [3.5.3] - 2019-06-18
+
+### Fixed
+
+- Fix `[routes]` header in UAS scenario's. (Issue #262, reported by
   Stefan Mititelu (@smititelu).)
   (Backported from b6c7b209 from 3.6.)
-* Fix bad Content-Length calculation when whitespace was between the CRLF
+- Fix bad Content-Length calculation when whitespace was between the CRLF
   pairs that separate the body. (Issue #337, fixed by Serg Stetsuk
   (@sergstetsuk)).
-* Fix crash in pcap play on send failure because of pthread\_cleanup macros.
+- Fix crash in pcap play on send failure because of pthread\_cleanup macros.
   (Issue #74, #370, reported by various people.)
 
+## [3.5.2] - 2018-07-13
 
-Bugs fixed in 3.5.2
-===================
-
-Build issues:
+### Changed
 
-* Improve ncurses/gsl detection and linkage on various platforms.
-  (Issue #205, #271, #275, reported by Paul Malpass, AlexB, Leon Roy,
-  Victor Seva.)
-* Fix compile issues on old CentOS and Solaris. (Issue #211, #245, #252,
-  reported by sjthomason, mscdex.)
-* Fix newer openssl detection. (Issue #302, #304, #315, #328.)
-* Recompile entire source after a reconfigure.
-* Reduce confusion when someone downloads a tag from git instead of the tar.gz
-  with the autogenerated files and valid version.h (#270, reported by AlexB).
-* Remove hardcoded build datetime from binary, for "reproducible builds".
-  (#286, by Victor Seva.)
-* Replace underscore in tag-name with tilde, for debian-style "~rc1" version
-  suffix.
+- Document `search_in="hdr"` test.
+- Also test without `HAVE_EPOLL`.
 
-Bugs:
+### Fixed
 
-* Handle Contact header with extra angle brackets ('<...>') outside of the
+- Build issues:
+  - Improve ncurses/gsl detection and linkage on various platforms.
+    (Issue #205, #271, #275, reported by Paul Malpass, AlexB, Leon Roy,
+    Victor Seva.)
+  - Fix compile issues on old CentOS and Solaris. (Issue #211, #245, #252,
+    reported by sjthomason, mscdex.)
+  - Fix newer openssl detection. (Issue #302, #304, #315, #328.)
+  - Recompile entire source after a reconfigure.
+  - Reduce confusion when someone downloads a tag from git instead of the 
tar.gz
+    with the autogenerated files and valid version.h (#270, reported by AlexB).
+  - Remove hardcoded build datetime from binary, for "reproducible builds".
+    (#286, by Victor Seva.)
+  - Replace underscore in tag-name with tilde, for debian-style "~rc1" version
+    suffix.
+- Handle Contact header with extra angle brackets ('<...>') outside of the
   uri-parameters (in the contact-params). The contact params should not be
   used in the `next_url`. (Issue #234, reported by Justin Zimmer.)
-* Fix TLS issues for during high load. (Issue #241, #243, reported by sgel83,
+- Fix TLS issues for during high load. (Issue #241, #243, reported by sgel83,
   and fixes by Rob Day.)
-* Fix problem with `get_inet_address` on FreeBSD (#331, reported by tsgan.)
-* Retry video RTP bind if port is taken (#276, thanks Corey Farrell).
+- Fix problem with `get_inet_address` on FreeBSD (#331, reported by tsgan.)
+- Retry video RTP bind if port is taken (#276, thanks Corey Farrell).
 
-Tests:
+## [3.5.1] - 2016-03-17
 
-* Document `search_in="hdr"` test.
-* Also test without `HAVE_EPOLL`.
+### Fixed
 
-
-Bugs fixed in 3.5.1
-===================
-
-* Fix qop-value in authorization Digest. It can only hold a single value
+- Fix qop-value in authorization Digest. It can only hold a single value
   (auth, auth-int, ...) and does not take double quotes, in contrast to
   the challenge. Some servers returned a 400 upon receiving this.
   (Issue #191, reported by @artlov.)
-* Fix compile error on Cygwin. (Issue #193, reported by @Gankarloo.)
+- Fix compile error on Cygwin. (Issue #193, reported by @Gankarloo.)
 
