Packages changed: ImageMagick (7.1.1.5 -> 7.1.1.6) Mesa (23.0.1 -> 23.0.2) Mesa-drivers (23.0.1 -> 23.0.2) MozillaFirefox (110.0.1 -> 112.0) QGnomePlatform-qt5 adobe-sourcesans3-fonts (3.046 -> 3.052) attica-qt5 (5.104.0 -> 5.105.0) augeas autoyast2 (4.6.0 -> 4.6.1) avahi avahi-glib2 baloo5 (5.104.0 -> 5.105.0) bash-completion bluedevil5 (5.27.3 -> 5.27.4) bluez-qt (5.104.0 -> 5.105.0) breeze (5.27.3 -> 5.27.4) breeze-gtk (5.27.3 -> 5.27.4) breeze5-icons (5.104.0 -> 5.105.0) ca-certificates (2+git20211004.3efbea9 -> 2+git20230406.2dae8b7) coreutils discover (5.27.3 -> 5.27.4) dmidecode dnf dracut (059+suse.366.gf45bc67a -> 059+suse.368.g2e7ac134) drkonqi5 (5.27.3 -> 5.27.4) firewalld (1.3.0 -> 1.3.1) frameworkintegration (5.104.0 -> 5.105.0) gcc13 (13.0.1+git6840 -> 13.0.1+git7162) gdb gdm ghostscript git glib2-branding-openSUSE glibc glslang gnome-control-center gnome-settings-daemon (44.0 -> 44.1) gnome-shell gnome-terminal (3.48.0 -> 3.48.1) gnutls (3.7.9 -> 3.8.0) gpgme grub2 gstreamer (1.22.1 -> 1.22.2) gstreamer-plugins-bad (1.22.1 -> 1.22.2) gstreamer-plugins-base (1.22.1 -> 1.22.2) gstreamer-plugins-good (1.22.1 -> 1.22.2) gtk4 gvfs hwdata (0.368 -> 0.369) ibus isl (0.25 -> 0.26) kactivities-stats (5.104.0 -> 5.105.0) kactivities5 (5.104.0 -> 5.105.0) kactivitymanagerd (5.27.3 -> 5.27.4) karchive (5.104.0 -> 5.105.0) kauth (5.104.0 -> 5.105.0) kbookmarks (5.104.0 -> 5.105.0) kcm_flatpak (5.27.3 -> 5.27.4) kcm_sddm (5.27.3 -> 5.27.4) kcmutils (5.104.0 -> 5.105.0) kcodecs (5.104.0 -> 5.105.0) kcompletion (5.104.0 -> 5.105.0) kconfig (5.104.0 -> 5.105.0) kconfigwidgets (5.104.0 -> 5.105.0) kcoreaddons (5.104.0 -> 5.105.0) kcrash (5.104.0 -> 5.105.0) kdbusaddons (5.104.0 -> 5.105.0) kde-cli-tools5 (5.27.3 -> 5.27.4) kde-gtk-config5 (5.27.3 -> 5.27.4) kdeclarative (5.104.0 -> 5.105.0) kded (5.104.0 -> 5.105.0) kdelibs4support (5.104.0 -> 5.105.0) kdesu (5.104.0 -> 5.105.0) kdnssd-framework (5.104.0 -> 5.105.0) kdoctools (5.104.0 -> 5.105.0) kernel-firmware (20230320 -> 20230406) kernel-source (6.2.9 -> 6.2.10) kexec-tools kfilemetadata5 (5.104.0 -> 5.105.0) kgamma5 (5.27.3 -> 5.27.4) kglobalaccel (5.104.0 -> 5.105.0) kguiaddons (5.104.0 -> 5.105.0) kholidays (5.104.0 -> 5.105.0) khotkeys5 (5.27.3 -> 5.27.4) khtml (5.104.0 -> 5.105.0) ki18n (5.104.0 -> 5.105.0) kiconthemes (5.104.0 -> 5.105.0) kidletime (5.104.0 -> 5.105.0) kimageformats (5.104.0 -> 5.105.0) kinfocenter5 (5.27.3 -> 5.27.4) kinit (5.104.0 -> 5.105.0) kio (5.104.0 -> 5.105.0) kirigami2 (5.104.0 -> 5.105.0) kitemmodels (5.104.0 -> 5.105.0) kitemviews (5.104.0 -> 5.105.0) kjobwidgets (5.104.0 -> 5.105.0) kjs (5.104.0 -> 5.105.0) kmenuedit5 (5.27.3 -> 5.27.4) knewstuff (5.104.0 -> 5.105.0) knotifications (5.104.0 -> 5.105.0) knotifyconfig (5.104.0 -> 5.105.0) kpackage (5.104.0 -> 5.105.0) kparts (5.104.0 -> 5.105.0) kpeople5 (5.104.0 -> 5.105.0) kpipewire (5.27.3 -> 5.27.4) kpty (5.104.0 -> 5.105.0) kquickcharts (5.104.0 -> 5.105.0) krunner (5.104.0 -> 5.105.0) kscreen5 (5.27.3 -> 5.27.4) kscreenlocker (5.27.3 -> 5.27.4) kservice (5.104.0 -> 5.105.0) ksshaskpass5 (5.27.3 -> 5.27.4) ksystemstats5 (5.27.3 -> 5.27.4) ktexteditor (5.104.0 -> 5.105.0) ktextwidgets (5.104.0 -> 5.105.0) kunitconversion (5.104.0 -> 5.105.0) kwallet (5.104.0 -> 5.105.0) kwayland (5.104.0 -> 5.105.0) kwayland-integration (5.27.3 -> 5.27.4) kwidgetsaddons (5.104.0 -> 5.105.0) kwin5 (5.27.3 -> 5.27.4) kwindowsystem (5.104.0 -> 5.105.0) kwrited5 (5.27.3 -> 5.27.4) kxmlgui (5.104.0 -> 5.105.0) layer-shell-qt (5.27.3 -> 5.27.4) lcms2 (2.14 -> 2.15) libKF5ModemManagerQt (5.104.0 -> 5.105.0) libKF5NetworkManagerQt (5.104.0 -> 5.105.0) libXfixes (6.0.0 -> 6.0.1) libXft (2.3.7 -> 2.3.8) libXpm (3.5.14 -> 3.5.16) libXt (1.2.1 -> 1.3.0) libgcrypt (1.10.1 -> 1.10.2) libgpg-error (1.46 -> 1.47) libkdecoration2 (5.27.3 -> 5.27.4) libkscreen2 (5.27.3 -> 5.27.4) libksysguard5 (5.27.3 -> 5.27.4) libmemcached (1.0.18 -> 1.1.4) libnice libopenmpt (0.6.9 -> 0.6.10) libpcap (1.10.3 -> 1.10.4) libqmi (1.30.8 -> 1.32.4) libqt5-qtbase (5.15.8+kde183 -> 5.15.8+kde185) libqt5-qtwebengine libsolv (0.7.23 -> 0.7.24) libstorage-ng (4.5.92 -> 4.5.96) libtomcrypt libva (2.17.0 -> 2.18.0) libva-gl (2.17.0 -> 2.18.0) libyui (4.5.0 -> 4.5.1) libyui-ncurses (4.5.0 -> 4.5.1) libyui-ncurses-pkg (4.5.0 -> 4.5.1) libyui-qt (4.5.0 -> 4.5.1) libyui-qt-graph (4.5.0 -> 4.5.1) libyui-qt-pkg (4.5.0 -> 4.5.1) libzypp (17.31.8 -> 17.31.10) llvm16 (16.0.0 -> 16.0.1) lua54 mdadm microos-tools (2.20 -> 2.20+git20230413.2a43cdb) milou5 (5.27.3 -> 5.27.4) mobile-broadband-provider-info (20221107 -> 20230416) mozilla-nss (3.88.1 -> 3.89) mozjs102 (102.9.0 -> 102.10.0) mutter (44.0+18 -> 44.0+54) ncurses (6.4.20230311 -> 6.4.20230408) nghttp2 (1.51.0 -> 1.52.0) open-iscsi open-vm-tools openexr (3.1.6 -> 3.1.7) openldap2 (2.6.3 -> 2.6.4) openldap2-contrib-src (2.6.3 -> 2.6.4) openssh oxygen5-sounds (5.27.3 -> 5.27.4) pam-config (2.2 -> 2.4) pam_kwallet (5.27.3 -> 5.27.4) patterns-base patterns-gnome patterns-kde (20221001 -> 20230403) patterns-microos pipewire (0.3.67 -> 0.3.69) plasma-browser-integration (5.27.3 -> 5.27.4) plasma-framework (5.104.0 -> 5.105.0) plasma-nm5 (5.27.3 -> 5.27.4) plasma5-addons (5.27.3 -> 5.27.4) plasma5-desktop (5.27.3 -> 5.27.4) plasma5-disks (5.27.3 -> 5.27.4) plasma5-integration (5.27.3 -> 5.27.4) plasma5-openSUSE plasma5-pa (5.27.3 -> 5.27.4) plasma5-systemmonitor (5.27.3 -> 5.27.4) plasma5-thunderbolt (5.27.3 -> 5.27.4) plasma5-workspace (5.27.3 -> 5.27.4.1) podman (4.4.4 -> 4.5.0) polkit-kde-agent-5 (5.27.3 -> 5.27.4) poppler (23.03.0 -> 23.04.0) poppler-qt5 (23.03.0 -> 23.04.0) powerdevil5 (5.27.3 -> 5.27.4) prison-qt5 (5.104.0 -> 5.105.0) publicsuffix (20230226 -> 20230414) purpose (5.104.0 -> 5.105.0) python-cryptography (40.0.1 -> 40.0.2) python-pexpect python-pytz (2023.2 -> 2023.3) python-redis (4.3.3 -> 4.5.4) python-setuptools (67.6.0 -> 67.6.1) qqc2-desktop-style (5.104.0 -> 5.105.0) raspberrypi-firmware (2023.02.22 -> 2023.03.22) raspberrypi-firmware-config (2023.02.22 -> 2023.03.22) rav1e (0.6.2+0 -> 0.6.4+0) redis (7.0.8 -> 7.0.11) rsync rubygem-ruby-dbus (0.20.0 -> 0.21.0) runc (1.1.5 -> 1.1.6) rust-keylime (0.2.0+git.1677691779.f7edd9a -> 0.2.0+git.1681457715.54484b7) sddm shadow shim snapper solid (5.104.0 -> 5.105.0) sonnet (5.104.0 -> 5.105.0) sudo syndication (5.104.0 -> 5.105.0) syntax-highlighting (5.104.0 -> 5.105.0) systemd (253.1 -> 253.3) systemsettings5 (5.27.3 -> 5.27.4) talloc tcl texlive texlive-specs-n (2022.196.2.005svn61719 -> 2023.201.2.005svn65956) threadweaver (5.104.0 -> 5.105.0) tigervnc util-linux util-linux-systemd vim (9.0.1430 -> 9.0.1443) vte (0.72.0 -> 0.72.1) webkit2gtk3 webkit2gtk4 wireplumber (0.4.13 -> 0.4.14) wsdd (0.7.0 -> 0.7.1) xdg-desktop-portal-gtk xdg-desktop-portal-kde (5.27.3 -> 5.27.4) xdm xf86-input-libinput (1.2.1 -> 1.3.0) xz yast2-installation (4.6.1 -> 4.6.2) yast2-packager (4.6.0 -> 4.6.1) yast2-pkg-bindings (4.6.0 -> 4.6.1) yast2-ruby-bindings (4.6.1 -> 4.6.2) yast2-snapper (4.6.0 -> 4.6.1) yast2-storage-ng (4.6.3 -> 4.6.5) yast2-update (4.6.0 -> 4.6.1) yast2-users (4.6.0 -> 4.6.1) zlib-ng-compat (2.0.6 -> 2.0.7) zvbi zypper (1.14.59 -> 1.14.60) === Details === ==== ImageMagick ==== Version update (7.1.1.5 -> 7.1.1.6) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.1.6 - https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-6---2023-04-02 - fixes CVE-2023-1906 [bsc#1210308] ==== Mesa ==== Version update (23.0.1 -> 23.0.2) Subpackages: Mesa-libEGL1 Mesa-libGL1 Mesa-libglapi0 libgbm1 - Update to version 23.0.2 * 2nd bug fix release: lots of patches for all over the tree, zink being the biggest singel source of changes. ==== Mesa-drivers ==== Version update (23.0.1 -> 23.0.2) Subpackages: Mesa-dri Mesa-gallium Mesa-libva - Update to version 23.0.2 * 2nd bug fix release: lots of patches for all over the tree, zink being the biggest singel source of changes. ==== MozillaFirefox ==== Version update (110.0.1 -> 112.0) - Mozilla Firefox 112.0 * https://www.mozilla.org/en-US/firefox/112.0/releasenotes/ MFSA 2023-13 (bsc#1210212) * CVE-2023-29531 (bmo#1794292) Out-of-bound memory access in WebGL on macOS * CVE-2023-29532 (bmo#1806394) Mozilla Maintenance Service Write-lock bypass * CVE-2023-29533 (bmo#1798219, bmo#1814597) Fullscreen notification obscured * CVE-2023-29534 (bmo#1816007, bmo#1816059, bmo#1821155, bmo#1821576, bmo#1821906, bmo#1822298, bmo#1822305) Fullscreen notification could have been obscured on Firefox for Android * MFSA-TMP-2023-0001 (bmo#1819244) Double-free in libwebp * CVE-2023-29535 (bmo#1820543) Potential Memory Corruption following Garbage Collector compaction * CVE-2023-29536 (bmo#1821959) Invalid free from JavaScript code * CVE-2023-29537 (bmo#1823365, bmo#1824200, bmo#1825569) Data Races in font initialization code * CVE-2023-29538 (bmo#1685403) Directory information could have been leaked to WebExtensions * CVE-2023-29539 (bmo#1784348) Content-Disposition filename truncation leads to Reflected File Download * CVE-2023-29540 (bmo#1790542) Iframe sandbox bypass using redirects and sourceMappingUrls * CVE-2023-29541 (bmo#1810191) Files with malicious extensions could have been downloaded unsafely on Linux * CVE-2023-29542 (bmo#1810793, bmo#1815062) Bypass of file download extension restrictions * CVE-2023-29543 (bmo#1816158) Use-after-free in debugging APIs * CVE-2023-29544 (bmo#1818781) Memory Corruption in garbage collector * CVE-2023-29545 (bmo#1823077) Windows Save As dialog resolved environment variables * CVE-2023-29546 (bmo#1780842) Screen recording in Private Browsing included address bar on Android * CVE-2023-29547 (bmo#1783536) Secure document cookie could be spoofed with insecure cookie * CVE-2023-29548 (bmo#1822754) Incorrect optimization result on ARM64 * CVE-2023-29549 (bmo#1823042) Javascript's bind function may have failed * CVE-2023-29550 (bmo#1720594, bmo#1751945, bmo#1812498, bmo#1814217, bmo#1818357, bmo#1818762, bmo#1819493, bmo#1820389, bmo#1820602, bmo#1821448, bmo#1822413, bmo#1824828) Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 * CVE-2023-29551 (bmo#1763625, bmo#1814314, bmo#1815798, bmo#1815890, bmo#1819239, bmo#1819465, bmo#1819486, bmo#1819492, bmo#1819957, bmo#1820514, bmo#1820776, bmo#1821838, bmo#1822175, bmo#1823547) Memory safety bugs fixed in Firefox 112 - requires * NSS 3.89 * Python >= 3.7 (for build) - removed obsolete mozilla-bmo1807652.patch - Fix Icons displayed incorrectly on GNOME/wayland via WMCLASS in desktop file - Mozilla Firefox 111.0.1 (boo#1209688) * Fixed a crash on macOS while pinch-zooming under some circumstances (bmo#1658986) * Fixed a bug causing Firefox to freeze on startup for some Windows users (bmo#1823159) - fix build on Tumbleweed (mozilla-bmo1807652.patch) - exclude i586/i686 once again because it fails to link libxul due to its size - Mozilla Firefox 111.0 * https://www.mozilla.org/en-US/firefox/111.0/releasenotes MFSA 2023-09 (bsc#1209173) * CVE-2023-28159 (bmo#1783561) Fullscreen Notification could have been