Debian Package Tracker
Register | Log in
Subscribe

pcp

System level performance monitoring and performance management

Choose email to subscribe with

general
  • source: pcp (main)
  • version: 7.2.1-2
  • maintainer: PCP Development Team (DMD)
  • uploaders: Ken McDonell [DMD] – Nathan Scott [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.2.6-1
  • oldstable: 6.0.3-1.1
  • stable: 6.3.8-1
  • unstable: 7.2.1-2
versioned links
  • 5.2.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.3-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.3.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.2.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libpcp-archive1
  • libpcp-archive1-dev
  • libpcp-gui2
  • libpcp-gui2-dev
  • libpcp-import-perl
  • libpcp-import1
  • libpcp-import1-dev
  • libpcp-import2
  • libpcp-import2-dev
  • libpcp-logsummary-perl
  • libpcp-mmv-perl
  • libpcp-mmv1
  • libpcp-mmv1-dev
  • libpcp-pmda-perl
  • libpcp-pmda3
  • libpcp-pmda3-dev
  • libpcp-trace2
  • libpcp-trace2-dev
  • libpcp-web1
  • libpcp-web1-dev
  • libpcp3
  • libpcp3-dev
  • libpcp4
  • libpcp4-dev
  • pcp (2 bugs: 0, 2, 0, 0)
  • pcp-atop
  • pcp-conf
  • pcp-doc
  • pcp-dstat (1 bugs: 0, 1, 0, 0)
  • pcp-export-pcp2elasticsearch
  • pcp-export-pcp2graphite
  • pcp-export-pcp2influxdb
  • pcp-export-pcp2json
  • pcp-export-pcp2spark
  • pcp-export-pcp2xlsx
  • pcp-export-pcp2xml
  • pcp-export-pcp2zabbix
  • pcp-export-zabbix-agent
  • pcp-gui
  • pcp-htop
  • pcp-import-benchmarks
  • pcp-import-collectl2pcp
  • pcp-import-ganglia2pcp
  • pcp-import-guidellm2pcp
  • pcp-import-iostat2pcp
  • pcp-import-mrtg2pcp
  • pcp-import-sar2pcp
  • pcp-import-sheet2pcp
  • pcp-pmda-infiniband
  • pcp-testsuite
  • pcp-zeroconf
  • python3-pcp
action needed
lintian reports 2 errors and 10 warnings high
Lintian reports 2 errors and 10 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-14 Last update: 2026-09-13 07:30
10 security issues in bookworm high

There are 10 open security issues in bookworm.

6 important issues:
  • CVE-2026-16524: A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
4 issues postponed or untriaged:
  • CVE-2023-6917: (needs triaging) A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.
  • CVE-2024-3019: (needs triaging) A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.
  • CVE-2024-45769: (needs triaging) A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
  • CVE-2024-45770: (needs triaging) A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
Created: 2024-02-29 Last update: 2026-09-01 22:00
9 security issues in bullseye high

There are 9 open security issues in bullseye.

6 important issues:
  • CVE-2026-16524: A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
2 issues postponed or untriaged:
  • CVE-2023-6917: (needs triaging) A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.
  • CVE-2024-3019: (needs triaging) A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.
1 ignored issue:
  • CVE-2024-45770: A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
Created: 2026-07-30 Last update: 2026-08-29 19:00
AppStream hints: 1 error and 1 warning for pcp-gui high
AppStream found metadata issues for packages:
  • pcp-gui: 1 error and 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2018-06-04 Last update: 2026-02-23 04:00
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-08-29 Last update: 2026-10-05 09:03
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 7.2.2-1, distribution unstable) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 6e925f6cb4dba183cf43cd3785c8e623d2a62a33
Merge: 62366c60 b5c7df2e
Author: Nathan Scott <nathans@redhat.com>
Date:   Sun Oct 4 13:15:48 2026 +1100

    Merge branch 'main' of github.com:performancecopilot/pcp

commit b5c7df2e0834ad413ae3c03e4456394c7f28e291
Merge: 5fd36b19 95b3768e
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sun Oct 4 11:49:14 2026 +1100

    Merge pull request #2744 from sjdot/sjdot/fix-off-by-one-hostname
    
    libpcp: fix gethostname() buffer length off by one

commit 95b3768e092451d74e0b54fda245e2feab70fdf2
Author: Steven Johnson <sjdot@protonmail.com>
Date:   Sat Oct 3 14:41:39 2026 -0400

    libpcp: fix gethostname() buffer length off by one
    
    Several calls to gethostname() pass MAXHOSTNAMELEN as the buffer len
    which is 64 bytes (on Linux). The buffer is sized with MAXHOSTNAMELEN+1
    which leaves room for the required trailing null char (65 bytes).
    
    If a hostname is set to MAXHOSTNAMELEN (64 characters) it will cause
    gethostname() to fail with ENAMETOOLONG because passing MAXHOSTNAMELEN
    as the buffer length does not account for the trailing null char
    required.
    
    This commit instead uses sizeof(buffer) to ensure that the 65 byte
    length is used.
    
    I hit this issue in src/libpcp/src/access.c but found the same pattern
    in src/libpcp/src/logportmap.c, src/libpcp3/src/access.c and
    src/libpcp3/src/logportmap.c also.
    
    Running in docker with a 64 character hostname with and without this
    patch:
    
    Before (fedora vanilla pcp):
    
            hostname length: 64
            pcp-7.2.1-1.fc44.x86_64
            Starting pmcd ... [Sat Oct  3 16:18:39] pmcd(96) Error: gethostname failure
            [Sat Oct  3 16:18:39] pmcd(96) Error: Can't get host name/IP address, giving up
            Warning: the following access control specification will be ignored
            pmcd config[line 20]: Warning: access control error for host 'local:*': Host is down
    
            pminfo: Cannot connect to PMCD on host "127.0.0.1": No permission to perform requested operation
            --- pmcd.log ---
            [Sat Oct  3 16:18:39] pmcd(98) Error: gethostname failure
            [Sat Oct  3 16:18:39] pmcd(98) Error: Can't get host name/IP address, giving up
            pmcd config[line 20]: Warning: access control error for host 'local:*': Host is down
            [Sat Oct  3 16:18:39] pmcd(98) Error: gethostname failure
            FAIL
    
    After (this commit):
    
            hostname length: 64
            Starting pmcd ...
    
            kernel.all.load
                inst [1 or "1 minute"] value 0.69
                inst [5 or "5 minute"] value 0.68000001
                inst [15 or "15 minute"] value 0.70999998
            --- pmcd.log ---
            PASS: loopback client connected
    
    Signed-off-by: Steven Johnson <sjdot@protonmail.com>

commit 5fd36b191d987c9a6292f2868aeef8b08937a6db
Merge: 2f642473 257c303d
Author: Nathan Scott <nathans@redhat.com>
Date:   Sat Oct 3 12:10:28 2026 +1000