+## [3.5.0] - 2016-02-08
 
-Features added in 3.5.0
-=======================
+### Added
 
-* Clean up source code, fix typo's, alter warning and error messages,
+- Clean up source code, fix typo's, alter warning and error messages,
   fix pedantic coding style. Add gtest framework and tests. Add regression
   tests. Fix and improve build scripts (see also: `build.sh`).
-* Use better timing with `clock_gettime` (or `clock_get_time` on OSX).
-* Don't complain about the dummy variable `_` being used only once.
-* Ignore 4x NUL keepalive (next to ignoring the CRLF CRLF keepalive).
-* Add `[date]` keyword.
-* Add `-trace_screen` option to log screen output in a file.
-* Add `-rate_increase` option to increase load periodically.
-* Add `-callid_slash_ign` to disable the magic triple slash behaviour.a
-* Alter `-aa` to also reply to OPTIONS.
-* Allow replaying pcaps with `LINUX_SLL`, `EN10MB` and 802.11 (and ratiotap)
+- Use better timing with `clock_gettime` (or `clock_get_time` on OSX).
+- Don't complain about the dummy variable `_` being used only once.
+- Ignore 4x NUL keepalive (next to ignoring the CRLF CRLF keepalive).
+- Add `[date]` keyword.
+- Add `-trace_screen` option to log screen output in a file.
+- Add `-rate_increase` option to increase load periodically.
+- Add `-callid_slash_ign` to disable the magic triple slash behaviour.a
+- Alter `-aa` to also reply to OPTIONS.
+- Allow replaying pcaps with `LINUX_SLL`, `EN10MB` and 802.11 (and ratiotap)
   link layer types. Handle 802.1Q tagged frames.
-* Allow starting SIPp without a TERM setting (a "working" terminal).
-* Allow m=image in SDP to pcapplay faxes/images.
-* `<exec play_pcap_audio="..."/>` and friends:
+- Allow starting SIPp without a TERM setting (a "working" terminal).
+- Allow m=image in SDP to pcapplay faxes/images.
+- `<exec play_pcap_audio="..."/>` and friends:
   - If the argument is not an absolute path, the pcap is searched next
     to the scenario, before falling back to checking the current
     working directory.
@@ -313,22 +448,38 @@
     option. Example: `<exec play_pcap_audio="[file1]"/>` with option
     `-key file1 /path/to/pcap`.
 
+### Fixed
 
-Bugs fixed in 3.5.0
-===================
-
-* Start SDP search in body instead of in header. Fix IPv6 media address in SDP.
-* Allow single CR and single LF in SDP.
-* Don't confuse cnonce with nonce, improve other auth parsing.
-* Don't abort SIPp if the To header is missing.
-* Fixes to XML parser; improve `get_peer_tag` behaviour.
-* Fix jump recursion crashes.
-* Fix a few (potential) memory leaks and dangerous code.
-* Remove a few autogenerated files from tree (configure, manpage).
-* Fix digest calculation when `qop` is given.
-
-
-3.4.1
-=====
-
-* Not documented here.
+- Start SDP search in body instead of in header. Fix IPv6 media address in SDP.
+- Allow single CR and single LF in SDP.
+- Don't confuse cnonce with nonce, improve other auth parsing.
+- Don't abort SIPp if the To header is missing.
+- Fixes to XML parser; improve `get_peer_tag` behaviour.
+- Fix jump recursion crashes.
+- Fix a few (potential) memory leaks and dangerous code.
+- Remove a few autogenerated files from tree (configure, manpage).
+- Fix digest calculation when `qop` is given.
+
+## [3.4.1] - 2014-03-09
+
+Not documented here.
+
+[3.7.9]: https://github.com/SIPp/sipp/releases/tag/v3.7.9
+[3.7.8]: https://github.com/SIPp/sipp/releases/tag/v3.7.8
+[3.7.7]: https://github.com/SIPp/sipp/releases/tag/v3.7.7
+[3.7.6]: https://github.com/SIPp/sipp/releases/tag/v3.7.6
+[3.7.5]: https://github.com/SIPp/sipp/releases/tag/v3.7.5
+[3.7.4]: https://github.com/SIPp/sipp/releases/tag/v3.7.4
+[3.7.3]: https://github.com/SIPp/sipp/releases/tag/v3.7.3
+[3.7.2]: https://github.com/SIPp/sipp/releases/tag/v3.7.2
+[3.7.1]: https://github.com/SIPp/sipp/releases/tag/v3.7.1
+[3.7.0]: https://github.com/SIPp/sipp/releases/tag/v3.7.0
+[3.7.0-rc1]: https://github.com/SIPp/sipp/releases/tag/v3.7.0_rc1
+[3.6.2-rc1]: https://github.com/SIPp/sipp/releases/tag/v3.6.2_rc1
+[3.6.1]: https://github.com/SIPp/sipp/releases/tag/v3.6.1
+[3.6.0]: https://github.com/SIPp/sipp/releases/tag/v3.6.0
+[3.5.3]: https://github.com/SIPp/sipp/releases/tag/v3.5.3
+[3.5.2]: https://github.com/SIPp/sipp/releases/tag/v3.5.2
+[3.5.1]: https://github.com/SIPp/sipp/releases/tag/v3.5.1
+[3.5.0]: https://github.com/SIPp/sipp/releases/tag/v3.5.0
+[3.4.1]: https://github.com/SIPp/sipp/releases/tag/v3.4.1
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/CMakeLists.txt 
new/sipp-3.7.9/CMakeLists.txt
--- old/sipp-3.7.8/CMakeLists.txt       2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/CMakeLists.txt       2026-09-30 09:12:47.000000000 +0200
@@ -44,6 +44,24 @@
   endif()
 endfunction()
 