hidden by download popups on Android * CVE-2023-25748 (bmo#1798798) Fullscreen Notification could have been hidden by window prompts on Android * CVE-2023-25749 (bmo#1810705) Firefox for Android may have opened third-party apps without a prompt * CVE-2023-25750 (bmo#1814733) Potential ServiceWorker cache leak during private browsing mode * CVE-2023-25751 (bmo#1814899) Incorrect code generation during JIT compilation * CVE-2023-28160 (bmo#1802385) Redirect to Web Extension files may have leaked local path * CVE-2023-28164 (bmo#1809122) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation * CVE-2023-28161 (bmo#1811181) One-time permissions granted to a local file were extended to other local files loaded in the same tab * CVE-2023-28162 (bmo#1811327) Invalid downcast in Worklets * CVE-2023-25752 (bmo#1811627) Potential out-of-bounds when accessing throttled streams * CVE-2023-28163 (bmo#1817768) ... changelog too long, skipping 12 lines ... - update create-tar.sh ==== QGnomePlatform-qt5 ==== - Add 0001-fix-qt-6.5-compilation.patch to fix a compilation error with qt 6.5 ==== adobe-sourcesans3-fonts ==== Version update (3.046 -> 3.052) - Update to 3.052: * Adds Medium weight requested by user. (GitHub issue #253) * Updates the design of several glyphs to arrive at more compact vertical metrics ==== attica-qt5 ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Attica5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== augeas ==== Subpackages: augeas-lenses libaugeas0 libfa1 - Use the correct license - LGPL-2.1 ==== autoyast2 ==== Version update (4.6.0 -> 4.6.1) - Rebuild the RPM database during upgrade (--rebuilddb) (bsc#1209565) - 4.6.1 ==== avahi ==== Subpackages: libavahi-client3 libavahi-common3 libavahi-core7 - Add avahi-CVE-2023-1981.patch: emit error if requested service is not found (boo#1210328 CVE-2023-1981). ==== avahi-glib2 ==== - Add avahi-CVE-2023-1981.patch: emit error if requested service is not found (boo#1210328 CVE-2023-1981). ==== baloo5 ==== Version update (5.104.0 -> 5.105.0) Subpackages: baloo5-file baloo5-file-lang baloo5-imports baloo5-kioslaves baloo5-kioslaves-lang baloo5-tools baloo5-tools-lang libKF5Baloo5 libKF5BalooEngine5 libKF5BalooEngine5-lang - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Add conventional python virtual-env folder to exclude filters * [TermGenerator] Skip all unprintable characters * Define the translation domain of BalooEngine ==== bash-completion ==== - Move cmake config files to devel ==== bluedevil5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: bluedevil5-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== bluez-qt ==== Version update (5.104.0 -> 5.105.0) Subpackages: bluez-qt-imports bluez-qt-udev libKF5BluezQt6 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== breeze ==== Version update (5.27.3 -> 5.27.4) Subpackages: breeze5-cursors breeze5-decoration breeze5-style breeze5-style-lang breeze5-wallpapers libbreezecommon5-5 - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * CheckBox,RadioButton: Fix RTL icon alignment * CheckBox,RadioButton: Fix RTL focus frame positioning * CheckBox,RadioButton: Extend focus line to cover an icon too (kde#467824) * Fix RTL for SP_ToolBarHorizontalExtensionButton * KStyle: make painted arrows more scalable, fix RTL delay menu arrows ==== breeze-gtk ==== Version update (5.27.3 -> 5.27.4) Subpackages: gtk2-metatheme-breeze gtk3-metatheme-breeze gtk4-metatheme-breeze metatheme-breeze-common - Add patch to fix oversized titlebuttons in GTK3 apps (kde#468203) * 0001-gtk3-restore-old-icon-size-for-titlebutton.patch - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * gtk4/windowcontrols: reduce right margin of close button * gtk3/titlebutton: extend control area to window borders * gtk4/windowcontrols: extend control area to window borders (kde#414777) * iconhelper: Query size via CSS * gtk4/aboutdialog: set icon size for large icons * gtk4/theme: Use 0.5 opacity for disabled pictures * menus: make size react to fractional scaling ==== breeze5-icons ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Add icons for showing and hiding a virtual keyboard * Redshift icons: Add missing semi-transparency, add new breeze-dark icons * Update Redshift icons to off on & sun (kde#462215) * Delete false Gparted and Kwikdisk icons (kde#467319) ==== ca-certificates ==== Version update (2+git20211004.3efbea9 -> 2+git20230406.2dae8b7) - Update to version 2+git20230406.2dae8b7: * Build in place support * Fix up argument parsing * merge spec file into git ==== coreutils ==== Subpackages: coreutils-doc - add fix-reflink-fallback.patch (bsc#1210033) ==== discover ==== Version update (5.27.3 -> 5.27.4) Subpackages: discover-backend-flatpak discover-backend-fwupd discover-backend-packagekit discover-lang discover-notifier - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * rpm-ostree: Improve handling of externally started transactions * rpm-ostree: Correctly set fetching and transaction state * rpm-ostree: Unify transaction setup in a single function * pk: Clear the offline state before starting a new one (kde#467638) * notifier: Don't show updates notification if Discover is running * pk: Do not create a QSet unnecessarily for isPackageNameUpgradeable * pk: Group getUpdateDetail calls into one * pk: Group offline updates resource size notifications * PackageKitNotifier: Do not refresh database if an offline update is pending ==== dmidecode ==== - dmioem-hpe-oem-record-237-firmware-change.patch: Fix the decoding of the last field of HPE OEM record type 237 (DIMM Vendor Information). ==== dnf ==== - BuildRequire pkgconfig(bash-completion) instead of bash-completion: the build system needs this to find out where to install the completion files to. ==== dracut ==== Version update (059+suse.366.gf45bc67a -> 059+suse.368.g2e7ac134) Subpackages: dracut-ima - Update to version 059+suse.368.g2e7ac134: * chore(suse): remove mkinitrd wrapper (bsc#1202351) (jsc#PED-1919) ==== drkonqi5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: drkonqi5-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== firewalld ==== Version update (1.3.0 -> 1.3.1) Subpackages: firewalld-bash-completion python3-firewall - update to 1.3.1: * fix(fw_nm): use IP interface names for connection lookup (18c8b81) * fix(fw_policy): raise exceptions (5ae9322) * fix(service): include: when used with rich rule (986f0be) * fix(nftables): rich: log: limit was not taking effect (0dc0575) * fix(build): rpm must build all as prerequisite (6896748) * fix: use error codes for FirewallError instances (370e5f2) * fix(ipset): chunk entries when restoring set (8a88855) * fix(applet): allows using KDE network connection editor (29c8ef6) ==== frameworkintegration ==== Version update (5.104.0 -> 5.105.0) Subpackages: frameworkintegration-plugin libKF5Style5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Don't play sound for plain notification (kde#457672) ==== gcc13 ==== Version update (13.0.1+git6840 -> 13.0.1+git7162) Subpackages: cpp13 libgcc_s1 libgfortran5 libgomp1 libobjc4 libstdc++6 libstdc++6-pp libubsan1 - Bump to d339e9802f758e051b0a1ef6db732ff846cbf4e3, git7162. - Add new x86-related intrinsics (amxcomplexintrin.h). - riscv-atomic.patch: RISC-V: Add support for inlining subword atomic operations - riscv-pthread.patch: Don't