[OpenNMS/opennms] 345d45: Update base image

mershad-manesh via opennms-cvs <[email protected]>
Newsgroups gmane.network.opennms.cvs
Message-ID <OpenNMS/opennms/push/refs/heads/merge-foundation/release-36.x-to-develop/[email protected]>
  Branch: refs/heads/merge-foundation/release-36.x-to-develop
  Home:   https://github.com/OpenNMS/opennms
  Commit: 345d4513c20fc2b7c60ce900b5b73a2eeffa4ced
      https://github.com/OpenNMS/opennms/commit/345d4513c20fc2b7c60ce900b5b73a2eeffa4ced
  Author: Morteza E <[email protected]>
  Date:   2026-08-04 (Tue, 04 Aug 2026)

  Changed paths:
    M opennms-container/common.mk
    M opennms-container/core/Dockerfile
    M opennms-container/minion/Dockerfile
    M opennms-container/sentinel/Dockerfile
    M smoke-test/src/main/java/org/opennms/smoketest/containers/MockCloudContainer.java

  Log Message:
  -----------
  Update base image


  Commit: 15857256fd475ed6486c967f5c9e4ae04753a492
      https://github.com/OpenNMS/opennms/commit/15857256fd475ed6486c967f5c9e4ae04753a492
  Author: Morteza E <[email protected]>
  Date:   2026-08-04 (Tue, 04 Aug 2026)

  Changed paths:
    M opennms-container/common.mk
    M opennms-container/core/Dockerfile
    M opennms-container/minion/Dockerfile
    M opennms-container/sentinel/Dockerfile
    M smoke-test/src/main/java/org/opennms/smoketest/containers/MockCloudContainer.java

  Log Message:
  -----------
  Update base image


  Commit: 2c65a22ece8f04fc94bf238f2003ddd37f5b22d6
      https://github.com/OpenNMS/opennms/commit/2c65a22ece8f04fc94bf238f2003ddd37f5b22d6
  Author: joseanesONMS <[email protected]>
  Date:   2026-08-04 (Tue, 04 Aug 2026)

  Changed paths:
    M ui/package.json
    M ui/pnpm-lock.yaml
    M ui/src/components/Resources/Graph.vue
    M ui/src/components/Resources/Graphs.vue
    A ui/src/components/Resources/utils/graphExport.ts
    M ui/src/composables/useDownload.ts
    A ui/tests/resourceGraphExport.test.ts
    A ui/tests/resourceGraphPdfExport.test.ts

  Log Message:
  -----------
  NMS-20153: CSV and PDF export for Resource Graphs (#8733)


  Commit: 19e0ef0974a7aa46c9f833594a7e6c1bb52401dd
      https://github.com/OpenNMS/opennms/commit/19e0ef0974a7aa46c9f833594a7e6c1bb52401dd
  Author: Scott Theleman <[email protected]>
  Date:   2026-08-04 (Tue, 04 Aug 2026)

  Changed paths:
    M .circleci/main/jobs/build/build-ui.yml

  Log Message:
  -----------
  NMS-20159: Run pnpm lint in CI for UI builds (#8739)


  Commit: d361c17677477314374224afc50585d7404aae4a
      https://github.com/OpenNMS/opennms/commit/d361c17677477314374224afc50585d7404aae4a
  Author: Christian Pape <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M container/karaf/pom.xml
    M container/karaf/src/main/internal/features-processing.xml
    M container/shared/pom.xml
    M container/shared/src/main/internal/features-processing.xml
    M features/minion/repository/pom.xml
    M features/sentinel/repository/pom.xml
    M opennms-full-assembly/pom.xml
    M opennms-full-assembly/src/assembly/components/osgi.xml
    M pom.xml

  Log Message:
  -----------
  NMS-20061: Use jline version 3.30.16


  Commit: cd5d20e369d0fe8f974e2d41d9de21983c3751fd
      https://github.com/OpenNMS/opennms/commit/cd5d20e369d0fe8f974e2d41d9de21983c3751fd
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M container/karaf/pom.xml
    M container/karaf/src/main/internal/features-processing.xml
    M container/shared/pom.xml
    M container/shared/src/main/internal/features-processing.xml
    M features/minion/repository/pom.xml
    M opennms-container/common.mk
    M opennms-container/core/Dockerfile
    M opennms-container/minion/Dockerfile
    M opennms-container/sentinel/Dockerfile
    M opennms-full-assembly/pom.xml
    M opennms-full-assembly/src/assembly/components/osgi.xml
    M pom.xml
    M smoke-test/src/main/java/org/opennms/smoketest/containers/MockCloudContainer.java

  Log Message:
  -----------
  Merge remote-tracking branch 'origin/foundation-2024' into foundation-2025


  Commit: fff0738688944c1733cc775c2faf494eb7a67d7b
      https://github.com/OpenNMS/opennms/commit/fff0738688944c1733cc775c2faf494eb7a67d7b
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/main/workflows/workflows_v2.json
    M .circleci/pyscripts/library/cci_components/workflow.py

  Log Message:
  -----------
  remove deprecated regex


  Commit: e4a5322fc43938fcc49e1c3d65961483dab11a3e
      https://github.com/OpenNMS/opennms/commit/e4a5322fc43938fcc49e1c3d65961483dab11a3e
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/main/jobs/publish.yml
    M .circleci/main/workflows/workflows_v2.json