+# A three-way cache option: AUTO, ON or OFF. ON and OFF may be given in any
+# spelling CMake takes for a boolean (1, TRUE, YES, 0, FALSE, NO, ...), as
+# packagers often pass -DOPTION=1. Sets <VAR>_MODE to AUTO, ON or OFF.
+function(tristate_option VAR DESCRIPTION)
+  set(${VAR} "AUTO" CACHE STRING "${DESCRIPTION}")
+  set_property(CACHE ${VAR} PROPERTY STRINGS AUTO ON OFF)
+  string(TOUPPER "${${VAR}}" value)
+  if(value STREQUAL "AUTO")
+    set(${VAR}_MODE AUTO PARENT_SCOPE)
+  elseif(value MATCHES "^(ON|1|TRUE|YES|Y)$")
+    set(${VAR}_MODE ON PARENT_SCOPE)
+  elseif(value MATCHES "^(OFF|0|FALSE|NO|N)$")
+    set(${VAR}_MODE OFF PARENT_SCOPE)
+  else()
+    message(FATAL_ERROR "${VAR} must be AUTO, ON or OFF, not '${${VAR}}'")
+  endif()
+endfunction()
+
 function(add_sipp_target TARGET_NAME)
   cmake_parse_arguments(SIPP "EXCLUDE_FROM_ALL" "" 
"SOURCES;EXTRA_LIBRARIES;EXTRA_INCLUDES;COMPILE_DEFINITIONS" ${ARGN})
 
@@ -132,25 +150,30 @@
 
 find_package(PkgConfig QUIET)  # import pkg_check_modules() and friends
 
-set(USE_SYSTEM_PUGIXML "AUTO" CACHE STRING "Use system pugixml: AUTO, ON, or 
OFF")
-if(USE_SYSTEM_PUGIXML STREQUAL "AUTO" AND EXISTS 
${PROJECT_SOURCE_DIR}/third_party/pugixml/CMakeLists.txt)
+# AUTO takes the bundled copy if its submodule is there, else the system one.
+tristate_option(USE_SYSTEM_PUGIXML "Use system pugixml: AUTO, ON, or OFF")
+set(BUNDLED_PUGIXML ${PROJECT_SOURCE_DIR}/third_party/pugixml)
+if(USE_SYSTEM_PUGIXML_MODE STREQUAL "OFF" OR
+        (USE_SYSTEM_PUGIXML_MODE STREQUAL "AUTO" AND EXISTS 
${BUNDLED_PUGIXML}/CMakeLists.txt))
+    if(NOT EXISTS ${BUNDLED_PUGIXML}/CMakeLists.txt)
+        message(FATAL_ERROR "USE_SYSTEM_PUGIXML is OFF, but the bundled 
pugixml is missing: run 'git submodule update --init'")
+    endif()
     message(STATUS "Using bundled pugixml")
-    set(PUGIXML_SOURCES 
${PROJECT_SOURCE_DIR}/third_party/pugixml/src/pugixml.cpp)
-    include_directories(${PROJECT_SOURCE_DIR}/third_party/pugixml/src)
+    set(PUGIXML_SOURCES ${BUNDLED_PUGIXML}/src/pugixml.cpp)
+    include_directories(${BUNDLED_PUGIXML}/src)
     set(PUGIXML_LIBRARIES "")
-    set(PUGIXML_FOUND TRUE)
-elseif(USE_SYSTEM_PUGIXML STREQUAL "AUTO" OR USE_SYSTEM_PUGIXML STREQUAL "ON")
+else()
     pkg_check_modules(PUGIXML pugixml)
     if(PUGIXML_FOUND)
         message(STATUS "Using system pugixml")
         include_directories(SYSTEM ${PUGIXML_INCLUDE_DIRS})
+    elseif(USE_SYSTEM_PUGIXML_MODE STREQUAL "ON")
+        message(FATAL_ERROR "USE_SYSTEM_PUGIXML is ON, but pkg-config cannot 
find pugixml: install its development package")
+    else()
+        message(FATAL_ERROR "pugixml is required. Either install the library 
or run 'git submodule update --init'")
     endif()
 endif()
 
-if(NOT PUGIXML_FOUND)
-    message(FATAL_ERROR "pugixml is required. Either install the library or 
run 'git submodule update --init'")
-endif()
-
 if(USE_WOLFSSL)
     pkg_search_module(SSL REQUIRED wolfssl>=3.15.0)
     if(TLS_KEY_LOGGING)
@@ -280,22 +303,27 @@
 )
 target_compile_features(sipp PUBLIC cxx_auto_type cxx_range_for)
 