    Merge branch 'sfeifer-libvalkey_issue'

commit 257c303d41fc5f079f8f74f3d2f425abb35718e4
Merge: 2f642473 2bf3d9b8
Author: Nathan Scott <nathans@redhat.com>
Date:   Sat Oct 3 12:10:16 2026 +1000

    Merge branch 'libvalkey_issue' of https://github.com/sfeifer/pcp into sfeifer-libvalkey_issue

commit 62366c60859ee2927c20fb9cad184d4461a15fef
Author: Nathan Scott <nathans@redhat.com>
Date:   Fri Oct 2 13:24:27 2026 +1000

    libpcp_web: fix Coverity reference handling
    
    Signed-off-by: Nathan Scott <nathans@redhat.com>

commit 1648058fc443f801e55e6f67cbe6cde32982794b
Merge: 2f642473 1a84499e
Author: Nathan Scott <nathans@redhat.com>
Date:   Sat Oct 3 11:46:53 2026 +1000

    Merge branch 'sfeifer-libvalkey_issue'

commit 1a84499e6e861e8aa94a5af45bdbadb1c22a03c8
Merge: 2f642473 2bf3d9b8
Author: Nathan Scott <nathans@redhat.com>
Date:   Sat Oct 3 11:46:46 2026 +1000

    Merge branch 'libvalkey_issue' of https://github.com/sfeifer/pcp into sfeifer-libvalkey_issue

commit 2f6424735d97a1dfdebfd8d724764cf4c001a2f1
Merge: 159aa70a ce18b50b
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sat Oct 3 07:16:18 2026 +1000

    Merge pull request #2742 from pauljevans/pevans-merge
    
    qa/1188: Update sysfs VDO stats output to include new metrics

commit 159aa70a5ce68d6bb37519470975fa72b8912ba1
Author: Sam Feifer <sfeifer@redhat.com>
Date:   Fri Oct 2 09:26:46 2026 -0400

    Add HTTP Basic authentication to the push model
    
    Offer per-client authentication for pmlogpush and pmlogger remote-push as
    an alternative to client-certificate (mutual TLS) authentication.  Client
    certificates require provisioning the same trusted certificate that
    pmproxy uses towards Grafana, which is awkward on internal networks and
    for federated setups; HTTP Basic auth lets each sender present its own
    credential over the [pmlogger] logger servlet endpoints.
    
    Basic credentials are only base64 encoded, not encrypted, so they are
    sent exclusively over a TLS-encrypted, server-authenticated connection
    (F_SECURE) and never in the clear - the transport encryption still comes
    from the server's certificate, independent of client auth.
    
    libpcp_web:
     - add pmhttpClientSetCredentials() and emit an Authorization: Basic
       header from http_client_get()/http_client_post(), refusing to send
       credentials unless the connection is secure, and failing closed with
       -E2BIG if the Authorization header would not fit
     - fix base64_encode(), which produced corrupt, unpadded output and had
       no in-tree callers; it now emits correct RFC 4648 padded output that
       pmproxy's base64_decode() accepts
    
    pmlogpush:
     - -U/--username plus -P/--password-file (or $PCP_PUSH_PASSWORD); the
       password is never taken on the command line, -U requires -S, and -U is
       rejected over a Unix domain socket (-s)
    
    pmlogger:
     - --push-user and --push-password-file (long-only; -U/-P are taken),
       requiring an https:// remote-push connection
    
    pmproxy:
     - the logger servlet previously only checked that credentials were
       present when [pmlogger] authenticate was set - any username/password
       was accepted.  pmproxy keeps no password store of its own, so validate
       the credentials as the pmseries servlet does: inject them as
       connection attributes and open a short-lived pmcd context whose SASL
       exchange is the authority.  The push user must be a valid pmcd SASL
       user on the authenticating host ([pmlogger] auth_host, default
       localhost).
     - a validated (user, secret) pair is cached on the keep-alive
       connection - surviving the per-request reset in http_client_release -
       so a multi-POST push authenticates once rather than once per record.
     - failures are classified as credential denial (403) or pmcd
       unreachable (503), failing closed on ambiguity.
    
    Documented in the pmlogpush(1) and pmlogger(1) man pages and in
    pmproxy.conf, and covered by QA test 2111, which provisions a real pmcd
    SASL user (as qa/1388 does) to exercise the positive and wrong-password
    paths.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

commit ac698d323591ccee09a47c3dbc5d3a6222d025b1
Author: Sam Feifer <sfeifer@redhat.com>
Date:   Fri Oct 2 09:26:37 2026 -0400

    Add TLS/HTTPS encryption to the PCP push model
    
    The push model ships PCP archive data to pmproxy over HTTP POST
    (/logger/{label,meta,index,volume}, default port 44322) from two
    senders - pmlogpush and pmlogger remote-push - through the shared
    HTTP client in libpcp_web.  That transport was plaintext only; this
    adds https:// support so the push path can be encrypted end-to-end,
    reusing PCP's existing OpenSSL machinery and /etc/pcp/tls.conf.
    
    libpcp/libpcp3:
    - New __pmSecureClientConnect(fd, hostname): raw TLS setup + handshake
      only (no PDU/SASL), sharing the SSL-setup block with the existing PDU
      client path.  Non-OpenSSL stub returns -EOPNOTSUPP.  Exported via
      exports.in and declared in libpcp.h.
    - Authenticate the HTTPS server: verify the peer certificate and match
      the hostname (or IP-address SAN) of the target, rejecting empty or
      leading-dot hostnames before SSL_set1_host.
    
    libpcp_web/http_client.c:
    - https scheme support: F_SECURE flag, TLS handshake after connect (no
      silent fallback - https fails cleanly if TLS is unavailable or the
      handshake fails), scheme-aware keep-alive matching and redirects.
    - Refuse redirects that downgrade https to cleartext http.
    
    The POST's header and body are sent as two writes; over TLS these become
    two records, which pmproxy now drains correctly per network read.
    
    Senders:
    - pmlogpush: new --secure/-S option (-S claimed in overrides() so it is
      not consumed as the standard start-time option); build_conn() emits
      https:// when set.
    - pmlogger: accept an https:// remote-push target.
    - logpush.class: documented https:// opt-in.
    
    QA:
    - New test qa/2112 exercises secure push, plaintext auto-detect, and
      clean failure (no cleartext fallback) of --secure against a non-TLS
      pmproxy.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

commit 593fef1cb1bba5925aa6a387f0e835da066f428a
Author: Sam Feifer <sfeifer@redhat.com>
Date:   Fri Oct 2 09:26:10 2026 -0400

    pmproxy: drain all decryptable TLS records per network read
    
    pmproxy's secure reader decrypted only one TLS record per network read,
    so a coalesced HTTP header+body (two records in one segment) left the
    body unread and hung the exchange.  Drain all decryptable records per
    read; guard against a synchronous client teardown mid-loop.
    