  Log Message:
  -----------
  re-enable publishing images to Dockerhub


  Commit: 34d3f0a048a317a4c76e589acda275afb3d1e9fb
      https://github.com/OpenNMS/opennms/commit/34d3f0a048a317a4c76e589acda275afb3d1e9fb
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/epoch

  Log Message:
  -----------
  force a build


  Commit: 0431c2c2666b60f8f46b3f6071718dcd5f771350
      https://github.com/OpenNMS/opennms/commit/0431c2c2666b60f8f46b3f6071718dcd5f771350
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M container/karaf/pom.xml
    M container/karaf/src/main/internal/features-processing.xml
    M container/shared/pom.xml
    M container/shared/src/main/internal/features-processing.xml
    M features/minion/repository/pom.xml
    M opennms-full-assembly/pom.xml
    M opennms-full-assembly/src/assembly/components/osgi.xml
    M pom.xml

  Log Message:
  -----------
  Merge remote-tracking branch 'origin/foundation-2025' into release-36.x


  Commit: f73af2fa771f8df12b4a226cf8f9e7975f6a806a
      https://github.com/OpenNMS/opennms/commit/f73af2fa771f8df12b4a226cf8f9e7975f6a806a
  Author: joseanesONMS <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M ui/packages/onms-ui/src/components/OnmsAutoComplete.vue
    M ui/tests/onms-ui/OnmsAutoComplete.test.ts

  Log Message:
  -----------
  NMS-20029: forward the #option slot in OnmsAutoComplete (#8742)


  Commit: 3dde578d02fe18ff07befd48175f8ad5632351c4
      https://github.com/OpenNMS/opennms/commit/3dde578d02fe18ff07befd48175f8ad5632351c4
  Author: mershad-manesh <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/config.yml

  Log Message:
  -----------
  Pin CirlceCI CLI to version 0.1.38646


  Commit: b1b77d7ad68bd7d0ad1afbaf294f035968db42ee
      https://github.com/OpenNMS/opennms/commit/b1b77d7ad68bd7d0ad1afbaf294f035968db42ee
  Author: mershad-manesh <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/epoch

  Log Message:
  -----------
  Update epoch


  Commit: 7342905636cdde8c2f04c385f5f9bdac43d5beb7
      https://github.com/OpenNMS/opennms/commit/7342905636cdde8c2f04c385f5f9bdac43d5beb7
  Author: Scott Theleman <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M ui/src/components/Menu/SideMenu.vue
    M ui/src/components/Menu/utils.ts
    M ui/tests/components/Menu/utils.test.ts

  Log Message:
  -----------
  NMS-20167: Sidemenu flicker, expand/collapse hotkey (#8749)

* NMS-20167: Remove menu flyout on mouse hover. Add tooltips for collapsed menu items.

* NMS-20167: Use Ctrl-Backslash to expand/collapse side menu.

* NMS-20167: Fixes

Stale flyout on Ctrl+\ toggle
Disable Ctrl+\ hotkey when typing / in an input/edit field
Fix comment wrapping


  Commit: 6c445ae6c327120986085fa07be7141036575d4e
      https://github.com/OpenNMS/opennms/commit/6c445ae6c327120986085fa07be7141036575d4e
  Author: Marshall Massengill <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M container/features/pom.xml
    M container/features/src/main/resources/features-core.xml
    M container/features/src/main/resources/features.xml
    M container/karaf/src/main/filtered-resources/etc/custom.properties
    A dependencies/angus-mail-shaded/pom.xml
    M dependencies/cxf/pom.xml
    R dependencies/javamail/pom.xml
    R dependencies/javamail/src/license/THIRD-PARTY.properties
    M dependencies/jaxb/pom.xml
    M dependencies/pom.xml
    M docs/modules/operation/pages/deep-dive/admin/configuration/token-authentication.adoc
    M docs/modules/operation/pages/deep-dive/meta-data.adoc
    M docs/modules/operation/pages/deep-dive/notifications/configuration.adoc
    M docs/modules/reference/pages/daemons/daemon-config-files/notifd.adoc
    M docs/modules/reference/pages/service-assurance/monitors/MailTransportMonitor.adoc
    M docs/modules/releasenotes/pages/whatsnew.adoc
    M features/poller/monitors/core/pom.xml
    M features/poller/monitors/core/src/main/java/org/opennms/netmgt/poller/monitors/MailTransportMonitor.java
    M features/wsman/pom.xml
    M opennms-ackd/pom.xml
    M opennms-ackd/src/main/java/org/opennms/netmgt/ackd/readers/MailAckProcessor.java
    M opennms-ackd/src/test/java/org/opennms/netmgt/ackd/readers/JavaMailAckReaderIT.java
    M opennms-base-assembly/pom.xml
    M opennms-base-assembly/src/main/filtered/bin/newts-repository-converter
    M opennms-base-assembly/src/main/filtered/etc/examples/javamail-configuration.properties
    M opennms-base-assembly/src/main/filtered/etc/javamail-configuration.properties
    M opennms-base-assembly/src/main/filtered/etc/javamail-configuration.xml
    A opennms-config/src/main/java/org/opennms/netmgt/config/tokenauth/TokenScope.java
    M opennms-config/src/main/resources/META-INF/opennms/applicationContext-token-auth.xml
    A opennms-config/src/test/java/org/opennms/netmgt/config/tokenauth/TokenScopeTest.java
    M opennms-enterprise-reporting/opennms-reportd/pom.xml
    M opennms-enterprise-reporting/opennms-reportd/src/main/java/org/opennms/netmgt/reporting/service/JavaMailDeliveryService.java
    M opennms-javamail/opennms-javamail-api/pom.xml
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailer.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailer2.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailerConfig.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaReadMailer.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaSendMailer.java
    A opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerConfigTokenTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerTest.java
    A opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerWireTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaReadMailerTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaSendMailerTest.java
    M opennms-services/pom.xml
    M opennms-web-api/pom.xml
    M opennms-web-api/src/main/java/org/opennms/web/svclayer/support/DefaultSchedulerService.java
    M opennms-web-dependencies/pom.xml
    M opennms-webapp-rest/pom.xml
    M pom.xml