-set(USE_SYSTEM_GTEST "AUTO" CACHE STRING "Use system GTest: AUTO, ON, or OFF")
-
-if(USE_SYSTEM_GTEST STREQUAL "AUTO" AND EXISTS 
${PROJECT_SOURCE_DIR}/gtest/googletest)
+# AUTO takes the bundled copy if its submodule is there, else the system one,
+# and builds no unit tests if there is neither.
+tristate_option(USE_SYSTEM_GTEST "Use system GTest: AUTO, ON, or OFF")
+set(BUNDLED_GTEST ${PROJECT_SOURCE_DIR}/gtest/googletest)
+if(USE_SYSTEM_GTEST_MODE STREQUAL "OFF" OR
+        (USE_SYSTEM_GTEST_MODE STREQUAL "AUTO" AND EXISTS ${BUNDLED_GTEST}))
+  if(NOT EXISTS ${BUNDLED_GTEST})
+    message(FATAL_ERROR "USE_SYSTEM_GTEST is OFF, but the bundled GTest is 
missing: run 'git submodule update --init'")
+  endif()
   message(STATUS "Using bundled GTest")
   include(GoogleTest)
   add_sipp_target(sipp_unittest
     EXCLUDE_FROM_ALL
     SOURCES "${PROJECT_SOURCE_DIR}/src/sipp_unittest.cpp" ${PUGIXML_SOURCES}
-            "${PROJECT_SOURCE_DIR}/gtest/googletest/src/gtest-all.cc"
+            "${BUNDLED_GTEST}/src/gtest-all.cc"
     COMPILE_DEFINITIONS "-DGTEST"
-    EXTRA_INCLUDES ${PROJECT_SOURCE_DIR}/gtest/googletest
-                   ${PROJECT_SOURCE_DIR}/gtest/googletest/include
+    EXTRA_INCLUDES ${BUNDLED_GTEST}
+                   ${BUNDLED_GTEST}/include
   )
   gtest_discover_tests(sipp_unittest TEST_PREFIX sipp_unittests:)
-elseif(USE_SYSTEM_GTEST STREQUAL "AUTO" OR USE_SYSTEM_GTEST STREQUAL "ON")
-  # Try system
+else()
   find_package(GTest QUIET)
   if(GTest_FOUND)
     message(STATUS "Using system GTest")
@@ -307,6 +335,8 @@
     )
     target_link_libraries(sipp_unittest GTest::gtest GTest::gtest_main)
     gtest_discover_tests(sipp_unittest TEST_PREFIX sipp_unittests:)
+  elseif(USE_SYSTEM_GTEST_MODE STREQUAL "ON")
+    message(FATAL_ERROR "USE_SYSTEM_GTEST is ON, but GTest was not found: 
install its development package")
   else()
     message(WARNING "GTest not found. Run 'git submodule update --init' or 
install libgtest-dev")
   endif()
@@ -331,7 +361,9 @@
       -P ${PROJECT_SOURCE_DIR}/include/version.cmake
   )
   add_dependencies(sipp version)
-  add_dependencies(sipp_unittest version)
+  if(TARGET sipp_unittest)
+    add_dependencies(sipp_unittest version)
+  endif()
 endif()
 
 if(CMAKE_SYSTEM_NAME STREQUAL "Linux" AND NOT TINFO_LIBRARY)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/docs/installation.rst 
new/sipp-3.7.9/docs/installation.rst
--- old/sipp-3.7.8/docs/installation.rst        2026-09-23 22:35:51.000000000 
+0200
+++ new/sipp-3.7.9/docs/installation.rst        2026-09-30 09:12:47.000000000 
+0200
@@ -64,6 +64,7 @@
     + C++ Compiler
     + curses or ncurses library
     + OpenSSL >= 1.1.1 or WolfSSL >= 3.15.0
+    + `pugixml`_: bundled as a git submodule, or the system library
     + For pcap play support: libpcap and libnet
     + For SCTP support: lksctp-tools
     + For distributed pauses: `Gnu Scientific Libraries`_
@@ -98,6 +99,22 @@
         cmake . -DUSE_GSL=1 -DUSE_PCAP=1 -DUSE_SCTP=1
         make
 
++ pugixml, and GoogleTest for the unit tests, come as git submodules
+  (``git submodule update --init``). ``-DUSE_SYSTEM_PUGIXML`` and
+  ``-DUSE_SYSTEM_GTEST`` choose between them and the system libraries:
+
+    + ``AUTO`` (the default): the submodule if it is checked out, else
+      the system library;
+    + ``ON`` (or ``1``, ``TRUE``, ``YES``): the system library, which
+      must be installed;
+    + ``OFF`` (or ``0``, ``FALSE``, ``NO``): the submodule, which must
+      be checked out.
+
+  For example, to build against the system libraries, as distribution
+  packages do::
+
+        cmake . -DUSE_SYSTEM_PUGIXML=ON -DUSE_SYSTEM_GTEST=ON
+
 
 .. warning::
   SIPp compiles under CYGWIN on Windows, provided that you
@@ -114,6 +131,7 @@
 
 .. _GNU GPL license: https://www.gnu.org/copyleft/gpl.html
 .. _Gnu Scientific Libraries: https://www.gnu.org/software/gsl/
+.. _pugixml: https://pugixml.org/
 .. _WinPcap developer package: https://www.winpcap.org/devel.htm
 .. _hewlett-packard: https://www.hp.com/
 .. _SIPp's master tree: https://github.com/SIPp/sipp/tree/master
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/include/version.h 
new/sipp-3.7.9/include/version.h
--- old/sipp-3.7.8/include/version.h    2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/include/version.h    2026-09-30 09:12:47.000000000 +0200
@@ -1,2 +1,2 @@
 #define SIPP_VERSION VERSION
-#define VERSION "v3.7.8"
+#define VERSION "v3.7.9"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/include/xp_parser.h 
new/sipp-3.7.9/include/xp_parser.h
--- old/sipp-3.7.8/include/xp_parser.h  2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/include/xp_parser.h  2026-09-30 09:12:47.000000000 +0200
@@ -22,7 +22,6 @@
 #ifndef __XP_PARSER_H__
 #define __XP_PARSER_H__
 
