File _patchinfo of Package patchinfo.22667

<patchinfo incident="22667">
  <issue tracker="bnc" id="914486">server:monitoring/monitoring-plugins: Bug</issue>
  <issue tracker="bnc" id="1132350">trackerbug: adapt all apparmor profiles containing /bin/bash after bash move</issue>
  <issue tracker="bnc" id="1047218">trackerbug: packages do not build reproducibly from including build time</issue>
  <issue tracker="bnc" id="1133107">monitoring-plugins: apparmor profile for check_procs</issue>
  <issue tracker="bnc" id="1132903">server:monitoring/monitoring-plugins: Bug monitoring-plugins-ping fails with '-4' argument on Leap 42.3</issue>
  <issue tracker="bnc" id="1191011">monitoring-plugins requires Python 2</issue>
  <issue tracker="bnc" id="1114483">icinga service looks for nonexistent directory</issue>
  <packager>lrupp</packager>
  <rating>moderate</rating>
  <category>recommended</category>
  <summary>Recommended update for monitoring-plugins</summary>
  <description>This update for monitoring-plugins fixes the following issues:

- Reverting patch for the problem, if you get more than 64K on 
  stdout

- recommend syslog for monitoring-plugins-log, as people probably 
  want to analize logs generated by (r)syslog or journald
  check_snmp will segfaults at line 489 if number of lines returned 
  by SNMPD is greater than number of defined thresholds
  -&gt; https://github.com/monitoring-plugins/monitoring-plugins/pull/1589
  When the MIBs are not quite right, snmpget outputs lots of errors on 
  STDERR before getting down to business.
  If this is enough to fill the pipe buffer, snmpget hangs waiting for 
  it to be cleared, which it never will be because check_snmp is 
  waiting for snmpget to output something on STDOUT.
  This simple fix from s2156945 for this is to read STDERR before STDOUT.
  cmd_run_array from utils_cmd.c is also used by plugins/check_by_ssh 
  and plugins/negate but you're likely to get lots of errors or lots 
  of output, not both at the same time.
  The real fix is probably to do a select() and read from both as 
  they come in.
  https://github.com/monitoring-plugins/monitoring-plugins/issues/1706
  feature enhancement for check_dhcp, which allows 
  to detect rogue DHCP servers. Use it with the "-x" flag
  provided by op5, mainly around RFC 4253:4.2 and 4253:5
  + fixing a few typos
  + properly parse a (delayed) version control string 
  + Handle non-alpha software versions reported by the checked service
  
- Remove unneeded BuildRequires on python-devel (bsc#1191011)

- Call gettextize with --no-changelog to make package build
  reproducible (bsc#1047218)

- Update to 2.3.1:
  Enhancements
  * check_curl: Add an option to verify the peer certificate and host using the system CA's
  Fixes
  * check_curl: fixed help, usage and errors for TLS 1.3
  * check_curl: fixed a potential buffer overflow in url buffer
  * check_dns: split multiple IP addresses passed in one -a argument
  * check_curl: added string_statuscode function for printing HTTP/1.1 and HTTP/2 correctly
  * check_curl: fix crash if http header contains leading spaces
  * check_curl: display a specific human-readable error message where possible
  * check_pgsql: Using snprintf which honors the buffers size and guarantees null termination.
  * check_snmp: put the "c" (to mark a counter) after the perfdata value
  * check_http: Increase regexp limit
  * check_http: make -C obvious
  * check_curl: Increase regexp limit (to 1024 as in check_http)
  * check_curl: make -C obvious (from check_http)
- add sha1 checksum file as source

- Update to 2.3 (final):
  Enhancements
  * check_dns: allow 'expected address' (-a) to be specified in CIDR notation (IPv4 only).
  * check_dns: allow for IPv6 RDNS
  * check_dns: Accept CIDR
  * check_dns: allow unsorted addresses
  * check_dns: allow forcing complete match of all addresses
  * check_apt: add --only-critical switch
  * check_apt: add -l/--list option to print packages
  * check_file_age: add range checking
  * check_file_age: enable to test for maximum file size
  * check_apt: adding packages-warning option
  * check_load: Adding top consuming processes option
  * check_http: Adding Proxy-Authorization and extra headers
  * check_snmp: make calcualtion of timeout value in help output more clear
  * check_uptime: new plugin for checking uptime to see how long the system is running
  * check_curl: check_http replacement based on libcurl
  * check_http: Allow user to specify HTTP method after proxy CONNECT
  * check_http: Add new flag --show-body/-B to print body
  * check_cluster: Added data argument validation
  * check_icmp: Add IPv6 support
  * check_icmp: Automatically detect IP protocol
  * check_icmp: emit error if multiple protocol version
  * check_disk: add support to display inodes usage in perfdata
  * check_hpjd: Added -D option to disable warning on 'out of paper'
  * check_http: support the --show-body/-B flag when --expect is used
  * check_mysql: allow mariadbclient to be used
  * check_tcp: add --sni
  * check_dns: detect unreachable dns service in nslookup output
  Fixes
  * Fix regression where check_dhcp was rereading response in a tight loop
  * check_dns: fix error detection on sles nslookup
  * check_disk_smb: fix timeout issue
  * check_swap: repaired -n behaviour
  * check_icmp: Correctly set address_family on lookup
  * check_icmp: Do not overwrite -4,-6 on lookup
  * check_smtp: initializes n before it is used
  * check_dns: fix typo in parameter description
  * check_by_ssh: fix child process leak on timeouts
  * check_mysql: Allow sockets to be specified to -H
  * check_procs: improve command examples for 'at least' processes
  * check_disk: include -P switch in help
  * check_mailq: restore accidentially removed options