  Log Message:
  -----------
  NMS-20102: Migrate all mail sending/reading from JavaMail 1.4.7 to Jakarta Mail 2.1 (Part of rework JavaMailNotificationStrategy) (#8701)

* NMS-20102: Jakarta Mail 2.1 build plumbing and MOXy javax.mail shim

Adds dependencyManagement for jakarta.mail-api 2.1.5, angus-mail 2.0.5,
angus-activation 2.0.3, and bumps jakarta.activation-api to 2.1.4 (the
jakarta-namespace line needed by angus; javax-namespace activation
classes continue to come from com.sun.activation:jakarta.activation
1.2.1, which opennms-webapp-rest now references directly).

EclipseLink MOXy 2.5.1 hard-references javax.mail.internet.MimeMultipart
from XMLBinaryDataHelper's initializer, so a javax.mail-namespace API
must stay on the classpath after the jakarta migration. jaxb-dependencies
switches from javax.mail:mail 1.4.7 to com.sun.mail:mailapi 1.6.7: API
classes only, no transport providers, and a distinct Maven GA so it
cannot collide with jakarta.mail-api 2.1.x under dependencyConvergence.
The Karaf javax.mail feature repoints to the jakarta.mail-api 1.6.7
bundle, matching the copy CXF's cxf-specs feature already installs.

* NMS-20102: Remove the jmta local-MTA transport

alt.dev.jmta:jmta:1.0 (2004) subclasses javax.mail.Transport and cannot
load under Jakarta Mail 2.x. The use-jmta attribute and the useJMTA
property remain accepted so existing configuration files keep loading;
JavaMailer now logs a one-time WARN and sends via the configured
transport instead. On the JavaSendMailer path use-jmta was already
inert: the transport always came from sendmail-protocol@transport,
which the schema restricts to smtp|smtps, so the removed "mta" branch
there was unreachable. Shipped defaults change to use-jmta="false".

Behavior change for installs that relied on the local MTA transport:
mail now goes over SMTP to the configured sendmail host (default
127.0.0.1:25) instead of through the in-process JMTA class.

* NMS-20102: Migrate mail code to Jakarta Mail 2.1 / Eclipse Angus

Renames javax.mail.* to jakarta.mail.* and javax.activation.* to
jakarta.activation.* across the mail senders/readers (opennms-javamail,
ackd, poller MailTransportMonitor, reportd, web-api) and their tests.
opennms-javamail-api now depends on jakarta.mail-api with angus-mail
and angus-activation as runtime providers, flowing transitively to all
consumers; direct importers declare jakarta.mail-api explicitly.

Spring 4.2.9's MimeMessageHelper is compiled against javax.mail, so
JavaSendMailer.buildMimeMessage() and reportd's JavaMailDeliveryService
build their MIME messages directly (same structure: single-part message
for sendmail, mixed multipart with a plain/HTML alternative and the
report attachment for reportd). This also drops opennms-javamail-api's
mandatory org.springframework.mail.javamail OSGi import.

Container: new jakarta.mail Karaf feature (API + Angus bundles at the
system start level); the opennms-javamail feature uses it; the
javax.mail feature remains for the MOXy shim consumers. custom.properties
exports the jakarta.mail/jakarta.activation packages from the flat
classpath. The wsman bundle marks jakarta.mail optional: it accidentally
embeds poller-monitors-core's whole org.opennms.netmgt.poller.monitors
package (split package with WsManMonitor), and the unused embedded
MailTransportMonitor copy is where its mail import comes from.

* NMS-20102: Ban javax.mail:mail and legacy mail spec jars

Inverts the enforcer rule that required javax.mail:mail: the banned list
now covers javax.mail:mail, com.sun.mail:javax.mail/jakarta.mail, the
merged org.eclipse.angus:jakarta.mail artifact (would duplicate the
API + angus-mail classes), and geronimo-javamail_1.4_spec, which reached
$OPENNMS_HOME/lib undeclared through abdera-parser/axiom and is now
excluded at its source in cxf-dependencies. com.sun.mail:mailapi remains
allowed as the MOXy shim.

