{"old": "/home/jenkins/agent/workspace/multiarch/src-openeuler/aarch64/AcTrail/old_rpms/", "new": "/home/jenkins/agent/workspace/multiarch/src-openeuler/aarch64/AcTrail/new_rpms/", "compare_result": "not pass", "compare_details": {"same": {"same_details": {"old": [], "new": []}, "same_num": 0}, "diff": {"diff_details": {"AcTrail": {"name": {"old": "AcTrail-0.7.2-1.oe2609.aarch64.rpm", "new": "AcTrail-0.7.2-2.oe2609.aarch64.rpm"}, "RPM Level": "level4", "rpm requires": {"more": ["/bin/sh"]}, "rpm provides": {}, "rpm files": {"more": ["/etc/actrail", "/var/lib/actrail/export", "/var/log/actrail", "/usr/share/actrail", "/usr/share/doc/AcTrail/security-file-permissions.md", "/var/lib/actrail"]}, "rpm cmd": {}, "rpm symbol": {}}}, "diff_num": 1}, "less": {"less_details": {}, "less_num": 0}, "more": {"more_details": {}, "more_num": 0}}, "pr_link": "https://gitcode.com/src-openeuler/AcTrail/pull/6", "pr_changelog": "* Sun Sep 20 2026 donglihao <donglihao1@huawei.com> - 0.7.2-2\n- fix(tls-sync) harden plan cache, align probe points, and fix response pairing\n- fix(payload) attribute HTTP/1 messages to the segment that carried their head\n- fix(daemon) resolve root host pid for --root-pid trace selectors\n- fix(daemon) keep serving when the control socket runs out of descriptors\n- fix(ctl,daemon) make control errors actionable and daemon logs observable\n- fix(daemon,config,view) harden runtime artifacts and root pid reporting\n- Enforce the file permission profile on installed program files (550),\n  plugin configuration files (640), and runtime directories (750)\n- Harden runtime artifact creation: daemon umask 0027, pid file 0600, and\n  explicit modes for the log, configuration, SQLite, export, and temporary\n  files, with tighten-on-start for directories an earlier release left wide\n- Document the file permission profile in docs/security-file-permissions.md\n- fix(daemon,config) log in local time\n- fix(daemon,config) reject runtime path collisions\n- feat(otel) correlate agent identities with executables\n- feat(otel) resolve the agent product from the observed executable\n- fix(daemon,config,tls-sync) close issue review findings: verify the daemon\n  executable identity by device/inode with a full-path fallback, resolve\n  shared-library paths independently, pin permission targets with O_NOFOLLOW,\n  and reject config/registry runtime path collisions\n"}