- Added 'cf-secret' binary for host-specific encryption (CFE-2613)
- 'cf-check diagnose --test-write' can now be used to test writing
into LMDB files (ENT-4484)
- 'if' constraint now works in combination with class contexts
(CFE-2615)
- Added $(sys.cf_version_release) variable (ENT-5348)
- Added new macros to parser: else, maximum_version, between_versions,
before_version, at_version and after_version. Version macros now
accept single digits (CFE-3198)
- Added cf-postgres requirement to cf-apache and cf-hub systemd units
(ENT-5125)
- Added files promise content attribute (CFE-3276)
- Added string_trim() policy function (CFE-3074)
- Added warning if CSV parser parses nothing from non-empty file
(CFE-3256)
- All changes made by 'files' promises are now reported. Also,
directory and file creations are now properly reported as 'info'
messages. And failures in edit_xml result in promises marked as
failed not interrupted. Purged dirs and files are reported as
repaired (ENT-5291, CFE-3260)
- Bootstrap to loopback interface is now allowed, with a warning
(CFE-3304)
- Client initiated reporting was fixed on RHEL 8.1 (ENT-5415)
- Fixed rare crashing bug when parsing zombie entries in ps output.
The problem was only ever observed on AIX, but could theoretically happen
on any platform depending on exact libc behavior. (ENT-5329)
- Fixed an issue causing duplicate entries in sys.interfaces, and
sys.hardware. (CFE-3046)
- Fixed ifelse() to return fallback in case of unresolved variables
OBS-URL: https://build.opensuse.org/package/show/systemsmanagement/cfengine?expand=0&rev=188
- Update to 3.12.1 (LTS)
- Added a new binary: cf-check
+ Corrupt local databases (LMDB) continues to be a problem.
cf-check will be used to diagnose and remediate problems
with corrupt databases. It is a standalone binary, which
doesn't evaluate policy or use the local databases, thus
it can be used in situations where the other binaries
like cf-agent would hang.
+ cf-check replaces our lmdb database dumper, lmdump.
+ `cf-check lmdump` or symlinking / renaming it to lmdump
will make cf-check have the exact same behavior as lmdump.
cf-check will include much more functionality in the future
and some of the code will be added to other binaries,
for example to do health checks of databases on startup.
Ticket: (ENT-4064)
- Class names set by module protocol are automatically canonified
(CFE-2877, CFE-2887)
- Correct log level for data_readstringarray* (CFE-2922)
- Eliminated error messages caused by attempting to kill expired processes
(CFE-2824)
- Fix cf-runalerts systemd unit conditions so the service will run
(ENT-3929)
- Fix the off-by-one error in cf-runagent background process spawning
(CFE-2873)
- Fixed a memory leak which occurred when reloading RSA keys from disk
- Fixed a memory leak which occurred while loading augments files
(CFE-2913)
- Fixed an issue while parsing ps output on AIX (ENT-4295)
- Fixed an issue with splay time in cf-execd (CFE-2931)
- Fixed error handling and memory leak in cf-key (CFE-2918)
OBS-URL: https://build.opensuse.org/request/show/685337
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/cfengine?expand=0&rev=74
- Update to 3.12.1 (LTS)
- Added a new binary: cf-check
+ Corrupt local databases (LMDB) continues to be a problem.
cf-check will be used to diagnose and remediate problems
with corrupt databases. It is a standalone binary, which
doesn't evaluate policy or use the local databases, thus
it can be used in situations where the other binaries
like cf-agent would hang.
+ cf-check replaces our lmdb database dumper, lmdump.
+ `cf-check lmdump` or symlinking / renaming it to lmdump
will make cf-check have the exact same behavior as lmdump.
cf-check will include much more functionality in the future
and some of the code will be added to other binaries,
for example to do health checks of databases on startup.
Ticket: (ENT-4064)
- Class names set by module protocol are automatically canonified
(CFE-2877, CFE-2887)
- Correct log level for data_readstringarray* (CFE-2922)
- Eliminated error messages caused by attempting to kill expired processes
(CFE-2824)
- Fix cf-runalerts systemd unit conditions so the service will run
(ENT-3929)
- Fix the off-by-one error in cf-runagent background process spawning
(CFE-2873)
- Fixed a memory leak which occurred when reloading RSA keys from disk
- Fixed a memory leak which occurred while loading augments files
(CFE-2913)
- Fixed an issue while parsing ps output on AIX (ENT-4295)
- Fixed an issue with splay time in cf-execd (CFE-2931)
- Fixed error handling and memory leak in cf-key (CFE-2918)
OBS-URL: https://build.opensuse.org/request/show/682853
OBS-URL: https://build.opensuse.org/package/show/systemsmanagement/cfengine?expand=0&rev=178
New Features:
- Add a --key-type option to specify RSA key size to cf-key
- New hash_to_int policy function (CFE-2733)
- Issue a warning on ignored locking attributes (CFE-2748)
- Add IPv6 hard classes with the "ipv6_" prefix (CFE-2310)
- Introduce "missing_ok" attribute in body copy_from
This allows to ignore missing sources in file copy operations
(CFE-2365)
- Enable Xen hypervisor detection on all x86 platforms (CFE-2203)
- Add sys.policy_entry variables (CFE-2572)
- Added inline_mustache template method (CFE-1846)
- New component cf-net (cf-net is a CLI for the CFEngine network
protocol, useful for debugging, testing etc) and accompanying
policy variable sys.cf_net containing path to cf-net binary
- Added --log-level option to all components
This allows you to specify any log level (info, verbose, debug
etc.).