Also fixes the newts-repository-converter activation-jar glob, which
matched nothing (lib/jdk9plus ships the servicemix activation-api jar,
not javax.activation-*.jar).

* NMS-20102: Wire JavaSendMailer's built properties into its Session

createProps() assembled <javamail-property> entries and the computed
mail.smtp.* keys, then returned the JVM-default session's properties
instead ("//get rid of this"), so none of it ever reached the Session;
configureProperties() additionally merged everything into a local
variable that went nowhere. The Session now receives the merged set:
javamail-configuration.properties (only when useJmProps=true, matching
the constructor contract), overlaid by <javamail-property> entries,
with computed keys filled in only where absent so user values win.
Session-property-driven features - mail.smtp.auth.mechanisms=XOAUTH2
in particular - become usable on the XML config path.

Applied property names are logged at INFO on session creation since
previously-inert <javamail-property> entries in existing configuration
files take effect on upgrade.

Also assigns the parent JavaMailer2 session, which reportd reads via
getSession() and previously received as null.

* NMS-20102: Resolve ${token:<name>} in mail credentials for XOAUTH2

Adds TokenScope, a mate Scope over the token-auth TokenProvider under
the "token" context, registered in the token-auth application context.
JavaMailerConfig now interpolates credentials against a FallbackScope
of the SCV scope and the token scope, each independently optional, so
${token:<name>} works wherever ${scv:...} already did: the
authenticateUser/authenticatePassword properties and the XML
user-auth fields (both resolved at connect time, so tokens are always
fresh via the token cache).

With Angus providing the XOAUTH2 SASL mechanism natively, OAuth2 SMTP
(Microsoft 365 client-credentials, Gmail) needs only configuration:
a token-auth definition for the provider's token endpoint, plus
authenticate=true, mail.smtp.auth.mechanisms=XOAUTH2, and
${token:<name>} as the password. No mail-code OAuth client required.

The token scope resolves per interpolation (no caching in the scope) -
covered by tests asserting fetch-per-call semantics.

* NMS-20102: Add wire-level mail tests (GreenMail + fake-SMTP XOAUTH2)

The mail code had no non-manual wire coverage: every send/receive test
was @Ignore'd against real servers. JavaMailerWireTest runs the actual
Angus SMTP/IMAP providers against an embedded GreenMail 2.x on dynamic
ports: plain send, authenticated send, JavaSendMailer end-to-end from a
SendmailConfig (locks in the createProps fix), and JavaReadMailer over
IMAP.

XOAUTH2 is asserted byte-level against a minimal in-test SMTP server,
since GreenMail doesn't implement that SASL mechanism: the client must
emit AUTH XOAUTH2 with base64("user=<u>\x01auth=Bearer <token>\x01\x01"),
which is the exact string Microsoft 365 and Gmail validate.

greenmail excludes org.eclipse.angus:jakarta.mail (the banned merged
API+impl jar); the split artifacts provide the same classes. The tests
set mail.smtp timeouts so protocol mismatches fail in seconds instead
of hanging the build.

* NMS-20102: Document XOAUTH2 mail authentication and migration notes

Adds a worked Microsoft 365 client-credentials example to the token
authentication page (token-auth block plus both the properties-file and
javamail-configuration.xml recipes), references the token context from
the notifd config-file table and the metadata DSL page, and comments the
XOAUTH2 pattern in the shipped javamail-configuration.properties.

Release notes cover the Jakarta Mail migration and its three upgrade
notes: checkserveridentity now defaults to true on SSL/TLS connections,
use-jmta is accepted but inert, and <javamail-property> entries take
effect on the sendmail path.

* NMS-20102: Apply adversarial-review findings

Code fixes:
- angus-mail on the flat classpath is replaced by angus-mail-shaded,
  which strips META-INF/mailcap and META-INF/javamail(.default).providers.
  Those javax-era resource names list jakarta-namespace classes, and the
  javax.activation command map reads them from every jar: with
  com.sun.activation as the javax impl, a text/plain DataHandler lookup
  fails outright (reproduced), taking down unrelated javax consumers.
  The jakarta runtime keeps working via META-INF/jakarta.mailcap and
  ServiceLoader, both retained; Karaf features keep vanilla angus-mail
  (bundle isolation makes the resources harmless there).
- reportd attachments carry their real MIME type again (PDF/CSV/XLS
  registered on the data source); a bare FileDataSource labeled every
  report application/octet-stream.
- JavaSendMailer only advertises mail.smtp(s).auth=true when a user-auth
  is actually configured; use-authentication="true" without credentials
  kept sending unauthenticated before the session properties became
  real, and now warns instead of failing the connect.
- transport 'mta' (still possible via the unvalidated properties file)
  maps to smtp with a warning instead of NoSuchProviderException; the
  removed-JMTA warning is per-mailer instead of once per JVM.
- TokenScope resolves to empty (WARN) on token-provider failures so a
  transient token-endpoint outage cannot abort mailer construction.
- JavaMailerConfig.getProperties is no longer synchronized: credential
  interpolation may fetch an OAuth token over HTTP, and the class
  monitor serialized every mail path in the JVM on that request.
- custom.properties additionally exports jakarta.activation.spi, so
  angus-activation wires both packages to the same provider.

