Packages changed: Mesa Mesa-drivers bind (9.18.10 -> 9.18.11) cockpit distrobox dracut (057+suse.353.g6dab83eb -> 059+suse.360.g2e0ed5f7) ell (0.55 -> 0.56) gdm gdm-branding-openSUSE gedit (44.1 -> 44.2) glib2 (2.74.4 -> 2.74.5) gnome-desktop (43 -> 43.1) gnutls gpgme hidapi (0.13.0 -> 0.13.1) icewm (3.3.0 -> 3.3.1) installation-images-MicroOS (17.68 -> 17.69) kernel-source (6.1.7 -> 6.1.8) keylime (6.5.2 -> 6.5.3) kpipewire libcontainers-common libheif libpcap (1.10.1 -> 1.10.3) libraw (0.21.0 -> 0.21.1) libstorage-ng (4.5.64 -> 4.5.65) liburing (2.2 -> 2.3) logrotate (3.20.1 -> 3.21.0) lsof (4.96.5 -> 4.97.0) microos-tools (2.17 -> 2.18) multipath-tools (0.9.2+59+suse.ac8942d -> 0.9.4+68+suse.98559ea) nano (7.1 -> 7.2) nautilus (43.1 -> 43.2) postfix python-numpy python-requests (2.28.1 -> 2.28.2) python-urllib3 (1.26.13 -> 1.26.14) samba (4.17.4+git.303.89e23854eb7 -> 4.17.4+git.314.7b07e3c51a6) scout (0.2.6+20211130.022a45c -> 0.2.7+20230124.b4e3468) soundtouch (2.3.1 -> 2.3.2) sudo (1.9.12p1 -> 1.9.12p2) systemd transactional-update (4.1.0 -> 4.1.2) vim (9.0.1188 -> 9.0.1234) vte wicked (0.6.71 -> 0.6.72) xorg-x11-server yast2-installation (4.5.13 -> 4.5.15) yast2-network (4.5.12 -> 4.5.15) yast2-ntp-client (4.5.2 -> 4.5.3) zeromq === Details === ==== Mesa ==== Subpackages: Mesa-libEGL1 Mesa-libGL1 Mesa-libglapi0 libgbm1 - force usage of gcc 12 only on Leap 15.5; there is no gcc12 on Leap 15.4 - Add BuildRequires for x264 and x265 in case video_codecs should be built. - re-enable build on Leap, but only for 15.5; there is no gcc12 on Leap 15.4, which is now officially required by Mesa 22.3 ==== Mesa-drivers ==== Subpackages: Mesa-dri Mesa-gallium Mesa-libva - force usage of gcc 12 only on Leap 15.5; there is no gcc12 on Leap 15.4 - Add BuildRequires for x264 and x265 in case video_codecs should be built. - re-enable build on Leap, but only for 15.5; there is no gcc12 on Leap 15.4, which is now officially required by Mesa 22.3 ==== bind ==== Version update (9.18.10 -> 9.18.11) - Update to release 9.18.11 Security Fixes: * An UPDATE message flood could cause named to exhaust all available memory. This flaw was addressed by adding a new update-quota option that controls the maximum number of outstanding DNS UPDATE messages that named can hold in a queue at any given time (default: 100). (CVE-2022-3094) * named could crash with an assertion failure when an RRSIG query was received and stale-answer-client-timeout was set to a non-zero value. This has been fixed. (CVE-2022-3736) * named running as a resolver with the stale-answer-client-timeout option set to any value greater than 0 could crash with an assertion failure, when the recursive-clients soft quota was reached. This has been fixed. (CVE-2022-3924) New Features: * The new update-quota option can be used to control the number of simultaneous DNS UPDATE messages that can be processed to update an authoritative zone on a primary server, or forwarded to the primary server by a secondary server. The default is 100. A new statistics counter has also been added to record events when this quota is exceeded, and the version numbers for the XML and JSON statistics schemas have been updated. Removed Features: * The Differentiated Services Code Point (DSCP) feature in BIND has been non-operational since the new Network Manager was introduced in BIND 9.16. It is now marked as obsolete, and vestigial code implementing it has been removed. Configuring DSCP values in named.conf now causes a warning to be logged. Feature Changes: * The catalog zone implementation has been optimized to work with hundreds of thousands of member zones. Bug Fixes: * A rare assertion failure was fixed in outgoing TCP DNS connection handling. * Large zone transfers over TLS (XoT) could fail. This has been fixed. * In addition to a previously fixed bug, another similar issue was discovered where quotas could be erroneously reached for servers, including any configured forwarders, resulting in SERVFAIL answers being sent to clients. This has been fixed. * In certain query resolution scenarios (e.g. when following CNAME records), named configured to answer from stale cache could return a SERVFAIL response despite a usable, non-stale answer being present in the cache. This has been fixed. * When an outgoing request timed out, named would retry up to three times with the same server instead of trying