add -latomic with -pthread - Bump to d0b961b802dd7d9d555ff4515835a479329326e9, git6995. ==== gdb ==== - Fix license, again (bsc#1210081). ==== gdm ==== Subpackages: gdm-schema gdmflexiserver libgdm1 typelib-1_0-Gdm-1_0 - Create two set of pam configuration files: + *-sle.pamd are for SLES15 and older + add postlogin-* includes to the others as required by openSUSEs PAM config policy ==== ghostscript ==== Subpackages: ghostscript-x11 - CVE-2023-28879.patch fixes CVE-2023-28879 Buffer Overflow in s_xBCPE_process cf. https://bugs.ghostscript.com/show_bug.cgi?id=706494 (bsc#1210062) ==== git ==== - sha256_clone_fix.patch: fix cloning of empty sha256 repositories (jsc#PED-3891) ==== glib2-branding-openSUSE ==== - prefer org.gnome.TextEditor.desktop instead of gedit. patterns-gnome was changed to install TextEditor (boo#1210648). ==== glibc ==== Subpackages: glibc-extra glibc-locale glibc-locale-base nscd - getlogin-no-loginuid.patch: getlogin_r: fix missing fallback if loginuid is unset (bsc#1209229, BZ #30235) ==== glslang ==== - Add StandAlone/ to glslang-nonstd-devel ==== gnome-control-center ==== Subpackages: gnome-control-center-color gnome-control-center-goa gnome-control-center-user-faces - Rebase gnome-control-center-disable-error-message-for-NM.patch - Add gnome-control-center-fix-6f1567f23.patch: network/connection-editor: fix crash when removing a connection (glgo#GNOME/gnome-control-center/commit/8cb77b4d3, bsc#1210377). ==== gnome-settings-daemon ==== Version update (44.0 -> 44.1) - Update to version 44.1: + Build improvements + Power: - Connect to light sensor asynchronously - Initialize check for VM environment earlier + Rfkill: Monitor WwanEnabled property changes properly + Smartcards: Check for the addition of new smartcard readers + Xsettings: Do not force deprecated High Contrast icon theme + Updated translations. - Use autopatch. ==== gnome-shell ==== Subpackages: gnome-extensions gnome-shell-calendar - Update gnome-shell-private-connection.patch: (bsc#1209373) ==== gnome-terminal ==== Version update (3.48.0 -> 3.48.1) Subpackages: gnome-shell-search-provider-gnome-terminal nautilus-extension-terminal - Update to version 3.48.1: + help: Add help translation for TR locale + server: More env var sanitisation + Updated translations. ==== gnutls ==== Version update (3.7.9 -> 3.8.0) - Temporarily disable GNULIB's year2038 support for 64bit time_t by using the --disable-year2038 flag. This omits support for timestamps past the year 2038: * Fixes the public API on 32-bit architectures avoiding to change the size of time_t as it cannot be changed without breaking the ABI compatibility. * Upstream issue: https://gitlab.com/gnutls/gnutls/-/issues/1466 - Update to 3.8.0: [bsc#1205763, bsc#1209627] * libgnutls: Fix a Bleichenbacher oracle in the TLS RSA key exchange. Reported by Hubert Kario (#1050). Fix developed by Alexander Sosedkin. [GNUTLS-SA-2020-07-14, CVSS: medium] [CVE-2023-0361] * libgnutls: C++ library is now header only. All definitions from gnutlsxx.c have been moved into gnutlsxx.h. Users of the C++ interface have two options: 1. include gnutlsxx.h in their application and link against the C library. (default) 2. include gnutlsxx.h in their application, compile with GNUTLS_GNUTLSXX_NO_HEADERONLY macro defined and link against the C++ library. * libgnutls: GNUTLS_NO_STATUS_REQUEST flag and %NO_STATUS_REQUEST priority modifier have been added to allow disabling of the status_request TLS extension in the client side. * libgnutls: TLS heartbeat is disabled by default. The heartbeat extension in TLS (RFC 6520) is not widely used given other implementations dropped support for it. To