Tests: XOAUTH2 wire test now drives the full documented composition
(${token:name} in javamail-configuration.properties resolved through
the token scope to the Bearer token on the wire); new authenticated
JavaSendMailer wire test; fake SMTP thread is a daemon; JavaSendMailer
wire tests set mail timeouts via <javamail-property>; test scope/system
property state is restored after each class.

Docs: metadata page no longer suggests readmail-config credentials
interpolate (they do not); XOAUTH2 mechanism line documented as
required rather than advisory; M365 prerequisites include the mailbox
permission grant; release notes cover the provider-less javax.mail API
(third-party plugins) and MailTransportMonitor sendmail-test behavior;
MailTransportMonitor reference page marks use-jmta deprecated; shipped
and example properties files carry the XOAUTH2 recipe with a
duplicate-key note.

* NMS-20102: Address Copilot review feedback

JavaSendMailer.buildMimeMessage() parses the to address with
InternetAddress.parse(to, false), matching JavaMailer, so
comma-separated recipient lists in sendmail-message work; the previous
single-address constructor matched the old MimeMessageHelper behavior
but diverged from the rest of the module. Wire test now sends to two
recipients. Also drops the duplicated mail.smtp.quitwait defaulting
block (pre-existing) and restores the opennms.home system property
after each JavaMailerWireTest.

* NMS-20102: Keep the message body on streamed mail attachments

JavaMailer.buildMessage() has two attachment branches: the file branch
builds a multipart with the message text followed by the attachment,
while the stream branch (added in 1dfc6c9e481, 2010) added only the
attachment part. Callers that set an input stream therefore lost the
message text entirely -- DefaultReportWrapperService sets both, so every
emailed database report arrived as a bare PDF or CSV with no body.

The stream branch now adds the text part first, matching the file
branch. Covered by a GreenMail wire test asserting both parts and their
order; the test fails on the previous behavior with one part instead of
two.

Pre-existing on release-36.x and unrelated to the Jakarta migration,
folded in here since this is the mail rework.

* NMS-20102: Document mail server TLS certificate verification

Angus enforces certificate trust and host-name verification
independently, and mail.smtp.ssl.trust suppresses only the first --
including when set to "*", the conventional workaround for self-signed
certificates. Installations carrying it therefore still fail
host-name verification after the upgrade, which the release note did
not convey.

Adds a Mail server TLS section to the notification configuration page
covering both properties, the two distinct failure messages, and which
property applies to each; the release note is trimmed to the behavior
change and points there. Verified against a STARTTLS server presenting
a certificate for a different name.

* NMS-20102: Trim the Jakarta Mail release note

Condense the whatsnew entry to the changes an upgrader has to act on and
push the detail to the notifications and token-authentication pages.
Also drop the note about readmail-config not supporting metadata
expressions, which does not belong in the list of what does.


  Commit: fe0cc01c0c813722dadfb1f53ac45138c1c0027e
      https://github.com/OpenNMS/opennms/commit/fe0cc01c0c813722dadfb1f53ac45138c1c0027e
  Author: Scott Theleman <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M ui/src/components/Menu/SideMenu.vue
    M ui/src/theme/primevue-setup.ts
    A ui/tests/components/Menu/SideMenu.test.ts

  Log Message:
  -----------
  NMS-20171: Fix various SideMenu issues (#8751)


  Commit: 589c655b262efc5226b971e80706f6ba09f26dba
      https://github.com/OpenNMS/opennms/commit/589c655b262efc5226b971e80706f6ba09f26dba
  Author: Scott Theleman <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    A ui/CLAUDE.md

  Log Message:
  -----------
  NMS-20173: Add ui/CLAUDE.md documenting UI conventions for Claude Code (#8752)


  Commit: d94d2e6ee87dbebf2b12df1581099710ead893a5
      https://github.com/OpenNMS/opennms/commit/d94d2e6ee87dbebf2b12df1581099710ead893a5
  Author: Chandra Gorantla <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M container/features/src/main/resources/features.xml
    M container/karaf/src/main/filtered-resources/etc/custom.properties
    M core/daemon/pom.xml
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Invoker.java
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Manager.java
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Starter.java
    A core/daemon/src/main/java/org/opennms/netmgt/vmmgr/StartupLifecycleHook.java
    M docs/modules/operation/nav.adoc
    A docs/modules/operation/pages/deep-dive/admin/high-availability.adoc
    M docs/modules/reference/pages/karaf-shell/karaf-shell.adoc
    M features/events/syslog/src/test/java/org/opennms/netmgt/syslogd/SyslogMessageTest.java
    A features/ha-management/ha-api/pom.xml
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaConfiguration.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaInstanceState.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaMode.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaRole.java
    A features/ha-management/ha-daemon/pom.xml
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/DbConnectionFactory.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaConfigSyncer.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaHeartbeatWriter.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStartupCoordinator.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStartupLifecycleHook.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStatusSchema.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaSyncFiles.java
    A features/ha-management/ha-daemon/src/main/resources/META-INF/services/org.opennms.netmgt.vmmgr.StartupLifecycleHook
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/DbConnectionFactoryTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaConfigSyncerTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaStartupCoordinatorTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaStartupLifecycleHookTest.java
    A features/ha-management/ha-rest/pom.xml
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/HaRestService.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/dto/HaInstanceStatusDto.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/dto/HaStatusCollectionDto.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/impl/HaRestServiceImpl.java
    A features/ha-management/ha-rest/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    A features/ha-management/ha-shell/pom.xml
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaConfigCommand.java
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaFailoverCommand.java
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaStatusCommand.java
    A features/ha-management/pom.xml
    M features/pom.xml
    M opennms-base-assembly/pom.xml
    A opennms-base-assembly/src/main/filtered-meridian/etc/ha-configuration.xml
    M opennms-base-assembly/src/main/filtered/etc/opennms.service
    M opennms-full-assembly/pom.xml
    M opennms-webapp/src/main/webapp/WEB-INF/applicationContext-spring-security.xml