    This matters for the push model's HTTPS transport, where a POST's header
    and body are sent as separate TLS records that may coalesce into one
    network segment.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

commit fba83d35048d80ac848b4c92e766fcf3655bdc4c
Author: Renaud Métrich <rmetrich@redhat.com>
Date:   Thu Oct 1 17:29:36 2026 +0200

    Address coderabbitai review
    
    https://github.com/performancecopilot/pcp/pull/2740/changes/BASE..51c662daef4ba9a572dbee1a1ce21ff595cdb1a7#r4156399112

commit 19be4de7a82fb19a0ff29e0e9e9bec11820c497f
Author: Renaud Métrich <rmetrich@redhat.com>
Date:   Thu Oct 1 14:41:30 2026 +0200

    pmproxy: fix sdslen(NULL) crash in http_reply() when gzip stream is stale
    
    When a pmseries query completes (or fails) on a keep-alive HTTP connection
    whose gzip deflate stream was already finalised by a previous response,
    compress_buffer() calls deflate(Z_FINISH) on a stream already at
    Z_STREAM_END.  deflate() returns Z_BUF_ERROR with zero output bytes,
    compress_buffer() returns NULL, and the NULL is passed straight to
    sdslen() in http_reply(), crashing with SIGSEGV at 0xFFFFFFFFFFFFFFFF.
    
    The crash is reproducible with any Grafana PCP-Valkey dashboard panel:
      1. Open a dashboard backed by pmproxy (pmseries queries with gzip).
      2. The first pmseries callback that fires after the prior response's
         Z_STREAM_END triggers the crash.
    
    Fix: restructure compress_buffer() so that the input SDS buffer is freed
    only after the output-length check.  When done=true and deflate produces
    no output (stale Z_STREAM_END), call deflateReset() and compress the
    same input once more.  This recovers the stream transparently and
    guarantees that compress_buffer() never returns NULL for a non-empty
    input when asked for a final flush.
    
    Valgrind reproducer:
      # valgrind --tool=memcheck --leak-check=no --num-callers=20 \
        --log-file=/tmp/vg-pmproxy.log \
        /usr/libexec/pcp/bin/pmproxy -F -A
      Reload any Grafana PCP-Valkey panel multiple times while restarting
      "valkey" service:
      # while :; do systemctl stop valkey; echo "valkey stopped"; \
        sleep 2; systemctl start valkey; echo "valkey started"; sleep 2; done
    
    Valgrind output with segfault:
    
     Invalid read of size 1
        at 0x400DC47: sdslen (sds.h:99)
        by 0x400DC47: http_reply (http.c:548)
        by 0x40120F9: on_pmseries_done (series.c:595)
        by 0x48A5306: series_query_finished (query.c:282)
        by 0x48A53D7: series_query_end_phase (query.c:302)
        by 0x48C5155: keySlotsReplyCallback (slots.c:590)
        by 0x48E86B7: valkeyClusterAsyncCallback (cluster.c:3053)
        by 0x48E1EE9: valkeyRunCallback (async.c:300)
        by 0x48E1EE9: valkeyProcessCallbacks (async.c:633)
        by 0x48C5034: valkeyLibuvPoll (libuv.h:54)
        by 0x4FA154C: uv__io_poll (linux.c:1546)
        by 0x4F8B9F1: uv_run (core.c:460)
        by 0x400A328: main_loop (server.c:921)
        by 0x40099F4: main (pmproxy.c:473)
      Address 0xffffffffffffffff is not stack'd, malloc'd or (recently) free'd
    
      Process terminating with default action of signal 11 (SIGSEGV)
    
    Co-assisted-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
    Signed-off-by: Renaud Métrich <rmetrich@redhat.com>

commit e7b4245089ca6b392486d1d43e3cdb4a102ac81e
Author: Renaud Métrich <rmetrich@redhat.com>
Date:   Thu Oct 1 10:36:49 2026 +0200

    libpcp_web: fix use-after-free in pmDiscover()
    
    When pmlogger logs are deleted, pmDiscoverFree() calls
    uv_fs_event_stop(p_old->event_handle) + free(p_old->event_handle) which
    led to writing to freed memory on callback execution, as demonstrated by
    valgrind's trace below:
    
    ~~~
    ==288259== Invalid write of size 8
    ==288259==    at 0x4F9BC0A: uv__queue_insert_tail (queue.h:81)
    ==288259==    by 0x4F9BC0A: uv_fs_event_init (linux.c:2658)
    ==288259==    by 0x48D5016: pmDiscoverMonitor.constprop.0.isra.0 (discover.c:535)
    ==288259==    by 0x48D5180: created_callback (discover.c:640)
    ==288259==    by 0x48D5180: created_callback (discover.c:621)
    ==288259==    by 0x48D536E: pmDiscoverTraverse (discover.c:199)
    ==288259==    by 0x48D536E: changed_callback (discover.c:2146)
    ==288259==    by 0x48D16AA: fs_change_callBack (discover.c:502)
    ==288259==    by 0x4F9CD91: uv__inotify_read.isra.0 (linux.c:2647)
    ==288259==    by 0x4F9D54C: uv__io_poll (linux.c:1546)
    ==288259==    by 0x4F879F1: uv_run (core.c:460)
    ==288259==    by 0x400A328: main_loop (server.c:921)
    ==288259==    by 0x40099F4: main (pmproxy.c:473)
    ==288259==  Address 0xa33ec40 is 32 bytes inside a block of size 136 free'd
    ==288259==    at 0x486EB7B: free (vg_replace_malloc.c:990)
    ==288259==    by 0x48D1192: pmDiscoverFree (discover.c:177)
    ==288259==    by 0x48D53FE: pmDiscoverPurgeDeleted (discover.c:251)
    ==288259==    by 0x48D53FE: changed_callback (discover.c:2156)
    ==288259==    by 0x48D16AA: fs_change_callBack (discover.c:502)
    ==288259==    by 0x4F9CD91: uv__inotify_read.isra.0 (linux.c:2647)
    ==288259==    by 0x4F9D54C: uv__io_poll (linux.c:1546)
    ==288259==    by 0x4F879F1: uv_run (core.c:460)
    ==288259==    by 0x400A328: main_loop (server.c:921)
    ==288259==    by 0x40099F4: main (pmproxy.c:473)
    ==288259==  Block was alloc'd at
    ==288259==    at 0x486B87E: malloc (vg_replace_malloc.c:447)
    ==288259==    by 0x48D4FEC: pmDiscoverMonitor.constprop.0.isra.0 (discover.c:529)
    ==288259==    by 0x48D5180: created_callback (discover.c:640)
    ==288259==    by 0x48D5180: created_callback (discover.c:621)
    ==288259==    by 0x48D536E: pmDiscoverTraverse (discover.c:199)
    ==288259==    by 0x48D536E: changed_callback (discover.c:2146)
    ==288259==    by 0x48D16AA: fs_change_callBack (discover.c:502)
    ==288259==    by 0x4F9CD91: uv__inotify_read.isra.0 (linux.c:2647)
    ==288259==    by 0x4F9D54C: uv__io_poll (linux.c:1546)
    ==288259==    by 0x4F879F1: uv_run (core.c:460)
    ==288259==    by 0x400A328: main_loop (server.c:921)
    ==288259==    by 0x40099F4: main (pmproxy.c:473)
    ~~~
    
    The fix consists in multiple parts:
    
    1. Purge before traverse in changed_callback()
    2. Stop freeing memory synchronously but through uv_close() callback
    3. Add a guard in pmDiscoverMonitor() to avoid freeing unconditionally
    
    Verified on RHEL10 with latest Upstream PCP code.
    