-int xp_unescape(const char *source, char *dest);
 int xp_set_xml_buffer_from_string(const char *str);
 int xp_set_xml_buffer_from_file(const char *filename);
 char* xp_open_element(int index);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/regress/github-#1062/run 
new/sipp-3.7.9/regress/github-#1062/run
--- old/sipp-3.7.8/regress/github-#1062/run     1970-01-01 01:00:00.000000000 
+0100
+++ new/sipp-3.7.9/regress/github-#1062/run     2026-09-30 09:12:47.000000000 
+0200
@@ -0,0 +1,21 @@
+#!/bin/sh
+# This regression test is a part of SIPp.
+# An attribute's XML entities are decoded once: "&amp;lt;" is the text
+# "&lt;", not "<".
+. "`dirname "$0"`/../functions"; init
+
+rm -f uac_*_logs.log
+sippfg -sf uac.xml -i 127.0.0.1 -p 24320 -m 1 -timeout 10 \
+    127.0.0.1:24321 -trace_logs >/dev/null 2>&1
+status=$?
+logs=`cat uac_*_logs.log 2>/dev/null`
+rm -f uac_*_logs.log
+
+expected='lit=&lt; &amp; < &lt;&quot;'
+if test $status -ne 0; then
+    fail "the scenario failed with $status"
+elif test "$logs" != "$expected"; then
+    fail "logged '$logs', not '$expected'"
+else
+    ok
+fi
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/regress/github-#1062/uac.xml 
new/sipp-3.7.9/regress/github-#1062/uac.xml
--- old/sipp-3.7.8/regress/github-#1062/uac.xml 1970-01-01 01:00:00.000000000 
+0100
+++ new/sipp-3.7.9/regress/github-#1062/uac.xml 2026-09-30 09:12:47.000000000 
+0200
@@ -0,0 +1,23 @@
+<?xml version="1.0" encoding="ISO-8859-1" ?>
+<!DOCTYPE scenario SYSTEM "sipp.dtd">
+<!-- An attribute's XML entities are decoded once. -->
+<scenario name="xml entities">
+  <send>
+    <![CDATA[
+      MESSAGE sip:[service]@[remote_ip]:[remote_port] SIP/2.0
+      Via: SIP/2.0/[transport] [local_ip]:[local_port];branch=[branch]
+      From: <sip:c@[local_ip]:[local_port]>;tag=[call_number]
+      To: <sip:[service]@[remote_ip]:[remote_port]>
+      Call-ID: [call_id]
+      CSeq: 1 MESSAGE
+      Content-Length: 0
+
+    ]]>
+  </send>
+  <nop>
+    <action>
+      <assignstr assign_to="s" value="&amp;lt;&amp;quot;"/>
+      <log message="lit=&amp;lt; &amp;amp; &lt; [$s]"/>
+    </action>
+  </nop>
+</scenario>
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/sipp.1 new/sipp-3.7.9/sipp.1
--- old/sipp-3.7.8/sipp.1       2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/sipp.1       2026-09-30 09:12:47.000000000 +0200
@@ -645,7 +645,7 @@
 .HP
 \fB\-2\fR: Fatal error binding a socket
 .IP
-SIPp v3.7.8\-TLS\-PCAP\-SHA256.
+SIPp v3.7.9\-TLS\-PCAP\-SHA256.
 .IP
 This program is free software; you can redistribute it and/or
 modify it under the terms of the GNU General Public License as
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/sipp.dtd new/sipp-3.7.9/sipp.dtd
--- old/sipp-3.7.8/sipp.dtd     2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/sipp.dtd     2026-09-30 09:12:47.000000000 +0200
@@ -71,13 +71,37 @@
 
 <!-- BEGIN actions -->
 
+<!-- the right-hand side of an arithmetic action: one of value or variable -->
+<!ENTITY % rhs '
+  value CDATA #IMPLIED
+  variable CDATA #IMPLIED
+  '>
+
+<!-- string and numeric comparisons: assign_to may be left out when
+     check_it or check_it_inverse is set; one of value or variable2 -->
+<!ENTITY % comparison '
+  assign_to CDATA #IMPLIED
+  variable CDATA #REQUIRED
+  value CDATA #IMPLIED
+  variable2 CDATA #IMPLIED
+  check_it (true|false) #IMPLIED
+  check_it_inverse (true|false) #IMPLIED
+  '>
+
 <!ELEMENT ereg EMPTY >
 <!ATTLIST ereg assign_to CDATA #REQUIRED >
 <!ATTLIST ereg check_it (true|false) "false" >
-<!ATTLIST ereg header NMTOKEN #IMPLIED >
+<!ATTLIST ereg check_it_inverse (true|false) #IMPLIED >
+<!ATTLIST ereg case_indep (true|false) #IMPLIED >
+<!ATTLIST ereg header CDATA #IMPLIED >
+<!ATTLIST ereg occurrence CDATA #IMPLIED >
+<!-- old misspelling of occurrence -->
+<!ATTLIST ereg occurence CDATA #IMPLIED >
 <!ATTLIST ereg regexp CDATA #REQUIRED >
-<!ATTLIST ereg search_in (msg|hdr) "msg" >
+<!ATTLIST ereg search_in (msg|body|hdr|var) "msg" >
 <!ATTLIST ereg start_line (true|false) #IMPLIED >
+<!-- the variable to search when search_in="var" -->
+<!ATTLIST ereg variable CDATA #IMPLIED >
 