the next available name server. This has been fixed. * Recently used ADB names and ADB entries (IP addresses) could get cleaned when ADB was under memory pressure. To mitigate this, only actual ADB names and ADB entries are now counted (excluding internal memory structures used for “housekeeping”) and recently used (<= 10 seconds) ADB names and entries are excluded from the overmem memory cleaner. * The “Prohibited” Extended DNS Error was inadvertently set in some NOERROR responses. This has been fixed. * Previously, TLS session resumption could have led to handshake failures when client certificates were used for authentication (Mutual TLS). This has been fixed. [bsc#1207471, bsc#1207473, bsc#1207475] ==== cockpit ==== Subpackages: cockpit-bridge cockpit-packagekit cockpit-system - restore dependency on /usr/bin/pwscore (bsc#1202277) - remove remove-pwscore.patch - enable build of cockpit-selinux module - changes to keep it sync with sle micro (0002-selinux-temporary-remove-setroubleshoot-section.patch) ==== distrobox ==== Subpackages: distrobox-bash-completion - Use tubleweed:latest as the default image instead of, hardcoded in 'distrobox-create', fedora:toolbox. ==== dracut ==== Version update (057+suse.353.g6dab83eb -> 059+suse.360.g2e0ed5f7) Subpackages: dracut-ima dracut-mkinitrd-deprecated - Update to version 059+suse.360.g2e0ed5f7: * revert(multipath): install multipathd.socket (bsc#1207524) - Update to version 059+suse.358.g8ecd6e83: See https://github.com/dracutdevs/dracut/releases/tag/058 for details (059 just adds missing entries in NEWS.md). Additional changes: * chore(suse): add execute permission to all scripts * chore(suse): update spec - Update to version 057+suse.355.g1b722fda: * fix(dracut.spec): require libopenssl1_1-hmac for dracut-fips (bsc#1206439) ==== ell ==== Version update (0.55 -> 0.56) - update to 0.56: * Add support for TLS session resume interfaces. ==== gdm ==== Subpackages: gdm-schema gdmflexiserver libgdm1 typelib-1_0-Gdm-1_0 - Update gdm-disable-gnome-initial-setup.patch: Refactoring to disable it on SLE runtime, so with the same executable it is still possible to run on Leap (jsc#PED-1719). ==== gdm-branding-openSUSE ==== - Bring back gnome-initial-setup for Leap 15.5 while keep it disabled on SLE 15 SP5 (jsc#PED-1719). ==== gedit ==== Version update (44.1 -> 44.2) Subpackages: python3-gedit - Update to version 44.2: + File Browser plugin: bug fix. + Updated translations. ==== glib2 ==== Version update (2.74.4 -> 2.74.5) Subpackages: glib2-tools libgio-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0 - Update to version 2.74.5: + Bugs fixed: glgo#GNOME/GLib#2843, glgo#GNOME/GLib#2881, glgo#GNOME/GLib#2883, glgo#GNOME/GLib!3165, glgo#GNOME/GLib!3166, glgo#GNOME/GLib!3182, glgo#GNOME/GLib!3197, glgo#GNOME/GLib!3204, glgo#GNOME/GLib!3214. + Updated translations. - Drop 1539540.patch: Fixed upstream. ==== gnome-desktop ==== Version update (43 -> 43.1) Subpackages: libgnome-desktop-3-20 libgnome-desktop-3_0-common libgnome-desktop-4-2 typelib-1_0-GnomeDesktop-3_0 - Update to version 43.1: + Fix gnome_parse_locale returning NULL for the C locale + Use more sensible default keyboard for es_US + Delete failed thumbnail if successfully savings thumbnail + Skip territory if no translation available + Updated translations. ==== gnutls ==== - FIPS: Change all the 140-2 references to FIPS 140-3 in order to account for the new FIPS certification [bsc#1207346] * Add gnutls-FIPS-140-3-references.patch - FIPS: GnuTLS DH/ECDH PCT public key regeneration [bsc#1207183] * Add gnutls-FIPS-PCT-DH.patch gnutls-FIPS-PCT-ECDH.patch ==== gpgme ==== Subpackages: libgpgme11 libgpgmepp6 python310-gpg - Update upstream keyring: https://gnupg.org/signature_key.asc - add python311.patch to build language bindings for python 3.11 ==== hidapi ==== Version update (0.13.0 -> 0.13.1) - update to 0.13.1: * hidraw: fix invalid read past the UDEV buffer ==== icewm ==== Version update (3.3.0 -> 3.3.1) Subpackages: icewm-config-upstream icewm-default icewm-lang - Update to 3.3.1: * Fully support nanosvg as an alternative to librsvg. * Rolled up windows can now be moved vertically with icesh. * Fix multi-monitor when primary monitor is right-below of secondary. * Don't resize when a client adjusts its WM_NORMAL_HINTS increments. * Report the audio interface in the configure summary. * Consider that the keyboard