  Log Message:
  -----------
  NMS-20109: Active/passive HA for OpenNMS core (#8700)

* WIP; testing

(cherry picked from commit 99ab08c00edc9df5453e7f3c90b3fe62a456d527)

* WIP

(cherry picked from commit b81400fbf988a99bf2512d8b2512ea365c23de14)

* test and iterate, test and iterate, test and

(cherry picked from commit 203bf32e3b4cbba44e2117f11f7d4593effadf36)

* WIP

(cherry picked from commit 853cf8a9ec43f42814304754d047ea887eefc236)

* don't rely on local clock

(cherry picked from commit 7b39e322211f2b90905e2d7a0a97fa1a17c0de55)

* periodically re-read the ha-configuration.xml sow e can change values on the fly

(cherry picked from commit d04e0a9f0b7a52919f5f19f8b32c847faecf70ca)

* skip syncing files in examples/ dir

(cherry picked from commit a98638e6d45c78f75315461cc59c62997c37c2f1)

* rest and shell refinements, correct some log messages

(cherry picked from commit 77b60c30a44409184ebfea73204366b451b5a208)

* Fixups for the config shell command

(cherry picked from commit e7bc80fce5b76c37fb7d2fb974972fbdb4995682)

* terminate immediately on split-brain detected instead of manager shutdown

(cherry picked from commit 5f54bea669cbe69c67bbb578e94a66837aaa6d6d)

* split-brain improvements; add active_since timestamp for tracking who became active when, and expose that value in both karaf shell and in ha rest api.

(cherry picked from commit 726f4cad4f4deae0b806af35cebdcc9acc7897bd)

* Convert to ShellTable for niceness

(cherry picked from commit 2b0ef35822c4f3747aace4ddbc015c812e37047d)

* NMS-20109: Make HA management an optional feature

- Create ha_instance_status from the coordinator at startup (advisory-lock
  serialized, includes agent_last_seen) instead of the core Liquibase
  changelog
- Write only last_heartbeat from the heartbeat cycle; state columns change
  on transitions only
- Add <mode>heartbeat-only</mode>: an external supervisor owns the state
  machine and OpenNMS only publishes liveness, never gating startup
- Move the HA REST endpoints out of opennms-webapp-rest into the ha-rest
  OSGi whiteboard bundle; enforce authorization via Spring Security
  intercept-urls
- Replace the filesystem-API config sync with a binary manifest transfer
  (sha256 diff, atomic apply, deletion propagation, sync-excludes); the
  hasync account no longer needs ROLE_FILESYSTEM_EDITOR

* NMS-20109: Handle some corner cases

Fail-closed startup
Partner check before claiming ACTIVE
No assume-inactive-on-error

* NMS-20109: Fail closed on HA config errors and harden sync path handling

- Abort startup instead of proceeding standalone when the HA config is
  unreadable, required fields are missing, or coordination throws;
  coordinator mode now requires a distinct partner-instance-id (enforced
  at load, REST update, and reload)
- Clamp failover-threshold to at least 2x the heartbeat interval and
  enforce a minimum sync interval before scheduling
- Suppress config sync in heartbeat-only mode, including config reloads
- Halt the JVM when failover cannot stop services after the step-down
  is advertised, instead of running on undetectable
- Config sync: support the ${scv:alias:attr|default} fallback syntax and
  resolve credentials via the stock vault (honors the configured keystore
  type); advertise the serving node's exclusions in the manifest and use
  the union of both nodes' lists for deletion propagation; canonicalize
  paths before exclusion matching; reject symlink escapes from etc/ and
  skip symlinks when building manifests; re-check HA state before every
  file write and deletion so a mid-cycle promotion aborts the pass
- Copy mode and sync-excludes in the ha-config shell command
- Use subtree intercept-url patterns for /rest/ha so trailing-slash
  variants keep requiring ROLE_ADMIN
- Document featuresBoot.d feature activation in the config template

* NMS-20109: Publish HA state after shutdown completes; lifecycle SPI

- Defer the STANDBY/FAILED row write until the service Invoker has
  finished stopping, so the partner can never promote alongside a node
  that is still draining; a hung drain falls back to heartbeat staleness
  at the failover threshold. The split-brain yield keeps its immediate
  write since the halt is instantaneous.
- Arbitrate split-brain only against a partner whose heartbeat is within
  the failover threshold: an ACTIVE row with a dead heartbeat means the
  partner stopped while holding the role, so the survivor continues as
  the sole active instance instead of halting in deference to it.
- Replace the reflective HA hooks in Starter and Manager with a
  StartupLifecycleHook SPI discovered via ServiceLoader; ha-daemon
  registers the implementation, and its absence is a no-op.
- Clarify the sync-excludes example in the config template.