 <!ELEMENT log EMPTY >
 <!ATTLIST log message CDATA #REQUIRED >
@@ -85,32 +109,87 @@
 <!ELEMENT warning EMPTY >
 <!ATTLIST warning message CDATA #REQUIRED >
 
+<!ELEMENT error EMPTY >
+<!ATTLIST error message CDATA #REQUIRED >
+
 <!ELEMENT exec EMPTY >
-<!-- one of command or int_cmd must be present -->
+<!-- exactly one of these must be present -->
 <!ATTLIST exec command CDATA #IMPLIED >
 <!ATTLIST exec int_cmd (stop_now|stop_gracefully|stop_call) "stop_call" >
-<!ATTLIST exec play_pcap CDATA #IMPLIED >
 <!ATTLIST exec play_pcap_audio CDATA #IMPLIED >
+<!ATTLIST exec play_pcap_image CDATA #IMPLIED >
+<!ATTLIST exec play_pcap_video CDATA #IMPLIED >
+<!ATTLIST exec play_dtmf CDATA #IMPLIED >
 <!ATTLIST exec rtp_stream CDATA #IMPLIED >
 <!ATTLIST exec rtp_echo CDATA #IMPLIED >
 
 <!ELEMENT rtp_echo EMPTY >
-<!ATTLIST rtp_echo value CDATA #REQUIRED >
+<!ATTLIST rtp_echo %rhs; >
 
 <!ELEMENT strcmp EMPTY >
-<!ATTLIST strcmp assign_to CDATA #REQUIRED >
-<!ATTLIST strcmp value CDATA #REQUIRED >
-<!ATTLIST strcmp variable CDATA #REQUIRED >
+<!ATTLIST strcmp %comparison; >
 
 <!ELEMENT test EMPTY >
-<!ATTLIST test assign_to CDATA #REQUIRED >
-<!ATTLIST test compare CDATA #REQUIRED >
-<!ATTLIST test value CDATA #REQUIRED >
-<!ATTLIST test variable CDATA #REQUIRED >
+<!ATTLIST test %comparison; >
+<!ATTLIST test compare 
(equal|not_equal|greater_than|less_than|greater_than_equal|less_than_equal) 
#REQUIRED >
 
 <!ELEMENT assign EMPTY >
-<!ATTLIST assign assign_to CDATA #REQUIRED >
-<!ATTLIST assign variable CDATA #REQUIRED >
+<!ATTLIST assign assign_to CDATA #REQUIRED %rhs; >
+
+<!ELEMENT add EMPTY >
+<!ATTLIST add assign_to CDATA #REQUIRED %rhs; >
+
+<!ELEMENT subtract EMPTY >
+<!ATTLIST subtract assign_to CDATA #REQUIRED %rhs; >
+
+<!ELEMENT multiply EMPTY >
+<!ATTLIST multiply assign_to CDATA #REQUIRED %rhs; >
+
+<!ELEMENT divide EMPTY >
+<!ATTLIST divide assign_to CDATA #REQUIRED %rhs; >
+
+<!ELEMENT jump EMPTY >
+<!ATTLIST jump %rhs; >
+
+<!ELEMENT pauserestore EMPTY >
+<!ATTLIST pauserestore %rhs; >
+
+<!ELEMENT assignstr EMPTY >
+<!ATTLIST assignstr assign_to CDATA #REQUIRED >
+<!ATTLIST assignstr value CDATA #REQUIRED >
+
+<!ELEMENT todouble EMPTY >
+<!ATTLIST todouble assign_to CDATA #REQUIRED >
+<!ATTLIST todouble variable CDATA #REQUIRED >
+
+<!ELEMENT sample EMPTY >
+<!ATTLIST sample assign_to CDATA #REQUIRED >
+<!ATTLIST sample distribution 
(fixed|uniform|normal|lognormal|exponential|weibull|pareto|gpareto|gamma|negbin)
 #REQUIRED >
+<!-- the parameters of the chosen distribution -->
+<!ATTLIST sample value CDATA #IMPLIED >
+<!ATTLIST sample min CDATA #IMPLIED >
+<!ATTLIST sample max CDATA #IMPLIED >
+<!ATTLIST sample mean CDATA #IMPLIED >
+<!ATTLIST sample stdev CDATA #IMPLIED >
+<!ATTLIST sample lambda CDATA #IMPLIED >
+<!ATTLIST sample k CDATA #IMPLIED >
+<!ATTLIST sample x_m CDATA #IMPLIED >
+<!ATTLIST sample shape CDATA #IMPLIED >
+<!ATTLIST sample scale CDATA #IMPLIED >
+<!ATTLIST sample location CDATA #IMPLIED >
+<!ATTLIST sample theta CDATA #IMPLIED >
+<!ATTLIST sample n CDATA #IMPLIED >
+<!ATTLIST sample p CDATA #IMPLIED >
+
+<!ELEMENT gettimeofday EMPTY >
+<!-- two comma-separated variables: seconds,microseconds -->
+<!ATTLIST gettimeofday assign_to CDATA #REQUIRED >
+
+<!ELEMENT index EMPTY >
+<!ATTLIST index assign_to CDATA #REQUIRED >
+
+<!ELEMENT trim EMPTY >
+<!ATTLIST trim assign_to CDATA #REQUIRED >
 