    ---
    
    Reproducer:
    
    1. Execute pmproxy under valgrind
    
      # valgrind --tool=memcheck --num-callers=20 --log-file=/tmp/pmproxy-use_after_free.log /usr/libexec/pcp/bin/pmproxy -F -A
    
    2. Execute reproducer consisting in creating fake pmlogger archives and deleting them
    
      LOGDIR=$(sudo -u pcp sh -c '. /etc/pcp.conf; echo $PCP_LOG_DIR')/pmlogger/$(hostname)
      echo "Churning archives in: $LOGDIR"
    
      for i in $(seq 1 100); do
          echo -n "."
          touch "${LOGDIR}/churn-test-${i}.0" \
                "${LOGDIR}/churn-test-${i}.meta" \
                "${LOGDIR}/churn-test-${i}.index"
          sleep 0.3
          rm -f "${LOGDIR}/churn-test-${i}.0" \
                "${LOGDIR}/churn-test-${i}.meta" \
                "${LOGDIR}/churn-test-${i}.index"
          sleep 0.3
      done
    
      After a few iterations the issue is detected by valgrind.
    
    Signed-off-by: Renaud Métrich <rmetrich@redhat.com>

commit ce18b50b524f08828e9a07e88da19a9a9a19e1fa
Author: Paul Evans <pevans@redhat.com>
Date:   Thu Oct 1 23:29:58 2026 +0100

    qa/1188: Update sysfs VDO stats output to include new metrics
    
    Update the sysfs backend VDO stats QA test output (1188.out) to
    take into account the added metrics from the libdevmapper backend
    introduction.

commit 2bf3d9b8d065862775286a40ff66293bd16d654b
Author: Sam Feifer <sfeifer@redhat.com>
Date:   Thu Oct 1 12:05:01 2026 -0400

    libpcp_web: fix duplicate keyMap typedef warning

commit ec98f7b4462a3ec78bf4eb5f1d9ede2cf5befc30
Merge: 92c8af80 2a278bd1
Author: Nathan Scott <nathans@redhat.com>
Date:   Thu Oct 1 10:19:00 2026 +1000

    Merge branch 'pauljevans-pevans-merge'

commit 92c8af802b462b766b33460617377a72305f7799
Merge: 0f4f9b69 4c7cf657
Author: Nathan Scott <nathans@redhat.com>
Date:   Thu Oct 1 09:57:35 2026 +1000

    Merge remote-tracking branch 'origin/series-gc'

commit 2a278bd109a239f800e695063592092732eaca80
Merge: 0f4f9b69 47511842
Author: Nathan Scott <nathans@redhat.com>
Date:   Thu Oct 1 09:56:46 2026 +1000

    Merge branch 'pevans-merge' of github.com:pauljevans/pcp into pauljevans-pevans-merge

commit 0f4f9b69cc2e75336b205c830b15c1f3f1283931
Merge: 99a5e4dd ec9c84e3
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Thu Oct 1 08:48:14 2026 +1000

    Merge pull request #2736 from tallpsmith/fix/macos-postinstall-account-order
    
    Fix/macos postinstall PCP account order

commit ec9c84e35d3a6babec15829f488bddb3e547a5bf
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 22:41:22 2026 +0000

    test-install-layout: fail when a package-installed runtime dir is missing
    
    pmlogger, pmie and pmproxy ship in the package, so absence is a defect.
    mmv and bash are created by their PMDA Install scripts, so they stay optional.

commit 59a8371972eaf846f54ae0b542de08b2403def2c
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 22:32:47 2026 +0000

    test-install-layout: check the primary link's pid is a pmlogger
    
    A stale link whose pid the OS reused for another process passed the old
    'is it running' check. Compare the process name, and reject non-numeric pids.

commit a7fb196963292b5fd8af0f3806a683639282325f
Merge: c3563b7f 99a5e4dd
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 22:29:51 2026 +0000

    Merge upstream/main into fix/macos-postinstall-account-order
    
    Keep both integration test groups: Test 27 (memory pressure) from main, Test 28 (installed layout) from this branch.

commit 99a5e4dd15aa434ff8501412a2dab24729cc3767
Merge: 5292b96f faa83c46
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Thu Oct 1 08:27:40 2026 +1000

    Merge pull request #2734 from tallpsmith/feature/darwin-memory-pressure
    
    src/pmdas/darwin: add mem.pressure.{level,state,available}

commit 5292b96f0ffdb8593fb9c404e3520b55ba0421e2
Merge: 7911500c 74b2f3bc
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 08:14:17 2026 +1000

    Merge pull request #2738 from kmcdonell/wip
    
    Package lists, build tweaks, QA fixups, pmGetOption() diagnostic rework in libpcp

commit 74b2f3bc197445829ea16bbc5b67791f76b469f9
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 07:36:53 2026 +1000

    qa/admin/myconfigure: reinstate configtools from debian/rules
    
    Was lost in the recent Makepkgs refactor.

commit afc77fdeb0a889b3a5ef48e3abb3a38fc9885e39
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 07:18:50 2026 +1000

    @coderabbitai suggested fixes for PR #2738
    
    Makepkgs and qa/admin/myconfigure: use ./Makepkgs.configopts for source stmt
    
    src/telnet-probe/telnet-probe.c: tweak argument checking logic and qa/589.out
            remake
    
    qa/1483 and qa/1620: fixups

commit a473c7cab6dd4b2af3a09d213a27c3330fe4d129
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 06:33:25 2026 +1000

    1620: remove -D args to pmlogger
    
    Did not help diagnose failure.
    
    Remade 1621.out as ordering of command line arguments also changed
    in an earlier commit.

commit fdbdebb1b78d3853a332d7afe5858da140831832
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 06:09:20 2026 +1000

    qa/344: another place where stdout and stderr need to be separated
    
    And remake 344.out.other (for non-Linux platforms).

commit 79478a179dd0a7508fa557a634db5d48e30dd5f0
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Thu Oct 1 06:03:11 2026 +1000

    src/libpcp/src/getopt.c: rework diagnostics in __pmStartOptions()
    
    Some of the options handling methods modify the value that is strdup'd
    from the environment ... move the diagnostics to report the value from the
    enviroment before any modification can happen.
    