* NMS-20109: Add docs for HA feature

* NMS-20109: Bound JDBC reads, mask sync password, unify heartbeat task

* NMS-20109: Survive status signals while gated; heartbeat through the drain

- register the SIGUSR1 status handler before the startup gate can block,
  so "opennms status" no longer kills a waiting standby; an empty status
  file is written when no services exist yet
- keep the heartbeat publishing liveness until the terminal state is
  written post-drain: the partner promotes on the state write, never on
  staleness beside a still-draining node (a hung drain is escalated by
  the service manager's stop timeout)
- promote when the partner row stays missing beyond the failover
  threshold instead of waiting forever
- serialize config-sync passes so a reschedule cannot overlap a
  still-running pass

* NMS-20109 : Update docs

* Restart in systemd unit and note in docs

* Fix conditional in nav while I'm here

* NMS-20109: Read partner identity once per monitor cycle

- Snapshot partner-instance-id in each monitor path so a cycle reasons about
  one partner throughout; a change during the anti-flap wait now restarts the
  verification instead of concluding about a different node.
- Reset the missing-row timer when partner-instance-id changes, so a new
  partner gets the full threshold before its absence counts toward promotion.
- Invoke the Manager MBean on the platform server instead of the first entry
  of MBeanServerFactory.findMBeanServer(null), whose ordering is unspecified;
  a miss would turn a planned failover into an immediate halt.
- Do not serve sync files through symlinks, which could otherwise alias an
  excluded file; manifests never advertise them.
- Cancel the superseded monitor and sync tasks before releasing the startup
  gate on promotion.

* NMS-20109: Report heartbeat staleness separately from role and state

- Rename the derived status flag from "degraded" to heartbeat-stale (STALE in
  the shell table) and compute it from heartbeat age alone. It also flagged a
  SECONDARY holding ACTIVE and the DEGRADED state, so both rows read
  DEGRADED=YES after a healthy failover, which reads as total failure.
- Align the class defaults with the shipped template — failover threshold 60s,
  sync interval 60s — and name the enforced minimums in the javadoc.

* NMS-20109: Handle some more edge case and docs

 - Manifest self-identification (#ha-manifest 1) refusing unmarked responses before any fetch or delete
 - partner-rest-url restart-only, with tests on both the REST and reload paths
 - Template defaults to https, plus a WARN when sync runs over http
 - Loud ERROR when a node's own status row has vanished
 - ROLE_REST dropped from the template, javadoc, and docs; this comment condensed
 - Docs: STANDBY vs DEGRADED distinction, automatic return as DEGRADED with a restart policy, and systemctl stop for maintenance

* Fix unrelated bug in syslog tests

* NMS-20109: Update docs on second node installation

---------

Co-authored-by: Dino <[email protected]>


  Commit: 886a143d1994b1b5925d66acd557aa50e38d6106
      https://github.com/OpenNMS/opennms/commit/886a143d1994b1b5925d66acd557aa50e38d6106
  Author: Morteza E <[email protected]>
  Date:   2026-08-05 (Wed, 05 Aug 2026)