may have been changed externally. * Increase the timeout for the dynamic menu generator to 2 seconds. * Don't reactivate a focused window when RaiseOnClick is guaranteed. * Let the winoption "ignorePositionHint" also ignore the USPosition. * Fix the "ignoreOverrideRedirect" winoption. * Let icesh also spy on RandR monitor configuration events. ==== installation-images-MicroOS ==== Version update (17.68 -> 17.69) - merge gh#openSUSE/installation-images#621 - support more general wicked firmware devices interface (jsc#PED-3118, jsc#PED-967) - 17.69 ==== kernel-source ==== Version update (6.1.7 -> 6.1.8) - Linux 6.1.8 (bsc#1012628). - dma-buf: fix dma_buf_export init order v2 (bsc#1012628). - btrfs: fix trace event name typo for FLUSH_DELAYED_REFS (bsc#1012628). - wifi: iwlwifi: fw: skip PPAG for JF (bsc#1012628). - pNFS/filelayout: Fix coalescing test for single DS (bsc#1012628). - selftests/bpf: check null propagation only neither reg is PTR_TO_BTF_ID (bsc#1012628). - net: ethernet: marvell: octeontx2: Fix uninitialized variable warning (bsc#1012628). - tools/virtio: initialize spinlocks in vring_test.c (bsc#1012628). - vdpa/mlx5: Return error on vlan ctrl commands if not supported (bsc#1012628). - vdpa/mlx5: Avoid using reslock in event_handler (bsc#1012628). - vdpa/mlx5: Avoid overwriting CVQ iotlb (bsc#1012628). - virtio_pci: modify ENOENT to EINVAL (bsc#1012628). - vduse: Validate vq_num in vduse_validate_config() (bsc#1012628). - vdpa_sim_net: should not drop the multicast/broadcast packet (bsc#1012628). - net/ethtool/ioctl: return -EOPNOTSUPP if we have no phy stats (bsc#1012628). - r8169: move rtl_wol_enable_rx() and rtl_prepare_power_down() (bsc#1012628). - r8169: fix dmar pte write access is not set error (bsc#1012628). - bpf: keep a reference to the mm, in case the task is dead (bsc#1012628). - RDMA/srp: Move large values to a new enum for gcc13 (bsc#1012628). - selftests: net: fix cmsg_so_mark.sh test hang (bsc#1012628). - btrfs: always report error in run_one_delayed_ref() (bsc#1012628). - x86/asm: Fix an assembler warning with current binutils (bsc#1012628). - f2fs: let's avoid panic if extent_tree is not created (bsc#1012628). - perf/x86/rapl: Treat Tigerlake like Icelake (bsc#1012628). - cifs: fix race in assemble_neg_contexts() (bsc#1012628). - memblock tests: Fix compilation error (bsc#1012628). - perf/x86/rapl: Add support for Intel Meteor Lake (bsc#1012628). - perf/x86/rapl: Add support for Intel Emerald Rapids (bsc#1012628). - of: fdt: Honor CONFIG_CMDLINE* even without /chosen node, take 2 (bsc#1012628). - fbdev: omapfb: avoid stack overflow warning (bsc#1012628). - Bluetooth: hci_sync: Fix use HCI_OP_LE_READ_BUFFER_SIZE_V2 (bsc#1012628). - Bluetooth: hci_qca: Fix driver shutdown on closed serdev (bsc#1012628). - wifi: brcmfmac: fix regression for Broadcom PCIe wifi devices (bsc#1012628). - wifi: mac80211: fix MLO + AP_VLAN check (bsc#1012628). - wifi: mac80211: reset multiple BSSID options in stop_ap() (bsc#1012628). - wifi: mac80211: sdata can be NULL during AMPDU start (bsc#1012628). - nommu: fix memory leak in do_mmap() error path (bsc#1012628). - nommu: fix do_munmap() error path (bsc#1012628). - nommu: fix split_vma() map_count error (bsc#1012628). - proc: fix PIE proc-empty-vm, proc-pid-vm tests (bsc#1012628). - Add exception protection processing for vd in axi_chan_handle_err function (bsc#1012628). - LoongArch: Add HWCAP_LOONGARCH_CPUCFG to elf_hwcap (bsc#1012628). - zonefs: Detect append writes at invalid locations (bsc#1012628). - nilfs2: fix general protection fault in nilfs_btree_insert() (bsc#1012628). - mm/shmem: restore SHMEM_HUGE_DENY precedence over MADV_COLLAPSE (bsc#1012628). - hugetlb: unshare some PMDs when splitting VMAs (bsc#1012628). - mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma (bsc#1012628). - serial: stm32: Merge hard IRQ and threaded IRQ handling into single IRQ handler (bsc#1012628). - Revert "serial: stm32: Merge hard IRQ and threaded IRQ handling into single IRQ handler" (bsc#1012628). - xhci-pci: set the dma max_seg_size (bsc#1012628). - usb: xhci: Check endpoint is valid before dereferencing it (bsc#1012628). - xhci: Fix null pointer dereference when host dies (bsc#1012628). - xhci: Add update_hub_device override for PCI xHCI hosts (bsc#1012628). - xhci: Add a flag to disable USB3 lpm on a xhci root port level (bsc#1012628). - usb: acpi: add helper