    Backport this to libpcp3.
    
    Restore the "$@" argument expansion in qa/728.
    
    And remake qa/728.out and qa/1730.out.

commit 47511842fee2b828de8af29f04295af0f5fb2e8b
Author: Paul Evans <pevans@redhat.com>
Date:   Wed Sep 30 16:34:59 2026 +0100

    pmdadm: gate vdo backend diagnostic behind -Dappl0
    
    The vdo backend availability message was emitted unconditionally via
    pmNotifyErr() on every dm PMDA load, leaking to stderr and breaking
    unrelated QA tests (e.g. 1742). Gate both diagnostics behind
    pmDebugOptions.appl0 so they are silent by default, and update QA test
    2110 to pass -Dappl0 on its backend-detection probe.

commit 520822f3b54a54c97400e0924f0a995af61677b6
Merge: 83e08828 7911500c
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 16:51:00 2026 +1000

    Merge branch 'main' of https://github.com/performancecopilot/pcp

commit c3563b7feafc68b8677593c93d27a139027c4812
Merge: 09173722 7911500c
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 06:25:27 2026 +0000

    Merge remote-tracking branch 'origin/main' into fix/macos-postinstall-account-order
    
    # Conflicts:
    #       build/mac/test/integration/run-integration-tests.sh

commit faa83c466ea83d5e4b31a3c6bd7fe7a62df978f8
Merge: 2cfbd072 7911500c
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 06:25:10 2026 +0000

    Merge remote-tracking branch 'origin/main' into feature/darwin-memory-pressure
    
    # Conflicts:
    #       build/mac/test/integration/run-integration-tests.sh

commit 2cfbd072ef092d436071548d6635259b73088c54
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 06:21:11 2026 +0000

    src/pmdas/darwin: fetch mem.pressure.{level,available} via fetch_mempressure
    
    Direct metrictab pointers bypassed mach_mempressure_error, so a failed
    sysctl read returned a stale or zero level as a successful value while
    mem.pressure.state reported the error. A stuck level reads as "no
    pressure" to a pmie rule such as level >= 2. Route all three items
    through fetch_mempressure(), as thermal.pressure.* already are.

commit 7911500c63cfa7ad7cc81be2a08428cb77ab8e5e
Merge: 35ba55bc 123bd45d
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 16:17:20 2026 +1000

    Merge pull request #2733 from tallpsmith/fix/darwin-nprocs-nthreads
    
    Fix/darwin nprocs nthreads

commit 83e0882853cddbe5cfc57af912dd7a995b57d4d5
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 15:22:41 2026 +1000

    qa: assorted tests: if _get_config() fails make sure output is visible
    
        modified:   023
        modified:   115
        modified:   575
        modified:   1226
        modified:   1249
        modified:   1541
        modified:   1541.out

commit 09173722352404c2df5c85addbaeba04d54cb14e
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 05:12:19 2026 +0000

    build/mac: integration test for installed runtime directory ownership
    
    Checks that $PCP_TMP_DIR/{pmlogger,pmie,pmproxy,mmv,bash} are owned by
    pcp:pcp, as the GNUmakefiles install them, and that the primary pmlogger
    has registered its "primary" link. Both fail on a fresh install without
    the preceding postinstall fix (#2735).

commit 8a0af0acf65866ca4a8b9c17088d598602ec17ae
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 05:11:03 2026 +0000

    build/mac: create the pcp account before install-pcp runs
    
    install-pcp chowns every file to the owner in the idb, but postinstall
    created the pcp user and group only afterwards. On a fresh install each
    chown to pcp failed silently (_warn only prints under -v), so everything
    the idb wanted pcp-owned stayed root:root except the two trees re-owned
    by hand later. With $PCP_TMP_DIR/pmlogger root-owned, pmlogger cannot
    register and pmlogger_daily -K kills it every 30 minutes.
    
    Move account creation above install-pcp in postinstall and postupgrade.
    
    Fixes #2735.

commit 3ba406110054badc5481d27a5e5cc4444c53d947
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 15:03:07 2026 +1000

    qa/1620: tidy up last commit

commit 4fed5d409f795475a6c2ee3df569f638f7e7b85e
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 14:55:24 2026 +1000

    qa/1620: rework a bunch of things
    
    All trying to understand why if pmproxy is not running when
    the test starts, there is about a 1 in 200 chance (according to grind) that the QA
    pmproxy will be killed off too early.
    
    1. Explicit wait for $PCP_RUN_DIR/pmproxy.pid to appear
    2. added _triage_wait_point after pmproxy started
    3. make second group of metrics log every 250msec instead of 1sec
    4. drop (sleep ...; kill) in background and replace it with a shell
       script that keeps checking the archive until kernel.all.load
       has been logged and then kill off pmproxy
    5. turn on some diagnostics for pmlogger

commit 400e48cab87acd2ce241915af83f3268766b2129
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 14:53:27 2026 +1000

    qa/1222: add _need_metric proc.numa_maps.heap

commit 8e200657b3b3e4e291e2f9b4d9e98300ffe78e14
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 14:49:47 2026 +1000

    qa/common.bpftrace: fix ups
    
    1. in _pmdabpftrace_check() add check for tracefs being mounted
       (nothing good is going to happen without it) and mount it
       if needed
    
    2. in _pmdabpftrace_check_probes() don't re-define the exit trap
       as this may bypass other necessary cleanup() actions

commit 3381997c2d71e7269d0a89e8149a300556b68f41
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 14:46:31 2026 +1000

    qa/common.check: fix broken _get_config() for MX Linux
    
    Logic here was cut-n-pasted from elsewhere and not even close to being
    correct.  Only vm13 was suffering because everywhere else we have some
    other sort of "init" thingie in place.

commit 123bd45d50493a0ac9c842afe04a3a38a0f21273
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 00:37:56 2026 +0000

    src/pmdas/darwin: add kernel.limits.{maxthreads,maxtaskthreads}
    
    Expose the thread ceilings (kern.num_threads, kern.num_taskthreads)
    so thread usage can be read against its cap. kern.num_tasks is left
    out: kern.maxproc is lower and binds first, and is already
    kernel.limits.maxproc.

commit 2c5db307abc339fce14f885d4ff83cd3396eb7b4
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 00:37:56 2026 +0000

    src/pmdas/darwin: refresh limits cluster before fetching it
    
    kernel.limits.* and vfs.vnodes.recycled live in mach_vfs, which was
    only refreshed for CLUSTER_VFS. Fetched on their own from a fresh
    agent they reported 0 until some vfs metric was fetched first.

commit 48542161c8e4a8de1acee8b2a2adf029c0ef98af
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 00:36:49 2026 +0000

    src/pmdas/darwin: add mem.pressure.{level,state,available}
    
    The raw memory counters cannot reproduce the kernel's own pressure
    verdict, which weighs compressed and purgeable memory. Expose it
    directly: kern.memorystatus_vm_pressure_level (1/2/4, the level
    behind Activity Monitor's Memory Pressure graph), its name, and
    kern.memorystatus_level (memory_pressure(1)'s free percentage).
    