- return ntp offset absolute (as positive value) in performance
  data since warn and crit are also positive values 


- change version to 2.3~alpha.$date.$commit
  update to current git as of 20200520T233014.cadac85e
  changes summarized
  * detect unreachable dns service in nslookup output
  * check_curl: host_name may be null
  * update test parameter according to check_http
  * check_curl: use CURLOPT_RESOLVE to fix connecting to the right ip
  * workaround for issue #1550 - better use "ping -4" instead
    of "ping" if supported
  * Use size_t instead of int when calling sysctl(3)
  * check_tcp: add --sni
  * Fix timeout_interval declarations
  * check_curl: NSS, parse more date formats from certificate (in
    -C cert check)
  * check_curl: more tolerant CN= parsing when checking
    certificates (hit on Centos 8)
  * setting no_body to TRUE when we have a HEAD request
  * some LIBCURL_VERSION checks around HTTP/2 feature
  * added --http-version option to check_curl to choose HTTP
  * improved curlhelp_parse_statusline to handle both HTTP/1.x
    and HTTP/2
  * check_curl: updates embedded picohttpparser to newest git
    version
  * setting progname of check_curl plugin to check_curl (at least
    for now)
  * Allow mariadbclient to be used for check_mysql
  * fix maxfd being zero
  * include -P switch in help
  * check_swap: repaired "-n" behaviour
  * improve command examples for 'at least' processes
  * check_mysql: Allow sockets to be specified to -H
  * Adding packages-warning option to check_apt plugin
  * Adding print top consuming processes option to check_load
  * check_snmp: make calcualtion of timeout value in help output more clear
  * [check_disk] add support to display inodes usage in perfdata
  * check_by_ssh: fix child process leak on timeouts
  * check_icmp: Add IPv6 support
  * check_dns: fix typo in parameter description
  * Also support the --show-body/-B flag when --expect is used
  * check_dns: improve support for checking multiple addresses
  * check_hpjd: Added -D option to disable warning on 'out of paper'
  * check_icmp: Do not overwrite -4,-6 on lookup
  * check_icmp: emit error if multiple protocol version
  * check_icmp: move opts string into a variable
  * check_cluster.c: Added data argument validation.
  * check_icmp: Correctly set address_family on lookup
  * check_icmp: process protocol version args first
  * check_icmp: Add IPv6 support
- add new subpackage monitoring-plugins-uptime


- 'monitoring-plugins-mysql' should also provide 'monitoring-plugins-mysql_query'
- Provide/Obsolete nagios-plugins in old version for better 
  compatibility and to allow dist upgrade (bsc#1114483)

- Checnking only for suse_version &gt;= 1500

  sle12/leap42 ping does not know the -4 parameter (bsc#1132903)

- update AppArmor profiles for usrMerge (related to bsc#1132350)

- update 'usr.lib.nagios.plugins.check_procs' again for &gt;= sle15
  case so that ptrace is allowed (bsc#1133107)

- add /etc/nrpe.d/*.cfg snipplets for 
  + nrpe-check_load =&gt; check_load
  + nrpe-check_mailq =&gt; check_mailq
  + nrpe-check_ntp_time =&gt; check_ntp_time
  + nrpe-check_swap =&gt; check_swap
  + nrpe-check_total_procs =&gt; check_procs
  + nrpe-check_zombie_procs =&gt; check_procs
  + nrpe-check_users =&gt; check_users
  + nrpe-check_mysql =&gt; check_mysql
  + nrpe-check_proc_cron =&gt; check_procs
  + nrpe-check_partition =&gt; check_disk
  + nrpe-check_ups =&gt; check_ups
- use %%license macro on newer versions

- copy usr.lib.nagios.plugins.check_procs as
  usr.lib.nagios.plugins.check_procs.sle15 and use that for sle15
  and above. "ptrace" to enable ptrace globally is needed here.

- Fix build with MariaDB 10.2 (in our case the build with libmariadb
  library from the mariadb-connector-c package)

- replace "ptrace" with "capability sys_ptrace" in 
  usr.lib.nagios.plugins.check_procs apparmor profile to avoid 
  errors on SLE-11

- add "ptrace" to usr.lib.nagios.plugins.check_procs apparmor
  profile

- Remove unused gnutls from buildrequires

- Replace %__-type macro indirections. Drop %clean, replace
  -exec \; by -exec +.