to check port lpm capability using acpi _DSM (bsc#1012628). - xhci: Detect lpm incapable xHC USB3 roothub ports from ACPI tables (bsc#1012628). - prlimit: do_prlimit needs to have a speculation check (bsc#1012628). - USB: serial: option: add Quectel EM05-G (GR) modem (bsc#1012628). - USB: serial: option: add Quectel EM05-G (CS) modem (bsc#1012628). - USB: serial: option: add Quectel EM05-G (RS) modem (bsc#1012628). - USB: serial: option: add Quectel EC200U modem (bsc#1012628). - USB: serial: option: add Quectel EM05CN (SG) modem ... changelog too long, skipping 227 lines ... - commit 2ebd33f ==== keylime ==== Version update (6.5.2 -> 6.5.3) Subpackages: keylime-config keylime-firewalld keylime-logrotate keylime-registrar keylime-tenant keylime-tpm_cert_store keylime-verifier python310-keylime - Update to version v6.5.3: * Bump version number to 6.5.3 * durable attestation: a simple "attestation replay" CLI utility * cmd_exec: Replace cast()s to bytes with asserts isinstance(..., bytes) * codestyle: Add type annotations to db/keylime_db.py and add to mypy * codestyle: Add type annotations to requests_client.py and add to mypy * codestyle: Add type annotations to tornado_requests.py and add to mypy * mypy: Change list of checked files to shorter list of unchecked files * codestyle: Add missing annotations to cmd_exec.py and add to mypy * codestyle: Have all files in ima directory checked by mypy * pylint: ignore zmq Context abstract-class-instantiated warnings * tenant: reliable and consistent add/delete operations (fixes #1158) (#1271) * tenant: fix the exit code for `bulkinfo` operation * config: support override via environment variables * Extend test execution instructions in TESTING.md * packit-ci: Add hotfix for tpm2-tss Fedora BZ#2158598 * tenant: Remove code hashing a public key and using hash as UUID * linters: Exclude intentionally invalid python file * config: Check for available config upgrade on startup * Do not install keylime nor configuration files during tests * .ci/test_wrapper: Add test user keylime:tss * config: Support quoted strings for TOML compatibility * gitignore: Do not use 'config' as a match pattern * tests: Add test for convert_config script * convert_config: Set version for each mapping processed * cmd/convert_config: Remove quotes and spaces around version string * convert_config: Set default output path as /etc/keylime for root * convert_config: Do not use keys() to iterate on maps * Install config upgrade script as keylime_upgrade_config * templates: Remove log_destination option * Fix default values in mappings * Correctly strip elements of a list on config v2.0 adjust script * setup: Don't use keylime.conf to generate the split configuration * convert_config: Add --defaults option to use default values * convert_config: Use str_to_version from common module * Add keylime/common/version.py for version manipulation * elchecking: load policy modules explicitly * Revert "tpm_abstract: move import of measured_boot into check_pcrs(..)" * codestyle: Add type-annotations to cli/policies.py and add to mypy * codestyle: Add type-annotations to cli/options.py and add to mypy * Introduce a RetDictType for return type of cmd_exec.run() * requirements, docs: add typing-extensions as a dependency * ima_dm: add type checks and hints * Switch code coverage measurement to Fedora 37 * codestyle: Fix annotation of mb_measurement_data * ima: Fix the ima_sign_verification_keys initial datatype * elchecking: add support for MeasuredBoot when SecureBoot is disabled * verifier: a (very simple) cache implementation for IMA policies (solves #1167) * codestyle: Add type annotations to cmd/convert_ima_policy.py and add to mypy * codestyle: Add type annotations to cmd/ima_emulator_adapter.py and add to mypy * codestyle: Add type annotations to cmd/user_data_encrypt.py and add to mypy * codestyle: Add type annotations to cmd/verifier.py and add to mypy * codestyle: Add type annotations to cmd/tenant.py and add to mypy * codestyle: Add type annotations to cmd/registrar.py and add to mypy * codestyle: Add type annotations to cmd/ca.py and add to mypy * codestyle: Add type annotations to cmd/agent.py and add to mypy * CI tests: Do not remove Fedora tag repository * tpm_abstract: move import of measured_boot into check_pcrs(..) * docker: fix and improve build_locally.sh * docker: use version 5.4 of tpm2-tools * docker: update container to Fedora 37 * codestyle: Type-annotate files in revocation_actions & add to mypy * Remove redundant parameter from enforce_pcrs() * codestyle: Add missing type annotations to files in common & add to mypy * api_version: Catch InvalidVersion for packaging v22.0 * verifier: fix for IMA policy checksum calculation * codestyle: Type-annotate measured_boot.py and add to mypy * codestyle: Fix variable assigments in tpm2_object_test.py and add to mypy * codestyle: Fix and add type annotations to tpm2_objects.py and add to mypy * codestyle: Cast the agent Dict to allow Any types to be assigned to it * codestyle: Change verifier_port annotation from int to str * codestyle: Avoid switching datatypes of agent by using differnt variable * codestyle: Fix event parameter to be an Optional[Event] * codestyle: Fix annotation of tosend parameter to be a Dict[str, Any] * codestyle: add type hints to elchecking module * codestyle: Type-annotate web_util.py and add to mypy * codestyle: Add missing type annotations to ima.py and add to mypy * codestyle: Add missing type annotations to ima_test.py and add to mypy * codestyle: Add missing type annotations to file_signatures.py and add to mypy * logging: remove option to log into separate file * codestyle: Add type annotations to tpm classes and address issues * codestyle: Add type-annotations to signing.py and add to mypy * codestyle: Add missing type annotations to api_version.py and add to mypy * codestyle: Add keylime_logging.py to mypy * codestyle: Add missing type-annotations to agentstates and add to mypy * codestyle: Add missing type annotations to failure.py and add to mypy * codestyle: Type-annotate user_utils_test.py and add to mypy * codestyle: Type-annotate user_utils.py and add to mypy * codestyle: Type-annotate ca_util.py and add to mypy * codestyle: Add missing annotations to cert_utils and add to mypy * codestyle: Type-annotate ca_impl_openssl and add to mypy * codestyle: Type-annotate tpm_ek_ca.py and add to mypy * codestyle: Type-annotate fs_util.py and add to mypy * codestyle: Add json.py to mypy.ini * codestyle: Type-annotate secure_mount.py and add to mypy * codestyle: Add missing annotations to crypto.py and add to mypy * common: remove metrics * cmd: removal of keylime_migrations_apply * codestyle: Set type of trusted_server_ca to List[str] and initialize with list ... changelog too long, skipping 87 lines ... * tpm_main: fix ek creation for tpm2-tools versions > 4.2 ==== kpipewire ==== Subpackages: kpipewire-imports libKPipeWire5 libKPipeWireRecord5 - Require pipewire-devel for the -devel package ==== libcontainers-common ==== - storage.conf: Unset 'driver' and set 'driver_priority' to allow podman to use 'btrfs' if available and fallback to 'overlay' if not. - .spec: rm %post script to set 'btrfs' as storage driver in storage.conf ==== libheif ==== Subpackages: gdk-pixbuf-loader-libheif libheif1 - Add missing BuildRequires for SVT-AV1 support for Tumbleweed (only for x86_64) - Disable dynamic plugin interface and build plugins statically instead (boo#1206945) ==== libpcap ==== Version update (1.10.1 -> 1.10.3) - update to 1.10.3: * Sort the PUBHDR variable in Makefile.in in "ls" order. * Fix typo in comment in pflog.h. * Remove two no-longer-present files from .gitignore. * Update code and comments for handling failure to set promiscuous mode based on new information. - update to 1.10.2: * Build system updates * Developer visible fixes * Fix some formatting string issues found by cppcheck * "Dead" pcap_ts from pcap_open_dead() and ..._with_tstamp_precision(): Don't crash if pcap_breakloop() is called. * Savefiles: multiple bug fixes handling files * Capture: Never process more than INT_MAX packets in a pcap_dispatch() call, to avoid integer overflow * Packet filtering: PFLOG bug fixes and improvements * Fix memory leak in capture device open * Fix detection of CAN/CAN FD packets in direction check * Fix double-free crashes on errors such as running on a kernel with CONFIG_PACKET_MMAP not configured * Multiple CANbus bug fixes * Fix pcap_findalldevs() to find usbmon devices * Fix handling of VLAN tagged packets if the link-layer type is changed from DLT_LINUX_SLL to DLT_LINUX_SLL2 * Always turn on PACKET_AUXDATA * Correctly compute the "real" length for isochronous USB transfers ==== libraw ==== Version update (0.21.0 -> 0.21.1) - update to 0.21.1: * fixed typo in panasonic metadata parser * Multiple fixes inspired by oss-fuzz project * Phase One/Leaf IIQ-S v2 support * Canon CR3 filmrolls * Canon CRM (movie) files * Tiled bit-packed (and 16-bit unpacked) DNGs * (non-standard) Deflate-compressed integer DNG files are allowed * Canon EOS R3, R7 and R10 * Fujifilm X-H2S, X-T30 II * OM System OM-1 * Leica M11 * Sony A7-IV (ILCE-7M4) * DJI Mavic 3 * Nikon Z9: standard compression formats only ==== libstorage-ng ==== Version update (4.5.64 -> 4.5.65) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Macedonian) (bsc#1149754) - 4.5.65 ==== liburing ==== Version update (2.2 -> 2.3) - add 0001-test-helpers-fix-socket-length-type.patch fixes tests on big endian - update to 2.3: * Support non-libc build for aarch64. * Add io_uring_{enter,enter2,register,setup} syscall functions. * Add sync cancel interface, io_uring_register_sync_cancel(). * Fix return value of io_uring_submit_and_wait_timeout() to match the man page. * Improvements to the regression tests * Add support and test case for passthrough IO * Add recv and recvmsg multishot helpers and support * Add documentation and support for IORING_SETUP_DEFER_TASKRUN * Fix potential missing kernel entry with IORING_SETUP_IOPOLL * Add support and documentation for zero-copy network transmit * Various optimizations * Many cleanups * Many man page additions and updates - drop handle-eintr.patch, test-xattr-don-t-rely-on-NUL-termination.patch: upstream ==== logrotate ==== Version update (3.20.1 -> 3.21.0) - Update to 3.21.0: * add ignoreduplicates directive to allow duplicate file matches * add --wait-for-state-lock option to wait for lock on the state file * avoid failure when an anonymous non-privileged user runs logrotate * support home dir expansion in olddir * reduce unnecessary rename operations with start N where N > 1 * unify handling of log levels * do not print error: when exit code is unaffected - Replace the vendor config logic: * Remove logrotate-vendor-dir.patch and the code from logrotate.service (also addresses boo#1202406) * Add a wrapper script which collects all config files in the right order - Create logrotate.keyring with kdudka's public key - Drop logrotate-rpmlintrc: rpmlint doesn't look at /usr/etc/logrotate.d/, so the false positive doesn't trigger. ==== lsof ==== Version update (4.96.5 -> 4.97.0) - update to 4.97.0: * Remove support because the os is no longer updated for more than 10 years * Remove support because the os is no longer updated for more than 20 years * Add experimental build system based on Autotools * Fixed LTsock testing on darwin * Remove NEW and OLD folders * Fix FreeBSD testcases * Rewrite documentation and publish at https://lsof.readthedocs.io/ ==== microos-tools ==== Version update (2.17 -> 2.18) - Update to version 2.18: - Add TMPDIR to tukit binddirs for Salt - 98selinux-microos: Add chroot as dependency - Fix spelling error in warning ==== multipath-tools ==== Version update (0.9.2+59+suse.ac8942d -> 0.9.4+68+suse.98559ea) Subpackages: kpartx libmpath0 - Update to version 0.9.4+68+suse.98559ea: * libmultipath: bump ABI version to 18.0.0 * libmultipath: pathinfo: don't fail for devices lacking INQUIRY properties (gh#opensvc/multipath-tools#56) * libmpathpersist: use conf->timeout for updating persistent reservations (gh#opensvc/multipath-tools#45) * libmultipath: is_path_valid(): check if device is in use (bsc#1203141) (added libmount dependency) * libmultipath: orphan paths if coalesce_paths frees newmp (bsc#1207546) * multipathd: handle no active paths in update_map_pr (bsc#1207546) * multipathd: make pr registration consistent (bsc#1207546) * libmultipath: don't leak memory on invalid strings (bsc#1207546) * multipath.conf(5): improve documentation of dev_loss_tmo (bsc#1207546) * libmpathpersist: fix command keyword ordering (bsc#1207546) * libmultipath: fix 'show paths format' failure * minor bugfixes * hwtable fixes * Build system rework * spec file: adapt make command line to changes in build system * spec file: use make -Orecurse (better readable output) * spec file: use verbose build ==== nano ==== Version update (7.1 -> 7.2) - update to 7.2: * is prevented from pasting in view mode. ==== nautilus ==== Version update (43.1 -> 43.2) Subpackages: gnome-shell-search-provider-nautilus libnautilus-extension4 - Update to version 43.2: + Regressions