    New cluster 27, following the vfs.c template. New integration test
    compares each metric against its sysctl.

commit bd65393a87f2d7c9874093f0c9f35f9f828ab3fe
Author: Paul Smith <tallpsmith@gmail.com>
Date:   Wed Sep 30 00:16:05 2026 +0000

    src/pmdas/darwin: report live process and thread counts
    
    kernel.all.nprocs and kernel.all.nthreads read kern.num_tasks and
    kern.num_threads, which are the kernel's task and thread table
    limits, not counts - they reported 3072/15360 on a host running
    ~1050 processes and ~3400 threads.
    
    Take both from processor_set_statistics(PROCESSOR_SET_LOAD_INFO),
    the same source top(1) uses. New integration test compares each
    metric against ps(1) and top(1).

commit 4989777cbb33e82b0f9098ae74b8b257aa113f0d
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 07:24:58 2026 +1000

    qa/1483: filter out more noise from QA-related failures in logs

commit 436b2a2e325eb3cc0c87338a3dd9a3ac6f17a3e8
Merge: 758fb064 35ba55bc
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 30 05:54:15 2026 +1000

    Merge branch 'main' of https://github.com/performancecopilot/pcp

commit 758fb06400f7c2a4e5afe9609438d80e254a8b22
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 21:35:27 2026 +1000

    Makepkgs: refactor for common configure options settings
    
    Remove platform-specific configure options setting into
    one place (Makepkgs.configopts) and use this in Makepkgs
    and qa/admin/myconfigure.

commit 35ba55bc224aa1d4f736047820eaac96470143d0
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Sep 29 14:39:31 2026 +1000

    qa: rework test 728 valgrind variant 1730 filtering

commit 4c7cf657cabff583b0f89dd5a88f10ae0514f635
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Sep 29 13:28:58 2026 +1000

    pmseries, libpcp_web: fix series GC review issues

commit 324021bfb29ddea848b708377e55721f819d88db
Author: lmchilton <lauren.chilton26@gmail.com>
Date:   Thu Jul 23 15:55:53 2026 -0400

    created QA test 1790

commit 129a90c469a8fe1143ff080876c000ce4dc0a542
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Apr 28 06:49:31 2026 +1000

    pmseries, libpcp_web: add --gc mode to remove expired series data
    
    Metric time series data expires via the pcp:values:series: stream TTL
    (stream.expire, default 86400s), but the ~10 ancillary keys per series
    (pcp:desc:series:, pcp:series:metric.name:, pcp:series:label.*.value:,
    etc.) accumulated indefinitely, causing unbounded key server growth.
    
    Add pmSeriesGC() to libpcp_web and a --gc / --dryrun mode to pmseries
    that scans pcp:desc:series:* for all known series, checks whether each
    stream is still alive, and for stale series removes:
    
      - pcp:desc:series:H, pcp:metric.name:series:H
      - pcp:instances:series:H, pcp:labelvalue:series:H, pcp:labelflags:series:H
      - membership in pcp:series:metric.name:*, pcp:series:inst.name:*,
        pcp:series:label.<name>.value:*, pcp:series:context.name:*
      - orphaned pcp:inst:series:* hashes when their inst-name set empties
    
    All key server operations are fully async using the existing
    baton/callback infrastructure.  Three new pmproxy MMV metrics track GC
    activity: series.gc.calls, series.gc.scanned, series.gc.cleaned.
    
    Output uses the standard info callback so results appear on stdout for
    the CLI and in the pmproxy log when invoked from a timer.
    
    Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

commit 7829847ec130aa61fae899d9d196677d199fba97
Merge: 61b56bf0 3fb0aab5
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Sep 29 12:07:12 2026 +1000

    Merge branches 'pauljevans-dm-vdo-updates' and 'db2-feedback'

commit 61b56bf08cbfa355d3141f0dfd06f908f880aabe
Merge: 9ef1ddf1 13ce3a47
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Sep 29 12:06:46 2026 +1000

    Merge branch 'dm-vdo-updates' of https://github.com/pauljevans/pcp into pauljevans-dm-vdo-updates

commit 9ef1ddf1ec49b2ca991fbb7700cea7cb73c4d01a
Merge: 62984b3c d13afe36
Author: Nathan Scott <natoscott@users.noreply.github.com>
Date:   Tue Sep 29 11:56:54 2026 +1000

    Merge pull request #2732 from performancecopilot/dependabot/github_actions/github/codeql-action-4.38.2
    
    build(deps): bump github/codeql-action from 4.38.1 to 4.38.2

commit 4aaef70d7257f33479c2a8eb9bd8be5be14af935
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 11:46:26 2026 +1000

    qa/540: remove repeated lines in output
    
    Comes from cross platform difference in stdio buffer management and state
    across fork() and exec().
    
    Was failing on vm04 (CentOS 8.5).

commit d13afe36580ec911750a681a8e35c721a83fdbbb
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Mon Sep 28 22:34:49 2026 +0000

    build(deps): bump github/codeql-action from 4.38.1 to 4.38.2
    
    Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.38.1 to 4.38.2.
    - [Release notes](https://github.com/github/codeql-action/releases)
    - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
    - [Commits](https://github.com/github/codeql-action/compare/v4.38.1...v4.38.2)
    
    ---
    updated-dependencies:
    - dependency-name: github/codeql-action
      dependency-version: 4.38.2
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>

commit 4715ef791a1d40fee5d7a0e6d0c929525a60ff6e
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 08:32:01 2026 +1000

    src/procmemstat/.gitignore: add executable

commit 29174dfddcb834d67869be85e1d2eebc58c8821a
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 08:30:34 2026 +1000

    src/selinux/have-interface: (new) helper script
    
    To determine if a policy interface is defined in the local build
    environment.

commit 9f571e1b022cb3bbdd484f84f475867a2dbab1bb
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 08:10:04 2026 +1000

    src/telnet-probe/telnet-probe.c: tweak argument parsing
    
    And remade qa/589.out.

commit 4adf314b5444b862e69c5f1a6ccaf97c9a2b2879
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 29 08:04:50 2026 +1000

    Debian builds: disable selinux
    
    The build has started failing on bozo (Ubuntu 26.04) because our
    .te policy files use "interfaces" that are not known in the Debian
    world ... it is unclear why this has just suddenly happened.
    
    Rather than polluting the .te files with:
        ifdef(`foo',`
            bar
        ')
    I've opted to not build any SELinux components when Debian packaging
    is being used.
    