- disable requires for apparmor on non-suse for now 

- adapt buildrequires for centos
- enclose all permissions handling with if suse_version 
- wrap recommends with if suse_version
- disable radius check (no freeradius-client-devel rpm found)

- update to 2.2:
  Enhancements
  + The check_http -S/--ssl option now accepts the arguments 1.1 and 
    1.2 to force TLSv1.1 and TLSv1.2 connections, respectively
  + The check_http -S/--ssl option now allows for specifying the 
    desired protocol with a + suffix to also accept newer versions
  + Let check_http check HTTPS web sites via proxies
  + check_http: add timeout to performance data as max value
  + check_http: report certificate expiry date in UTC
  + check_snmp: add IPv6 support
  + check_snmp's performance data now also includes warning/
    critical thresholds
  + New check_snmp -N option to specify SNMPv3 context name
  + Let check_smtp's -D option imply -S
  + Let check_smtp's -e option match against the full SMTP response
  + check_dig: expected response is now case-insensitive
  + New check_mailq -s option which tells the plugin to use sudo(8)
  + New check_nt -l parameters: seconds|minutes|hours|days
  + New -W/-C option for check_ldap to check number of entries
  + check_users: add support for range thresholds
  + check_fping now auto-detects IPv6 addresses
  + check_radius now supports the radcli library
  + Support OpenSSL 1.1
  Fixes
  + check_http: fix host header port handling
  + Let check_real terminate lines with CRLF when talking to the server, 
    as mandated by RFC 2326
  + Fix check_procs on HP-UX
  + check_smtp's -e/--expect option can now be combined with -S/--starttls
  + Fix incorrect performance data thresholds emitted by check_ups
  + Don't let check_procs miss some processes on busy Solaris systems
  Warnings
  + The format of the performance data emitted by check_mrtgtraf has 
    been changed to comply with the development guidelines
  + check_ssh now returns CRITICAL for protocol/version errors
  + If a plugin is invoked with -h/--help or -V/--version, the exit status
    is now UNKNOWN
  + The superseeded check_ntp.pl was removed, please use check_ntp_peer
    or check_ntp_time instead

- usr.lib.nagios.plugins.check_disk:
  include abstractions/nameservice to be able to check nfs mounts

- update to 2.1.2:
  ENHANCEMENTS
  + check_snmp's performance data now also includes warning/critical
    thresholds
  + New check_snmp "-N" option to specify SNMPv3 context name
  + New check_nt "-l" parameters: seconds|minutes|hours|days
  + New check_mailq -s option which tells the plugin to use sudo(8)
  + New -W/-C option for check_ldap to check number of entries (Gerhard Lausser)
  + The check_http -S/--ssl option now accepts the arguments "1.1" and "1.2"
    to force TLSv1.1 and TLSv1.2 connections, respectively
  + The check_http -S/--ssl option now allows for specifying the desired
    protocol with a "+" suffix to also accept newer versions
  FIXES
  + Let check_real terminate lines with CRLF when talking to the server, as
    mandated by 2326
  + Fix check_procs on HP-UX
  + check_smtp's -e/--expect option can now be combined with -S/--starttls
  + Fix incorrect performance data thresholds emitted by check_ups
  WARNINGS
  + The format of the performance data emitted by check_mrtgtraf has been
    changed to comply with the development guidelines
  + check_ssh now returns CRITICAL for protocol/version errors
  + If a plugin is invoked with -h/--help or -V/--version, the exit status
    is now UNKNOWN
  + The superseded check_ntp.pl was removed, please use check_ntp_peer or
    check_ntp_time instead

- fix wrong requires for monitoring-plugins-dbi* packages
  (fixes bnc #914486) 

- add a note about permissions for the extra-opts file in README

- use the check_ircd script as submitted via GitHub

- update to 2.1.1:
  FIXES
  + Fix check_ntp's jitter checking
  + Fix check_ntp's handling of invalid server responses
  + Fix check_apt's handling of invalid regular expressions
  + Fix check_real's server response processing
  + Fix backslash escaping in check_tcp's --help output
  + Fix check_jabber to work with Openfire servers
  + Fix check_oracle bad string matching when testing TNS server
  + Fixed check_ifstatus performance data output
  + Fixed expire time output for sslutils
  + check_dns now verifies if the answer is returning from the queried
    server
  + Fix check_by_ssh to accept --hostname as argument
  ENHANCEMENTS
  + New check_hpjd -p option for port specification (abrist)
  + New ./configure --with-qmail-qstat-command option to specify the path to
    qmail-qstat(8)
  + New check_ifstatus -n option to ignore interfaces by name
  + check_ntp_peer has now specific state output for each metric
  + New check_mysql -n option to ignore authentication failures
  + Added IP and port or socket name to error messages
  + New check_ntp_time -o option to add expected offset
  + check_disk shows now troubled partions in verbose mode
  + check_dig has now support for drill and dig
  + check_dig has now support for -6 option
  + Add performance data to check_file_age
- ran spec-cleaner
- require portmap on older distributions for building instead of 
  rpcbind
- newer openSUSE versions use rsyslog: require virtual syslog 
  package for build

- remove nagios-devel from BuildRequires</description>
</patchinfo>
openSUSE Build Service is sponsored by