  Changed paths:
    M .circleci/config.yml
    M .circleci/main/jobs/build/build-ui.yml
    M container/features/pom.xml
    M container/features/src/main/resources/features-core.xml
    M container/features/src/main/resources/features.xml
    M container/karaf/pom.xml
    M container/karaf/src/main/filtered-resources/etc/custom.properties
    M container/karaf/src/main/internal/features-processing.xml
    M container/shared/pom.xml
    M container/shared/src/main/internal/features-processing.xml
    M core/daemon/pom.xml
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Invoker.java
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Manager.java
    M core/daemon/src/main/java/org/opennms/netmgt/vmmgr/Starter.java
    A core/daemon/src/main/java/org/opennms/netmgt/vmmgr/StartupLifecycleHook.java
    A dependencies/angus-mail-shaded/pom.xml
    M dependencies/cxf/pom.xml
    R dependencies/javamail/pom.xml
    R dependencies/javamail/src/license/THIRD-PARTY.properties
    M dependencies/jaxb/pom.xml
    M dependencies/pom.xml
    M docs/modules/operation/nav.adoc
    M docs/modules/operation/pages/deep-dive/admin/configuration/token-authentication.adoc
    A docs/modules/operation/pages/deep-dive/admin/high-availability.adoc
    M docs/modules/operation/pages/deep-dive/meta-data.adoc
    M docs/modules/operation/pages/deep-dive/notifications/configuration.adoc
    M docs/modules/reference/pages/daemons/daemon-config-files/notifd.adoc
    M docs/modules/reference/pages/karaf-shell/karaf-shell.adoc
    M docs/modules/reference/pages/service-assurance/monitors/MailTransportMonitor.adoc
    M docs/modules/releasenotes/pages/whatsnew.adoc
    M features/events/syslog/src/test/java/org/opennms/netmgt/syslogd/SyslogMessageTest.java
    A features/ha-management/ha-api/pom.xml
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaConfiguration.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaInstanceState.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaMode.java
    A features/ha-management/ha-api/src/main/java/org/opennms/netmgt/ha/HaRole.java
    A features/ha-management/ha-daemon/pom.xml
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/DbConnectionFactory.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaConfigSyncer.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaHeartbeatWriter.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStartupCoordinator.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStartupLifecycleHook.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaStatusSchema.java
    A features/ha-management/ha-daemon/src/main/java/org/opennms/netmgt/ha/HaSyncFiles.java
    A features/ha-management/ha-daemon/src/main/resources/META-INF/services/org.opennms.netmgt.vmmgr.StartupLifecycleHook
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/DbConnectionFactoryTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaConfigSyncerTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaStartupCoordinatorTest.java
    A features/ha-management/ha-daemon/src/test/java/org/opennms/netmgt/ha/HaStartupLifecycleHookTest.java
    A features/ha-management/ha-rest/pom.xml
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/HaRestService.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/dto/HaInstanceStatusDto.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/dto/HaStatusCollectionDto.java
    A features/ha-management/ha-rest/src/main/java/org/opennms/netmgt/ha/rest/impl/HaRestServiceImpl.java
    A features/ha-management/ha-rest/src/main/resources/OSGI-INF/blueprint/blueprint.xml
    A features/ha-management/ha-shell/pom.xml
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaConfigCommand.java
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaFailoverCommand.java
    A features/ha-management/ha-shell/src/main/java/org/opennms/netmgt/ha/shell/HaStatusCommand.java
    A features/ha-management/pom.xml
    M features/minion/repository/pom.xml
    M features/poller/monitors/core/pom.xml
    M features/poller/monitors/core/src/main/java/org/opennms/netmgt/poller/monitors/MailTransportMonitor.java
    M features/pom.xml
    M features/wsman/pom.xml
    M opennms-ackd/pom.xml
    M opennms-ackd/src/main/java/org/opennms/netmgt/ackd/readers/MailAckProcessor.java
    M opennms-ackd/src/test/java/org/opennms/netmgt/ackd/readers/JavaMailAckReaderIT.java
    M opennms-base-assembly/pom.xml
    A opennms-base-assembly/src/main/filtered-meridian/etc/ha-configuration.xml
    M opennms-base-assembly/src/main/filtered/bin/newts-repository-converter
    M opennms-base-assembly/src/main/filtered/etc/examples/javamail-configuration.properties
    M opennms-base-assembly/src/main/filtered/etc/javamail-configuration.properties
    M opennms-base-assembly/src/main/filtered/etc/javamail-configuration.xml
    M opennms-base-assembly/src/main/filtered/etc/opennms.service
    A opennms-config/src/main/java/org/opennms/netmgt/config/tokenauth/TokenScope.java
    M opennms-config/src/main/resources/META-INF/opennms/applicationContext-token-auth.xml
    A opennms-config/src/test/java/org/opennms/netmgt/config/tokenauth/TokenScopeTest.java
    M opennms-container/common.mk
    M opennms-container/core/Dockerfile
    M opennms-container/minion/Dockerfile
    M opennms-container/sentinel/Dockerfile
    M opennms-enterprise-reporting/opennms-reportd/pom.xml
    M opennms-enterprise-reporting/opennms-reportd/src/main/java/org/opennms/netmgt/reporting/service/JavaMailDeliveryService.java
    M opennms-full-assembly/pom.xml
    M opennms-full-assembly/src/assembly/components/osgi.xml
    M opennms-javamail/opennms-javamail-api/pom.xml
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailer.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailer2.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaMailerConfig.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaReadMailer.java
    M opennms-javamail/opennms-javamail-api/src/main/java/org/opennms/javamail/JavaSendMailer.java
    A opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerConfigTokenTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerTest.java
    A opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaMailerWireTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaReadMailerTest.java
    M opennms-javamail/opennms-javamail-api/src/test/java/org/opennms/javamail/JavaSendMailerTest.java
    M opennms-services/pom.xml
    M opennms-web-api/pom.xml
    M opennms-web-api/src/main/java/org/opennms/web/svclayer/support/DefaultSchedulerService.java
    M opennms-web-dependencies/pom.xml
    M opennms-webapp-rest/pom.xml
    M opennms-webapp/src/main/webapp/WEB-INF/applicationContext-spring-security.xml
    M pom.xml
    M smoke-test/src/main/java/org/opennms/smoketest/containers/MockCloudContainer.java
    A ui/CLAUDE.md
    M ui/packages/onms-ui/src/components/OnmsAutoComplete.vue
    M ui/src/components/Menu/SideMenu.vue
    M ui/src/components/Menu/utils.ts
    M ui/src/theme/primevue-setup.ts
    A ui/tests/components/Menu/SideMenu.test.ts
    M ui/tests/components/Menu/utils.test.ts
    M ui/tests/onms-ui/OnmsAutoComplete.test.ts

  Log Message:
  -----------
  Merge remote-tracking branch 'origin/release-36.x' into develop


Compare: https://github.com/OpenNMS/opennms/compare/d51aaed8694e...886a143d1994

To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications


_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list

To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.