addressed: - Launch search from shell correctly - Make nautilus-autorun-software work again - Restore 2-dimensional navigation from sushi - Resolve stuttering scrolling - Reintroduce 64px icon size for grid view - Show full filename again in grid, using tooltips + Other bugfixes: - Avoid a many crashes - Stop showing � in the type on Properties - Show rename error dialogs again - Handle X11-only drag-and-drop quirks - Allow autorun.sh without executable bit - Improve selection-setting - Restrict DND actions over drag source - Focus replaces files - Improve keyboard focus navigation on the new views - Stop blocking on the tracker connection - Don't add missing emblems + Updated translations. ==== postfix ==== - Fix SELinux labeling issue caused by /usr/sbin/config.postfix (bsc#1207227). ==== python-numpy ==== - Slightly reformat the specfile condition blocks: The %python_subpackages generator misses " %if" lines with a preceding whitespace. Relevant for d:l:p:backports not having libalternatives. ==== python-requests ==== Version update (2.28.1 -> 2.28.2) - update to 2.28.2: - Requests now supports charset\_normalizer 3.x. - Updated MissingSchema exception to suggest https scheme rather than http. - drop requests-allow-charset-normalizer-3.patch (upstream) ==== python-urllib3 ==== Version update (1.26.13 -> 1.26.14) - update to 1.26.14: * Fixed parsing of port 0 (zero) returning None, instead of 0. * Removed deprecated getheaders() calls in contrib module. ==== samba ==== Version update (4.17.4+git.303.89e23854eb7 -> 4.17.4+git.314.7b07e3c51a6) Subpackages: libsamba-policy0-python3 samba-ad-dc-libs samba-client samba-client-libs samba-libs samba-libs-python3 samba-python3 - libdsdb-module-samba4 should be packaged as part of samba-libs and not samba-ad-dc-libs. Additionally no need for it to be removed conditionally. - Clean up logic for PAM migration settings in spec file. ==== scout ==== Version update (0.2.6+20211130.022a45c -> 0.2.7+20230124.b4e3468) Subpackages: scout-command-not-found - Update to version 0.2.7+20230124.b4e3468: * Bump version to v0.2.7 * allow multiple baseurls in repo file * remove deprecated class * Translated using Weblate (Macedonian, German, Ukrainian) ==== soundtouch ==== Version update (2.3.1 -> 2.3.2) - update to 2.3.2: * autotools improvements ==== sudo ==== Version update (1.9.12p1 -> 1.9.12p2) Subpackages: sudo-plugin-python - Update to 1.9.12p2: * Fixes bsc#1207082 * Changes in 1.9.12p2: Fixed a compilation error on Linux/aarch64. GitHub issue #197. Fixed a potential crash introduced in the fix GitHub issue #134. If a user’s sudoers entry did not have any RunAs user’s set, running sudo -U otheruser -l would dereference a NULL pointer. Fixed a bug introduced in sudo 1.9.12 that could prevent sudo from creating a I/O files when the iolog_file sudoers setting contains six or more Xs. Fixed a compilation issue on AIX with the native compiler. GitHub issue #231. Fixed CVE-2023-22809, a flaw in sudo’s -e option (aka sudoedit) that could allow a malicious user with sudoedit privileges to edit arbitrary files. For more information, see Sudoedit can edit arbitrary files. ==== systemd ==== Subpackages: libsystemd0 libudev1 systemd-doc udev - Drop 1000-Revert-getty-Pass-tty-to-use-by-agetty-via-stdin.patch It's no more necessary since util-linux 2.38 has been released in Factory. - Make sure we apply the presets on units shipped by systemd package ==== transactional-update ==== Version update (4.1.0 -> 4.1.2) Subpackages: dracut-transactional-update libtukit4 transactional-update-zypp-config tukit - Version 4.1.2 - Don't try to mount user mounts if they don't exist [boo#1207366] - Version 4.1.1 - Mount user specific binddirs last: Prevously the internal mounts would potentially overwrite user bind mounts [boo#1205011] - selinux: Relabel shadowed /var files during update to make sure they don't interfere with the update [boo#1205937] - Clean up /var/lib/overlay more aggressively [boo#1206947] - tukit: Merge /etc overlay into parent if --discard is used together with --continue - previously the files were incorrectly always merged with the currently running system - status: do not execute the status command if experimental - Don't delete created mount point dirs any more - Small code optimizations ==== vim ==== Version update (9.0.1188 -> 9.0.1234) Subpackages: vim-data vim-data-common vim-small - Updated to version 9.0.1234, fixes the following problems * Return value of type() for class and object unclear. * Invalid memory access with folding and using "L". * Some Bazel files are not recognized. * No error when class function argument shadows a member. * Cannot map when using the Kitty key protocol. * Compiler warning for comparing pointer with int. * Restoring KeyTyped when building statusline not tested. * Code is indented more than necessary. * Dump file missing from patch. * Abstract class not supported yet. * Crash when using kitty and using a mapping with . * AppVeyor builds with an old Python version. * Assignment with operator doesn't work in object method. * Crash when iterating over list of objects. * Return type of values() is always list. * Expression compiled the wrong way after using an object. * Crash when handling class that extends another class with more than one object members. * Testing with Python on AppVeyor does not work properly. * Error when object type is expected but getting "any". * Code is indented more than necessary. * Getting interface member does not always work. * Compiler complains about declaration after label. * Storing value in interface member does not always work. * Cannot read back what setcellwidths() has done. * Adding a line below the last one does not expand fold. * File left behind after running tests. * Using isalpha() adds dependency on current locale. * Coverity warns for ignoring return value. * Using an object member in a closure doesn't work. * Completion includes functions that don't work. * Handling of FORTIFY_SOURCE flags doesn't match Fedora usage. * Termcap/terminfo entries do not indicate where modifiers might appear. * Code is indented more than necessary. * Cannot use setcellwidths() below 0x100. * Cannot call a :def function with a number for a float argument. * Reading past the end of a line when formatting text. ==== vte ==== - Add ddb2c8a.patch: widget: Use correct end row for getting the selected text. The range is end-exclusive, so use end_row() instead of last_row(). Fixes glgo#GNOME/vte#2584 ==== wicked ==== Version update (0.6.71 -> 0.6.72) Subpackages: wicked-service - version 0.6.72 - nbft: introduced new wicked-nbft sub-package to setup network interfaces using NBFT firmware configuration according to the NVM Express Boot Specification 1.0 (jsc#PED-3132) - client: add `wicked firmware extensions|interfaces|enable|disable` command to improve `ibft`,`nbft`,`redfish` firmware extension and interface handling (jsc#PED-3132) - client: improve error handling in netif firmware discovery extension execution - appconfig: improved to handle extension definition overrides in the wicked-config - nanny: fix use-after-free in debug mode (bsc#1206447) - spec: replace transitional `%usrmerged` macro with regular version check (boo#1206798) - client: improve to show `no-carrier` in ifstatus output - linux: cleanup inclusions and update uapi header to 6.0 - ethtool: link mode nwords cleanup and new advertise link mode map names ==== xorg-x11-server ==== Subpackages: xorg-x11-server-Xvfb xorg-x11-server-extra - rename u_xorg-server-oob-read-enqueue-event.patch to U_xorg-server-oob-read-enqueue-event.patch since it's already upstream - Add u_xorg-server-oob-read-enqueue-event.patch: fix an out-of-bounds read in EnqueueEvent. ==== yast2-installation ==== Version update (4.5.13 -> 4.5.15) - Connect only NBFT when linuxrc sets UseNBFT (jsc#PED-967) - 4.5.15 - Discover and connect to all NVMe-over-Fabrics subsystems in case that linuxrc sets UseNBFT (jsc#PED-967). - 4.5.14 ==== yast2-network ==== Version update (4.5.12 -> 4.5.15) - During installation, do not configure DHCP if there is some active interface configured by firmware (jsc#PED-967). - 4.5.15 - Fix the return of packages needed by the selected backend when running an autoinstallation (bsc#1207221) - 4.5.14 - Fixed dirname evaluation when creating the directory for the configuration files to be copied to the target system (bsc#1206723, bsc#1207382) - 4.5.13 ==== yast2-ntp-client ==== Version update (4.5.2 -> 4.5.3) - bsc#1188980 - ntp dialog allows to manually set ntp source - ntp source can be selected as pool or server - ntp sources are written into /etc/chrony.d/pools.conf - 4.5.3 ==== zeromq ==== Subpackages: libzmq5 zeromq-tools - qemu-user.patch: Fix build with qemu linux-user emulation