    The rationale is that AppArmor is the solution in this space for
    Debian and SELinux and AppArmor can never co-exist.

commit 13ce3a4799111014bd6a63ab16929187572ee55c
Author: Paul Evans <pevans@redhat.com>
Date:   Fri Sep 25 11:07:57 2026 +0100

    pmdadm: collect VDO stats via the device-mapper message backend
    
    The out-of-tree kvdo module exposed VDO statistics under /sys/kvdo, but
    in-tree dm-vdo (kernel 6.9 and later) removed that sysfs tree, so the dm
    PMDA's VDO metrics returned no values on modern kernels.
    
    Add a second collection backend that issues the device-mapper "stats"
    message to each vdo target and parses the response with libdevmapper's
    dm_vdo_stats_parse() (libdm >= 1.02.214). The new backend is preferred
    when configure finds a new enough version of libdm but can fall back to
    the legacy /sys/kvdo backend if the sysfs tree exists and has valid
    VDO volume information (newer libdm but older kernel). The existing
    sysfs code path is unchanged.
    
    Support is gated at build time by a new HAVE_DM_VDO_STATS autoconf link
    test (separate from the existing HAVE_DEVMAPPER), when the version of
    libdm is too old the PMDA builds as before with the sysfs backend only.
    
    Added 15 new dm-vdo metrics which are new to the libdm collection
    pathway. QA  test 2110 has been added to exercise the new libdm message
    backend from a captured stats response, this test skips when the PMDA was
    built without the libdm message-backend support.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

commit 3fb0aab579e6c5f3d677e367a3b00a9be449ab0c
Author: Nathan Scott <nathans@redhat.com>
Date:   Mon Sep 28 18:20:03 2026 +1000

    pmdadb2: use documented activity counter

commit 532a1dd7c04717242923443138a3ae25f30f5708
Author: Nathan Scott <nathans@redhat.com>
Date:   Mon Sep 28 18:11:01 2026 +1000

    pmdadb2: add activity wait and completion metrics

commit 62984b3c86426fbc22fcd289f7cacb5a29f441bb
Merge: d425970d eaa3b6c8
Author: Nathan Scott <natoscott@users.noreply.github.com>
Date:   Mon Sep 28 16:24:29 2026 +1000

    Merge pull request #2724 from performancecopilot/dependabot/github_actions/github/codeql-action-4.38.1
    
    Bump github/codeql-action from 4.37.9 to 4.38.1

commit afe74149e1b008d430f81cca7788f795830de42f
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Mon Sep 28 08:30:15 2026 +1000

    qa/1705: BPFTRACE_MAX_PROBES=512 no longer working
    
    Setting the environment variable has no effect on version 0.26 of
    bpftrace (on openSUSE Tumbleweed).  Instead you need to craft a
    
        config = {
            max_probes = 512
        }
    
    stanza in the probe script.  This is the preferred approach for
    versions of bpftrace at 0.23 or later.

commit fa776e5b0984d9e1571a1c8bd43b9ba97221fe58
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Mon Sep 28 08:23:08 2026 +1000

    lio PMDA - Python packagers cannot agree on submodule naming
    
    historically it has been rtslib_fb.utils and then along comes
    openSUSE Tumbleweed (may be others, this is just the first one
    I've triaged) and the module is really called rtslib.utils here.
    
    Need conditional try: goo in the PMDA and better module checking
    in qa/1061.

commit ab72ebe7e93dc48e38e043f11026cb88bf3439fd
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Mon Sep 28 08:19:55 2026 +1000

    bpftrace PMDA won't build on CentOS 7.9 - disable via configure for vm08
    
    Made this vm08-specific (rather than in the spec file), as I believe this
    is the only place where we're still building for CentOS 7.

commit a02b23f6ac28d1df2129bf55180a4051453313f7
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sun Sep 27 06:33:32 2026 +1000

    qa/198: relace memory growth limit for sampledso PMDA
    
    This is a DSO, so we're really measuring memory growth for
    pmcd and all DSO PMDAs.

commit a0baeeddbe4797e3c2ea51ad29bde42e93e7bfba
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sun Sep 27 06:30:41 2026 +1000

    qa/1491: tweak filter
    
    When rc scripts are expected to be in /etc.init.d but are not present for
    particular PMDA because it is not packaged, there are two potential error
    messages from pmcheck that need to be filtered.

commit ee766830b3fc7d64aa2949665595c6d5b69f60de
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sun Sep 27 06:28:15 2026 +1000

    qa/344: take control of stdout and stderr

commit e1bf4d9959aca15c5558acfff8fd743104da5fe8
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sun Sep 27 06:26:01 2026 +1000

    qa/check.callback.sample: dodge AVCs from AppArmor but leave AVCs from SELinux
    
    We're only interested in any new SELinux ones from running a QA test.

commit 5a287c2ac1d00227415dd2dd4f914966c572310f
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sat Sep 26 06:26:47 2026 +1000

    package list and scripts update
    
    - openSUSE
    - Ubuntu 24.04

commit 5a6895df675be3f2afdce8bf5eaad10f46b48678
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Sat Sep 26 06:25:32 2026 +1000

    qa/admin/post-setup: improve guard checking if ufw is the active firewall

commit d425970d0bbaa7cc39909a1be962a8a24fad071e
Author: Jan Kurik <jkurik@redhat.com>
Date:   Thu Sep 24 09:38:34 2026 +0200

    pmdapostgresql: validate configuration before install or remove
    
    Fail with a clear error when required authentication settings remain
    commented out in the shipped configuration template. Update the man page
    to document the required configuration and correct stale setting names.
    
    Resolves: RHEL-183368

commit 449ed906df4d7ddc1e3e9b0baa31872b1e849e3c
Author: Jan Kurik <jkurik@redhat.com>
Date:   Tue Sep 22 11:49:17 2026 +0200

    Doc: added description of pmlogger authentication to remote pmcd
    
    Resolves: RHEL-140595

commit 465777cb0fe8679f5d21441d69f3d24e306c7b92
Author: Sam Feifer <sfeifer@redhat.com>
Date:   Wed Sep 23 14:36:03 2026 -0400

    pmproxy: fix SIGSEGV when pmseries setup hits an unsupported key server

commit 91a95fa137e9824a9adc86439478ade288b0d615
Merge: fb2e875c 4c14432f
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 17:52:01 2026 +1000

    Merge pull request #2726 from kmcdonell/wip
    
    QA Fixups

commit 4c14432fe6d4d901dd5202fea73efc532e35b66d
Merge: 0018e845 6c2078d6
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 16:21:48 2026 +1000

    Merge branch 'wip' of https://github.com/kmcdonell/pcp into wip

commit 0018e84544ef0998f59713f1c4abf4989f56d9da
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 16:20:53 2026 +1000

    small changes suggested by @coderabbitai for PR #2726

commit 6c2078d6773a250fbb99b4f0b68d276fb90ffe7d
Merge: d5b28a7e fb2e875c
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 12:11:41 2026 +1000