It is also less strict, allowing different spelling. As an example,
--log-level i, --log-level INFO, --log-level inform are all the same.
- Added special behavior for bundles named __main__
If the bundle is defined in the entry policy it will be defined as
main.
If the bundle is defined elsewhere, it will be removed.
This makes it easy to make importable library policy which can also
be executed directly.
- See https://github.com/cfengine/core/blob/3.12.x/ChangeLog for other
changes and bug fixes
- drop 0003-CFE-2629-Openssl-1.1-compatibility.patch (upstream)
drop reproducible.patch (upstream)
OBS-URL: https://build.opensuse.org/package/show/systemsmanagement/cfengine?expand=0&rev=174
- add 0003-CFE-2629-Openssl-1.1-compatibility.patch
for openssl-1.1.0 compatibility
- Update to 3.11.0
New Features:
- allow function calls in promiser using universal "with"
attribute. (CFE-1092)
- add example of with attribute (CFE-1092)
- Detect Amazon Linux and set "AmazonLinux" hard class and
sys.flavour variable.
- New sysctlvalue() and data_sysctlvalues() functions from /proc/sys
(CFE-2513)
- readdata() also auto-detects .yml files as YAML
- Added support for ENV and CSV file parsing (CFE-1881)
- Added vars and classes for CoreOS (ENT-3043)
- cf-agent: implement --show-evaluated-vars and
--show-evaluated-classes
- Support for custom ports and host names as policy hub (CFE-953)
- cf-promises: allows --show-vars and --show-classes to take an
optional filter
- Added a new tool: cf-net. cf-net is a CLI for the CFEngine
network protocol, useful for debugging, testing etc.
(CFE-2493)
- New policy variable: sys.cf_net contains path to cf-net binary
- Read /etc/os-release into sys.os_release (CFE-1881)
- Full changelog at https://github.com/cfengine/core/blob/3.11.0/ChangeLog
OBS-URL: https://build.opensuse.org/request/show/558813
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/cfengine?expand=0&rev=70
New Features:
- allow function calls in promiser using universal "with"
attribute. (CFE-1092)
- add example of with attribute (CFE-1092)
- Detect Amazon Linux and set "AmazonLinux" hard class and
sys.flavour variable.
- New sysctlvalue() and data_sysctlvalues() functions from /proc/sys
(CFE-2513)
- readdata() also auto-detects .yml files as YAML
- Added support for ENV and CSV file parsing (CFE-1881)
- Added vars and classes for CoreOS (ENT-3043)
- cf-agent: implement --show-evaluated-vars and
--show-evaluated-classes
- Support for custom ports and host names as policy hub (CFE-953)
- cf-promises: allows --show-vars and --show-classes to take an
optional filter
- Added a new tool: cf-net. cf-net is a CLI for the CFEngine
network protocol, useful for debugging, testing etc.
(CFE-2493)
- New policy variable: sys.cf_net contains path to cf-net binary
- Read /etc/os-release into sys.os_release (CFE-1881)
- Full changelog at https://github.com/cfengine/core/blob/3.11.0/ChangeLog
OBS-URL: https://build.opensuse.org/package/show/systemsmanagement/cfengine?expand=0&rev=164
New features/additions:
- "make tar-package" should create a tarball with the contents of
"make install" (ENT-3041)
Bugfixes:
- Fix rare output truncation on Solaris 10/11 (CFE-2527)
- Change: Don't error during dry run for proposed execution.
(CFE-2561)
- prevent LMDB assertion on AIX by ensuring nested DB calls are
not occuring during signal handler cleanup (CFE-1996)
- Detect Amazon Linux and set "AmazonLinux" hard class and
sys.flavour variable.
- Fix "lastseenexpireafter" 32-bit signed int overflow.
- Add missing pcre build flags to cf-key (CFE-2525)
- Fix a bug which could cause cf-execd to believe there was
an error when sending the email report, when there really wasn't.
- cf-serverd: Auto configure max open files ulimit according to
maxconnections (CFE-2575)
- Added vars and classes for CoreOS (ENT-3043)
OBS-URL: https://build.opensuse.org/package/show/systemsmanagement/cfengine?expand=0&rev=156