 <!ELEMENT urldecode EMPTY >
 <!ATTLIST urldecode variable CDATA #REQUIRED >
@@ -118,6 +197,32 @@
 <!ELEMENT urlencode EMPTY >
 <!ATTLIST urlencode variable CDATA #REQUIRED >
 
+<!ELEMENT verifyauth EMPTY >
+<!ATTLIST verifyauth assign_to CDATA #REQUIRED >
+<!ATTLIST verifyauth username CDATA #REQUIRED >
+<!ATTLIST verifyauth password CDATA #REQUIRED >
+
+<!ELEMENT lookup EMPTY >
+<!ATTLIST lookup assign_to CDATA #REQUIRED >
+<!ATTLIST lookup file CDATA #REQUIRED >
+<!ATTLIST lookup key CDATA #REQUIRED >
+
+<!ELEMENT insert EMPTY >
+<!ATTLIST insert file CDATA #REQUIRED >
+<!ATTLIST insert value CDATA #REQUIRED >
+
+<!ELEMENT replace EMPTY >
+<!ATTLIST replace file CDATA #REQUIRED >
+<!ATTLIST replace line CDATA #REQUIRED >
+<!ATTLIST replace value CDATA #REQUIRED >
+
+<!ELEMENT setdest EMPTY >
+<!ATTLIST setdest host CDATA #REQUIRED >
+<!ATTLIST setdest port CDATA #REQUIRED >
+<!ATTLIST setdest protocol CDATA #REQUIRED >
+
+<!ELEMENT closecon EMPTY >
+
 <!-- END actions -->
 
 <!ELEMENT timewait EMPTY >
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/src/auth.cpp new/sipp-3.7.9/src/auth.cpp
--- old/sipp-3.7.8/src/auth.cpp 2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/src/auth.cpp 2026-09-30 09:12:47.000000000 +0200
@@ -316,6 +316,7 @@
     EVP_DigestUpdate(mdctx, (unsigned char *) &ha2_hex, HASH_HEX_SIZE);
     EVP_DigestFinal_ex(mdctx, resp, &digest_len);
     hashToHex(&resp[0], result, MD5_HASH_SIZE);
+    EVP_MD_CTX_free(mdctx);
 
     return 1;
 }
@@ -575,12 +576,14 @@
         return nullptr;
     }
 
-    // EVP_DecodeBlock doesn't account for padding
-    if (len > 0 && buf[len - 1] == '=') decoded_len--;
-    if (len > 1 && buf[len - 2] == '=') decoded_len--;
+    // OpenSSL decodes the '=' padding as zero bytes, wolfSSL doesn't
+    if (decoded_len == (int)(len / 4 * 3)) {
+        if (len > 0 && buf[len - 1] == '=') decoded_len--;
+        if (len > 1 && buf[len - 2] == '=') decoded_len--;
+    }
 
     out[decoded_len] = '\0';
-    *newlen = decoded_len + 1;
+    *newlen = decoded_len;
     return out;
 }
 
@@ -884,4 +887,31 @@
     free(header);
 }
 
+TEST(DigestAuth, base64_decode_string) {
+    int len;
+    char* out = base64_decode_string("YWJj", 4, &len);
+    ASSERT_NE(nullptr, out);
+    EXPECT_EQ(3, len);
+    EXPECT_STREQ("abc", out);
+    free(out);
+    out = base64_decode_string("YWJjZGU=", 8, &len);
+    ASSERT_NE(nullptr, out);
+    EXPECT_EQ(5, len);
+    EXPECT_STREQ("abcde", out);
+    free(out);
+    out = base64_decode_string("YWJjZA==", 8, &len);
+    ASSERT_NE(nullptr, out);
+    EXPECT_EQ(4, len);
+    EXPECT_STREQ("abcd", out);
+    free(out);
+    /* Zero bytes are decoded, not taken as padding */
+    out = base64_decode_string("AAAA", 4, &len);
+    ASSERT_NE(nullptr, out);
+    EXPECT_EQ(3, len);
+    EXPECT_EQ(0, memcmp("\0\0\0", out, 4));
+    free(out);
+    EXPECT_EQ(nullptr, base64_decode_string("YW!j", 4, &len));
+    EXPECT_EQ(0, len);
+}
+
 #endif //GTEST
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/src/scenario.cpp 
new/sipp-3.7.9/src/scenario.cpp
--- old/sipp-3.7.8/src/scenario.cpp     2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/src/scenario.cpp     2026-09-30 09:12:47.000000000 +0200
@@ -265,19 +265,16 @@
 static char* xp_get_string(const char *name, const char *what)
 {
     const char *ptr;
-    char *unescaped;
 
     if (!(ptr = xp_get_value(name))) {
         ERROR("%s is missing the required '%s' parameter.", what, name);
     }
 
-    unescaped = (char *)malloc(strlen(ptr) + 1);
-    if (!unescaped) {
+    char *copy = strdup(ptr);
+    if (!copy) {
         ERROR("Out of memory!");
     }
-    xp_unescape(ptr, unescaped);
-
-    return unescaped;
+    return copy;
 }
 
 static double xp_get_double(const char *name, const char *what)
@@ -1885,13 +1882,13 @@
 
 int createStringTable(const char* inputString, char*** stringList, int* 
sizeOfList)
 {
+    *stringList = nullptr;
+    *sizeOfList = 0;
+
     if(!inputString) {
         return 0;
     }
 
-    *stringList = nullptr;
-    *sizeOfList = 0;
-
     /* FIXME: temporary workaround: needs rewrite */
     char* input = const_cast<char*>(inputString);
     do {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/src/xp_parser.cpp 
new/sipp-3.7.9/src/xp_parser.cpp
--- old/sipp-3.7.8/src/xp_parser.cpp    2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/src/xp_parser.cpp    2026-09-30 09:12:47.000000000 +0200
@@ -35,73 +35,6 @@
 static char xp_elem_name[256];
 static int xp_invalid_line = 0;
 
-static const char *xp_find_escape(const char *escape, size_t len)
-{
-    static struct {
-        const char *name;
-        const char *value;
-    } html_escapes[] = {
-        { "amp", "&" },
-        { "gt", ">" },
-        { "lt", "<" },
-        { "quot", "\"" },
-        { nullptr, nullptr }
-    };
-
-    for (auto *n = html_escapes; n->name; ++n) {
-        if (strncmp(escape, n->name, len) == 0 && strlen(n->name) == len)
-            return n->value;
-    }
-    return nullptr;
-}
-
-int xp_unescape(const char *source, char *dest)
-{
-    const char *from;
-    char *to;
-
-    if (!source || !dest) {
-        return -1;
-    }
-
-    from = source;
-    to = dest;
-
-    while (*from) {
-        size_t pos = strcspn(from, "&");
-        memcpy(to, from, pos);
-        to += pos;
-        from += pos;
-
-        if (*from != '&')
-            break;
-
-        from++;  // skip '&'
-
-        size_t term = strcspn(from, ";");
-        if (from[term] == '\0') {
-            *to++ = '&';
-            memcpy(to, from, term);
-            to += term;
-            break;
-        }
-
-        const char *escape = xp_find_escape(from, term);
-        if (!escape) {
-            *to++ = '&';
-            continue;
-        }
-
-        size_t escape_len = strlen(escape);
-        memcpy(to, escape, escape_len);
-        to += escape_len;
-        from += term + 1;
-    }
-
-    *to = '\0';
-    return to - dest;
-}
-
 static bool xp_load(const char *xml_text)
 {
     xp_stack.clear();
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/sipp-3.7.8/src/xp_parser_ut.cpp 
new/sipp-3.7.9/src/xp_parser_ut.cpp
--- old/sipp-3.7.8/src/xp_parser_ut.cpp 2026-09-23 22:35:51.000000000 +0200
+++ new/sipp-3.7.9/src/xp_parser_ut.cpp 2026-09-30 09:12:47.000000000 +0200
@@ -197,60 +197,4 @@
     xp_close_element();
 }
 
-TEST(xp_unescape, empty) {
-    char buffer[] = "";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("", dst);
-}
-
-TEST(xp_unescape, noop) {
-    char buffer[] = "<xml>no escape sequences</xml>";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("<xml>no escape sequences</xml>", dst);
-}
-
-TEST(xp_unescape, begin_and_end) {
-    char buffer[] = "&lt;xml>this &amp;&amp; that</xml&gt;";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("<xml>this && that</xml>", dst);
-}
-
-TEST(xp_unescape, single_double_quote) {
-    char buffer[] = "&quot;";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("\"", dst);
-}
-
-TEST(xp_unescape, escaped_escape) {
-    char buffer[] = "&amp;amp;";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("&amp;", dst);
-}
-
-TEST(xp_unescape, unclosed_escape) {
-    char buffer[] = "&lt; &amp &amp";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("< &amp &amp", dst);
-}
-
-TEST(xp_unescape, late_closed_escape) {
-    char buffer[] = "&lt; &amp &amp; &gt;";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("< &amp & >", dst);
-}
-
-TEST(xp_unescape, unknown_escape) {
-    char buffer[] = "&lt;&garbage;&gt;";
-    char dst[sizeof(buffer)];
-    xp_unescape(buffer, dst);
-    EXPECT_STREQ("<&garbage;>", dst);
-}
-
 #endif //GTEST

Reply via email to