    Merge branch 'performancecopilot:main' into wip

commit d5b28a7e09bc69645c48d7d5f95bdacdffb61eeb
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 12:10:27 2026 +1000

    qa/admin/pcp-daily: some VMs are slow to boot

commit 20ca66fd6eb6276fc43797b07dac28339dacc6a5
Merge: 16eab819 b793576a
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 12:10:13 2026 +1000

    Merge branch 'main' into wip

commit 16eab819735d7ece523886718f181a4b46063173
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 12:09:40 2026 +1000

    qa/admin/package-lists/openSUSE+15.6+x86_64: package list update

commit b793576a9f3ea65da56055da30b90ea60a1c9406
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Sep 23 11:08:37 2026 +1000

    qa/381 & 2109: small diagnostic additions

commit fb2e875c12c4afa2fc24f91100ee28e4a9e08dc1
Merge: c98aa546 7ee9a010
Author: Lauren Chilton <86691983+lmchilton@users.noreply.github.com>
Date:   Tue Sep 22 11:03:21 2026 -0400

    Merge pull request #2676 from lmchilton/openscanhub-revisions
    
    pcp2openmetrics & pcp2opentelemetry revisions

commit 50bbb02e01797b2ff126d15907787abe51aa0d10
Merge: c52eef61 c98aa546
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 21:24:32 2026 +1000

    Merge branch 'main' of https://github.com/performancecopilot/pcp

commit c52eef613a8843b8f73d533e9e0ca76fd2f82c92
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 21:23:16 2026 +1000

    qa/2109: more diagnostics and add -s option to pmproxy execution
    
    Still not working on vm01, but this is helping the triage.

commit 708736293f1cf9ee1c858b9ce833cb6170f33144
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 21:22:16 2026 +1000

    qa/589: filter tweak and remade .out after telenet-probe change

commit 19963c1b8029c3e85eec7b3ed80a68868d2abd5a
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 21:21:08 2026 +1000

    qa/common.check: add -v (verbose) option for _find_free_port()

commit 92e51efcab16262891772721d0304bbd5da635c8
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 17:14:43 2026 +1000

    src/telnet-probe/telnet-probe.c: convert to use pmGetOptions()
    
    Mostly so I can use -D ...

commit dcbf8283373ae2c0f3e87b19a5ce46c7c3f29398
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 17:14:18 2026 +1000

    src/libpcp/src/install-dev: small improvement to diagnostic message

commit f221658a2d1f8321061be2498655a4b83aa4f751
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 17:12:04 2026 +1000

    libpcp_web: add pkgconf support
    
    Seems to have been overlooked ... cloned from libpcp_archive
    pc.in file and makefile rules.

commit c98aa5464a9aab7bc389b3b6ca95ff63c9ba4566
Merge: d45580af 862ae222
Author: Nathan Scott <nathans@redhat.com>
Date:   Tue Sep 22 11:58:53 2026 +1000

    Merge branch 'bpftrace-build-dep'

commit eaa3b6c888f0ed41477f35f932403883e05c0f28
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date:   Mon Sep 21 22:34:32 2026 +0000

    Bump github/codeql-action from 4.37.9 to 4.38.1
    
    Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.9 to 4.38.1.
    - [Release notes](https://github.com/github/codeql-action/releases)
    - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
    - [Commits](https://github.com/github/codeql-action/compare/v4.37.9...v4.38.1)
    
    ---
    updated-dependencies:
    - dependency-name: github/codeql-action
      dependency-version: 4.38.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>

commit 4d328e3b0cfc79c330ec288d30b4a63b11c8bceb
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Sep 22 07:52:18 2026 +1000

    qa/1485 and 1487: remade after tmpfs.* metrics were fixed
Created: 2026-05-23 Last update: 2026-10-04 21:02
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • pcp-doc could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2026-10-05 08:30
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-16524: (needs triaging) A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: (needs triaging) A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: (needs triaging) An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: (needs triaging) A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: (needs triaging) A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: (needs triaging) An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-30 Last update: 2026-09-01 22:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-08-14 03:18
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for pcp (- to 7.2.1-2): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ New but not reproduced on amd64 - info: pcp-testsuite
    • ∙ ∙ New but not reproduced on arm64 - info: pcp, pcp-testsuite
    • ∙ ∙ New but not reproduced on armhf - info: pcp, pcp-testsuite
    • ∙ ∙ New but not reproduced on i386 - info: pcp, pcp-testsuite
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/p/pcp.html
    • ∙ ∙ 52 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-08-30] pcp REMOVED from testing (Debian testing watch)
  • [2026-08-16] pcp 7.2.1-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-14] Accepted pcp 7.2.1-2 (source) into unstable (Nathan Scott)
  • [2026-08-01] pcp 7.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-30] Accepted pcp 7.2.0-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2026-05-29] pcp 7.1.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-26] Accepted pcp 7.1.5-1 (source) into unstable (Nathan Scott)
  • [2026-05-25] pcp 7.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-22] Accepted pcp 7.1.4-1 (source) into unstable (Nathan Scott)
  • [2026-05-02] Accepted pcp 7.1.3-2 (source) into unstable (Nathan Scott)
  • [2026-04-27] pcp 7.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-24] Accepted pcp 7.1.2-1 (source) into unstable (Nathan Scott)
  • [2026-04-02] pcp 7.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-30] Accepted pcp 7.1.1-1 (source) into unstable (Nathan Scott)
  • [2026-01-30] pcp 7.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-28] Accepted pcp 7.1.0-1 (source) into unstable (Nathan Scott)
  • [2025-12-05] pcp 7.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-21] Accepted pcp 7.0.5-1 (source) into unstable (Nathan Scott)
  • [2025-11-19] Accepted pcp 7.0.4-1 (source) into unstable (Nathan Scott)
  • [2025-11-12] Accepted pcp 7.0.3-1 (source arm64 all) into unstable (Nathan Scott)
  • [2025-11-01] pcp REMOVED from testing (Debian testing watch)
  • [2025-10-16] Accepted pcp 7.0.2-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-09-23] Accepted pcp 7.0.1-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-09-01] Accepted pcp 7.0.0-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-04-21] pcp 6.3.8-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-11] Accepted pcp 6.3.8-1 (source) into unstable (Nathan Scott)
  • [2025-04-07] pcp 6.3.7-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-28] Accepted pcp 6.3.7-1 (source) into unstable (Nathan Scott)
  • [2025-03-17] Accepted pcp 6.3.6-1 (source) into unstable (Nathan Scott)
  • [2025-03-15] Accepted pcp 6.3.5-1 (source) into unstable (Nathan Scott)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (2, 10)
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 7.2.1-2build1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing