Packages changed: Mesa (21.2.2 -> 21.2.3) Mesa-drivers (21.2.2 -> 21.2.3) audit (3.0.3 -> 3.0.5) audit-secondary (3.0.3 -> 3.0.5) blog (2.20 -> 2.21) btrfsprogs (5.14 -> 5.14.1) codec2 (1.0.0 -> 1.0.1) crypto-policies (20210225.05203d2 -> 20210917.c9d86d1) desktop-file-utils diffutils dracut (055+suse.117.ge5fc2048 -> 055+suse.119.g6c4187af) ffmpeg-4 fuse-overlayfs (1.4.0 -> 1.7.1) gamin gcc gd iio-sensor-proxy (3.1 -> 3.3) kernel-firmware (20210901 -> 20210928) knewstuff libinput (1.19.0 -> 1.19.1) libmtp (1.1.18 -> 1.1.19) libnss_usrfiles libsoup libsrtp2 (2.4.1 -> 2.4.2) libva mozjs78 (78.13.0 -> 78.14.0) open-iscsi openSUSE-build-key perl-libwww-perl (6.56 -> 6.57) portaudio (190600_20161030 -> 190700_20210406) rav1e selinux-policy systemd sysvinit (2.99 -> 3.00) tdb (1.4.3 -> 1.4.4) tevent (0.10.2 -> 0.11.0) xrdb xwayland === Details === ==== Mesa ==== Version update (21.2.2 -> 21.2.3) Subpackages: Mesa-libEGL1 Mesa-libGL1 Mesa-libglapi0 libgbm1 - update to 21.2.3 * third bugfix release ==== Mesa-drivers ==== Version update (21.2.2 -> 21.2.3) Subpackages: Mesa-dri Mesa-gallium - update to 21.2.3 * third bugfix release ==== audit ==== Version update (3.0.3 -> 3.0.5) Subpackages: libaudit1 libauparse0 - Update to version 3.0.5: * In auditd, flush uid/gid caches when user/group added/deleted/modified * Fixed various issues when dealing with corrupted logs * In auditd, check if log_file is valid before closing handle - Include fixed from 3.0.4: * Apply performance speedups to auparse library * Optimize rule loading in auditctl * Fix an auparse memory leak caused by glibc-2.33 by replacing realpath * Update syscall table to the 5.14 kernel * Fixed various issues when dealing with corrupted logs ==== audit-secondary ==== Version update (3.0.3 -> 3.0.5) Subpackages: audit python3-audit system-group-audit - Fix hardened auditd.service (bsc#1181400) * add fix-hardened-service.patch Make /etc/audit read-write from the service. Remove PrivateDevices=true to expose /dev/* to auditd.service. - Enable stop rules for audit.service (cf. bsc#1190227) * add enable-stop-rules.patch - Change default log_format from ENRICHED to RAW (bsc#1190500): * add change-default-log_format.patch (SUSE-specific patch) - Update to version 3.0.5: * In auditd, flush uid/gid caches when user/group added/deleted/modified * Fixed various issues when dealing with corrupted logs * In auditd, check if log_file is valid before closing handle - Include fixed from 3.0.4: * Apply performance speedups to auparse library * Optimize rule loading in auditctl * Fix an auparse memory leak caused by glibc-2.33 by replacing realpath * Update syscall table to the 5.14 kernel * Fixed various issues when dealing with corrupted logs ==== blog ==== Version update (2.20 -> 2.21) Subpackages: libblogger2 - Move to /usr for UsrMerge (boo#1191057) ==== btrfsprogs ==== Version update (5.14 -> 5.14.1) Subpackages: btrfsprogs-udev-rules libbtrfs0 - Update to 5.14.1 * fixes: * defrag: fix parsing of compression (option -c) * add workaround for old kernels when reading zone sizes * let only check and restore open the fs with transid failures, namely preventing btrfstune to do so * convert: --uuid copy does not fail on duplicate uuids ==== codec2 ==== Version update (1.0.0 -> 1.0.1) - Update to version 1.0.1: * Release to support freedv-gui 1.6.1 ==== crypto-policies ==== Version update (20210225.05203d2 -> 20210917.c9d86d1) - Remove the scripts and documentation regarding fips-finish-install and test-fips-setup * Add crypto-policies-FIPS.patch - Update to version 20210917.c9d86d1: * openssl: fix disabling ChaCha20 * pacify pylint 2.11: use format strings * pacify pylint 2.11: specify explicit encoding * fix minor things found by new pylint * update-crypto-policies: --check against regenerated * update-crypto-policies: fix --check's walking order * policygenerators/gnutls: revert disabling DTLS0.9... * policygenerators/java: add javasystem backend * LEGACY: bump 1023 key size to 1024 * cryptopolicies: fix 'and' in deprecation warnings * *ssh: condition ecdh-sha2-nistp384 on SECP384R1 * nss: hopefully the last fix for nss sigalgs check * cryptopolicies: Python 3.10 compatibility * nss: postponing check + testing at least something * Rename 'policy modules' to 'subpolicies' * validation.rules: fix a missing word in error * cryptopolicies: raise errors right after warnings * update-crypto-policies: capitalize warnings * cryptopolicies: syntax-precheck scope errors * .gitlab-ci.yml, Makefile: enable codespell * all: fix several typos * docs: don't leave zero TLS/DTLS protocols on * openssl: separate TLS/DTLS MinProtocol/MaxProtocol * alg_lists: order protocols new-to-old for consistency * alg_lists: max_{d,}tls_version * update-crypto-policies: fix pregenerated + local.d * openssh: allow validation with pre-8.5 * .gitlab-ci.yml: run commit-range against upstream * openssh: Use the new name for PubkeyAcceptedKeyTypes * sha1_in_dnssec: deprecate * .gitlab-ci.yml: test commit ranges * FIPS:OSPP: sign = -*-SHA2-224 * scoped policies: documentation update * scoped policies: use new features to the fullest... * scoped policies: rewrite + minimal policy changes * scoped policies: rewrite preparations * nss: postponing the version check again, to 3.64 - Remove patches fixed upstream: crypto-policies-typos.patch - Rebase: crypto-policies-test_supported_modules_only.patch - Merge crypto-policies-asciidoc.patch into crypto-policies-no-build-manpages.patch ==== desktop-file-utils ==== - suse-update-mime-defaults: add Pantheon desktop environment ==== diffutils ==== - Skip stack overflow tests under qemu emulation (bsc#1190046) ==== dracut ==== Version update (055+suse.117.ge5fc2048 -> 055+suse.119.g6c4187af) Subpackages: dracut-ima dracut-mkinitrd-deprecated - Update to version 055+suse.119.g6c4187af: * fix(suse-initrd): handle cases with zero modprobe.d files (bsc#1189895) ==== ffmpeg-4 ==== Subpackages: libavcodec58_134 libavformat58_76 libavutil56_70 libswresample3_9 - Add ffmpeg-CVE-2020-22037.patch: Backport from upstream to fix denial of service vulnerability exists due to a memory leak in avcodec_alloc_context3 at options.c (bsc#1186756). ==== fuse-overlayfs ==== Version update (1.4.0 -> 1.7.1) - Update to version 1.7.1 * set FUSE_CAP_POSIX_ACL only when it is supported by FUSE. * treat statx failure with EINVAL as ENOSYS, so that the fallback is attempted. - Update to version 1.7.0 * fix read xattrs for device files * don't create whiteout files in opaque dirs. * fix reading files when running with euid != 0. * enable POSIX ACLs. - Update to version 1.6.0 * fix an invalid access when filtering internal xattrs that could deal to a segfault. - Update to version 1.5.0 * honor FUSE_OVERLAYFS_DISABLE_OVL_WHITEOUT also for renames * use strncpy instead of strcpy * fix renameat2(RENAME_NOREPLACE) on older kernels that lack device whiteouts for unprivileged users. * fix creating a symlink on top of a removed file. * fix copyup of xattrs longer than 256 bytes. ==== gamin ==== - Fix source URI. ==== gcc ==== - Move /lib/cpp to /usr/lib/cpp for the usr merge. [bsc#1191060] ==== gd ==== - reenable gd/gd2 legacy formats, was disabled by upstream by default [bsc#1190762] ==== iio-sensor-proxy ==== Version update (3.1 -> 3.3) - Update to version 3.3: * Fix a bug left-over in one of the 3.2 bug fixes where some accelerometers would fail to initialise. - Changes from version 3.2: * Fix problems parsing numbers with decimal separator. - Require gudev >= 237 for building (for consistency with upstream). - Drop the rpmlintrc file and add back appropriate service macros in pre/post scriptlets. ==== kernel-firmware ==== Version update (20210901 -> 20210928) Subpackages: kernel-firmware-all kernel-firmware-amdgpu kernel-firmware-ath10k kernel-firmware-ath11k kernel-firmware-atheros kernel-firmware-bluetooth kernel-firmware-bnx2 kernel-firmware-brcm kernel-firmware-chelsio kernel-firmware-dpaa2 kernel-firmware-i915 kernel-firmware-intel kernel-firmware-iwlwifi kernel-firmware-liquidio kernel-firmware-marvell kernel-firmware-media kernel-firmware-mediatek kernel-firmware-mellanox kernel-firmware-mwifiex kernel-firmware-network kernel-firmware-nfp kernel-firmware-nvidia kernel-firmware-platform kernel-firmware-prestera kernel-firmware-qcom kernel-firmware-qlogic kernel-firmware-radeon kernel-firmware-realtek kernel-firmware-serial kernel-firmware-sound kernel-firmware-ti kernel-firmware-ueagle kernel-firmware-usb-network - Update to version 20210928 (git commit 7a30050592e2): * brcm: Add 43455 based AP6255 NVRAM for the ACEPC T8 Mini PC * linux-firmware: Update firmware file for Intel Bluetooth 9462 * amdgpu: update VCN firmware for dimgrey cavefish * amdgpu: update VCN firmware for navy flounder * amdgpu: update VCN firmware for sienna cichlid * amdgpu: update VCN firmware for vangogh * amdgpu: update VCN firmware for renoir * amdgpu: update VCN firmware for picasso * amdgpu: update VCN firmware for raven2 * amdgpu: update VCN firmware for raven * amdgpu: Add initial firmware for Beige Goby * cxgb4: Update firmware to revision 1.26.2.0 * linux-firmware: update frimware for mediatek bluetooth chip (MT7921) * linux-firmware: Update firmware file for Intel Bluetooth AX211 * linux-firmware: Update firmware file for Intel Bluetooth AX201 * linux-firmware: Update firmware file for Intel Bluetooth 9560 * qed: Add firmware 8.59.1.0 * linux-firmware: Update firmware file for Intel Bluetooth AX211 * linux-firmware: Update firmware file for Intel Bluetooth AX210 * linux-firmware: Update firmware file for Intel Bluetooth AX200 * linux-firmware: Update firmware file for Intel Bluetooth AX201 * linux-firmware: Update firmware file for Intel Bluetooth 9560 * linux-firmware: Update firmware file for Intel Bluetooth 9260 * linux-firmware: Update firmware file for Intel Bluetooth 8265 * iwlwifi: add FWs for new So device types with multiple RF modules * amdgpu: add initial firmware for Yellow Carp * i915: Update ADLP DMC v2.12 * linux-firmware: add frimware for mediatek bluetooth chip (MT7922) * linux-firmware: Update AMD SEV firmware (bsc#1186938) * Revert "iwlwifi: add FW for new So/Gf device type" - Update aliases ==== knewstuff ==== Subpackages: knewstuff-imports libKF5NewStuff5 libKF5NewStuffCore5 - Add upstream patch: * 0001-Include-a-user-agent-on-KNS-requests.patch - Add fix-crash.patch. This patch fixes a crash in DownloadWidget. (kde#443025) ==== libinput ==== Version update (1.19.0 -> 1.19.1) - Update to release 1.19.1 * New: Detects (and works around) buggy devices that claim to have a high-resolution scroll wheel but which do not actually send events. * New assumption that any non-bluetooth touchpad is internal. * Jumping cursor warning has been reduced once again. ==== libmtp ==== Version update (1.1.18 -> 1.1.19) Subpackages: libmtp-udev libmtp9 - updated to 1.1.19 release - Lots of USB ids added, especially Garmin devices - use a local libusb context, not the global one - various bugfixes ==== libnss_usrfiles ==== - Install into _libdir [bsc#1191070] ==== libsoup ==== Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0 - Ignore test failure on 32-bit arm, as it is done for 32-bit x86 https://gitlab.gnome.org/GNOME/libsoup/-/issues/236 ==== libsrtp2 ==== Version update (2.4.1 -> 2.4.2) - Update to release 2.4.2 * Fixes an unspecified regression introduced in 2.4.1 ==== libva ==== Subpackages: libva-drm2 libva2 - fixed JIRA number in previous changelog ==== mozjs78 ==== Version update (78.13.0 -> 78.14.0) - Update to version 78.14.0esr. ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0_2_0 - Update to latest from upstream, fixing: * Moving the executables from /sbin to /usr/sbin (bsc#1191054) * Remove default dependencies from iscsi-init.service (bsc#1187190) ==== openSUSE-build-key ==== - Only add openSUSE Backports key when building for a Leap system (sle_version > 0). Tumbleweed does not use Backports. ==== perl-libwww-perl ==== Version update (6.56 -> 6.57) - updated to 6.57 see /usr/share/doc/packages/perl-libwww-perl/Changes 6.57 2021-09-20 20:20:14Z - Update docs for protocols_allowed and protocols forbidden (GH#386) (Olaf Alders) ==== portaudio ==== Version update (190600_20161030 -> 190700_20210406) - Correct download source URL - Update to version v190700_20210406 - removed patch `0001-Merge-branch-ticket_275_pass_void-into-master.patch` as it is included in this release. ==== rav1e ==== - Replace rust-packaging with cargo-packaging ==== selinux-policy ==== Subpackages: selinux-policy-targeted - Fix auditd service start with systemd hardening directives (boo#1190918) * add fix_auditd.patch ==== systemd ==== Subpackages: libsystemd0 libudev1 systemd-sysvinit udev - Work around rpmlint complaining about /var/log/journal shipped with setgid bit This setgid bit has been already reviewed in the past and wasn't a concern. However we want the mode/ownership adjusted by tmpfiles and avoid the duplication of these info in rpm. - Don't ghost own any directories created dynamically by tmpfiles Again rpmlint complains but it doesn't seem to make sense to try to track all paths (including theirs perms, ownerships...) created dynamically. And 'rpm -V' is likely to report issues later with these paths anyway. This effectively partially reverts the two previous commits. - Make sure the build process won't create /var/log/journal - /var/log/journal/remote is owned by systemd-journal-remote - systemd.spec: fix a bunch of rpmlint errors/warnings - Drop systemd-logger This sub package was introduced in order to configure persistent journal and also to make sure that another syslog provider (such as rsyslog) couldn't be installed at the same time: each syslog provider conflicts with each others. However this mechanism didn't work since uninstalling systemd-logger wasn't magically turning off persistent logging because /var/log/journal is likely to be populated hence not removed. Moreover using a subpackage to configure the mode of journald was overkill and the usual ways (main conf file or drop-ins) should be preferred. - Import commit 7a5801342fe2f53e5c2a8578d6db132c0eca2d97 8d65ec4a66 test: wc is needed by test/units/testsuite-50.sh 1527bcc5dd test: make the installation of the debug tools optional in the image f4e6bf0b37 journalctl: never fail at flushing when the flushed flag is set (bsc#1188588) - Update the dependencies of the testsuite package The debug tools are optional thus no more required. OTOH strip(1) is needed when building the test image and nc(1) is needed by some tests. - Drop git internal files from the testsuite sub-package - Adjust pam macros ==== sysvinit ==== Version update (2.99 -> 3.00) - Update to sysvinit 3.00: * Better device detection of bootlogd ==== tdb ==== Version update (1.4.3 -> 1.4.4) - Update to version 1.4.4 + Fix a memory leak on error + python: remove all 'from __future__ import print_function' + Fix CID 1471761 String not null terminated + Use hex_byte() in parse_hex() + Use hex_byte() in read_data() + fix studio compiler build + Fix some signed/unsigned comparisons + also use __has_attribute macro to check for attribute support + Fix clang 9 missing-field-initializer warnings + pytdb tests: add test for storev() + pytdb: add python binding for storev() + tdbtorture: Use ARRAY_DEL_ELEMENT() + py3: Remove #define PyInt_FromLong PyLong_FromLong + py3: Remove #define PyInt_AsLong PyLong_AsLong + py3: Remove #define PyInt_Check PyLong_Check + tdb: Align integer types - Drop obsolete patch ignore-tdb1-run-transaction-expand.diff - Fix header file using undefined function visibility macro; Add patch 0001-tdb-Fix-invalid-syntax-in-tdb.h.patch; (bso#14762); ==== tevent ==== Version update (0.10.2 -> 0.11.0) - Update to version 0.11.0 + Other minor build fixes; (bso#14526); + Add custom tag to events + Add event trace api ==== xrdb ==== - Remove fallback to /lib/cpp, it's the same package as /usr/bin/cpp anyway (boo#1191060). ==== xwayland ==== - U_glamor-Fix-handling-of-1-bit-pixmaps.patch * glamor: Fix handling of 1-bit pixmaps; fixes e.g. issues with gimp on Wayland (which needs Xwayland) (boo#1189310)