enable back support for it, supply --enable-heartbeat-support to configure script. * libgnutls: SRP authentication is now disabled by default. It is disabled because the SRP authentication in TLS is not up to date with the latest TLS standards and its ciphersuites are based on the CBC mode and SHA-1. To enable it back, supply - -enable-srp-authentication option to configure script. * libgnutls: All code has been indented using "indent -ppi1 -linux". CI/CD has been adjusted to catch regressions. This is implemented through devel/indent-gnutls, devel/indent-maybe and .gitlab-ci.yml’s commit-check. You may run devel/indent-gnutls to fix any indentation issues if you make code modifications. * guile: Guile-bindings removed. They have been extracted into a separate project to reduce complexity and to simplify maintenance, see . * minitasn1: Upgraded to libtasn1 version 4.19. * API and ABI modifications: GNUTLS_NO_STATUS_REQUEST: New flag GNUTLS_SRTP_AEAD_AES_128_GCM: New gnutls_srtp_profile_t enum member GNUTLS_SRTP_AEAD_AES_256_GCM: New gnutls_srtp_profile_t enum member * Merge gnutls-FIPS-Set-error-state-when-jent-init-failed.patch and gnutls-FIPS-jitterentropy-threadsafe.patch into the main patch gnutls-FIPS-jitterentropy.patch * Rebase gnutls-FIPS-140-3-references.patch * Rebase patches with upstream version: - gnutls-FIPS-PCT-DH.patch gnutls-FIPS-PCT-ECDH.patch * Remove patches merged/fixed upstream: - gnutls-FIPS-disable-failing-tests.patch - gnutls-verify-library-HMAC.patch - gnutls_ECDSA_signing.patch - gnutls-Make-XTS-key-check-failure-not-fatal.patch - gnutls-FIPS-SLI-pbkdf2-verify-keylengths-only-SHA.patch * Update keyring with https://gnutls.org/gnutls-release-keyring.gpg - FIPS: Make the jitterentropy calls thread-safe [bsc#1208146] * Add gnutls-FIPS-jitterentropy-threadsafe.patch - FIPS: GnuTLS DH/ECDH PCT public key regeneration [bsc#1207183] * Rebase patches with the version submitted upstream. * Avoid copying the key material: gnutls-FIPS-PCT-DH.patch * Improve logic around memory release: gnutls-FIPS-PCT-ECDH.patch ==== gpgme ==== Subpackages: libgpgme11 libgpgmepp6 python310-gpg - Add a Qt6 flavor to build Qt6 bindings - Use %ldconfig_scriptlets ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-snapper-plugin grub2-systemd-sleep-plugin - Fix no prep partition error on non-PReP architectures by making the prep_loadenv module exclusive to powerpc_ieee1275 platform (bsc#1210489) * 0004-Introduce-prep_load_env-command.patch - Fix the issue of freeing an uninitialized pointer * 0002-prep_loadenv-Fix-regex-for-Open-Firmware-device-spec.patch - Rediff * 0005-export-environment-at-start-up.patch * 0009-Add-crypttab_entry-to-obviate-the-need-to-input-pass.patch - Resolve some issues with OS boot failure on PPC NVMe-oF disks and made enhancements to PPC secure boot's root device discovery config (bsc#1207230) - Ensure get_devargs and get_devname functions are consistent * 0001-openfw-Ensure-get_devargs-and-get_devname-functions-.patch - Fix regex for Open Firmware device specifier with encoded commas * 0002-prep_loadenv-Fix-regex-for-Open-Firmware-device-spec.patch - Fix regular expression in PPC secure boot config to prevent escaped commas from being treated as delimiters when retrieving partition substrings. - Use prep_load_env in PPC secure boot config to handle unset host-specific environment variables and ensure successful command execution. * 0004-Introduce-prep_load_env-command.patch - Refreshed * 0005-export-environment-at-start-up.patch ==== gstreamer ==== Version update (1.22.1 -> 1.22.2) Subpackages: libgstreamer-1_0-0 typelib-1_0-Gst-1_0 - Update to version 1.22.2: + Highlighted bugfixes: - avdec_h264: fix decoder deadlocks with FFmpeg 6.0 - rtspsrc: . fix regression with URI protocols in OPTIONS requests for RTSP over TLD . improved control url handling compatibility for broken servers - decklink: fix 10 bit RGB (r210) format auto detection for capture and fix playout if video caps are configured before audio caps - d3d11videosink: Fix tearing in case of fullscreen mode - playbin: fix deadlock when stopping stream with subtitles visible (even more) - typefinding: fix regression not detecting application/dash+xml in some corner cases - osxvideosink: fix broken aspect ratio and frame drawing region - decodebin3, parsebin: Improve elementary stream handling when decoders are not present and fix hang when removing a failing stream - urisourcebin: Propagate sticky events from parsebin, so that the `STREAM_START` event with the `GstStream` info is always available when pads get exposed - v4l2: Add support for YVU420M format; mark JPEG content as parsed - h264decoder, h265decoder: DPB bumping process and latency reporting fixes - Opus: Fix reading of extended channel config in MPEG-TS and fix missing sample rate when remuxing from RTP to Matroska - zxing: add support for building against zxing-c++ 2.0 - cerbero: Fix packaging of Rust plugins on Android; fix modern Gentoo distro detection - various bug fixes, memory leak fixes, and other stability and reliability improvements + Gstreamer: - datetime: Return G_MAXFLOAT instead of G_MAXDOUBLE for no timezone offset - inputselector: Wake up streaming thread before PLAYING_TO_PAUSED transition - tools: fix potential crash when passing command-line options on Windows - Rebase patches with quilt. ==== gstreamer-plugins-bad ==== Version update (1.22.1 -> 1.22.2) Subpackages: libgstadaptivedemux-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstplayer-1_0-0 libgstsctp-1_0-0 libgsttranscoder-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Update to version 1.22.2: + cea708overlay: fix HCR interpretation + d3d11bufferpool: Fix invalid access in debug print loop + d3d11compositor: Fix composition error on release_pad() + d3d11converter: Fix conversion backend selection + d3d11videosink: Fix tearing in case of fullscreen mode + d3d11window: fix memory leak + debugqroverlay: fix string leak + decklinkaudiosink: Fix playback when video caps is configured before audio + decklink: fix 10 bit RGB (r210) format auto detection + decklinkvideosrc: - RGB 4:4:4 doesn't work after GStreamer upgrade (regression) - unable to show HDMI stream that Blackmagic's Media Express is able to see + gtkwaylandsink: - Destroy GstWlWindow when parent GtkWindow is destroyed - Fix crash when rendering after the window is closed + h264decoder: Fix DPB bumping process + h264decoder, h265decoder: Latency reporting related fixes + h264parse: Validate VUI framerate + jpegparse: reset parse state when the SOI is not the first marker + ksvideo, directshow: Fix reference leaks in device providers + nvencoder: Fix CQP option setting + nvh264encoder: Fix template caps to include progressive mode as well + openjpegdec: allow multithread decoding only in subframe mode + tsdemux: Fix reading of extended Opus channel configuration + vulkan: fix validation layer issues + vulkanoverlaycompositor: fix potential use after free + vulkanswapper: correctly handle force-aspect-ratio=false + wasapi2: Fix potential crash on device activation failure + webrtc: Fix segfault traversing ice transports + webrtc: patch leak caused by early return + zxing: add support for zxing-c++ 2.0 - Rebase reduce-required-meson.patch. - Move pkgconfig(libchromaprint) BuildRequires to chromaprint plugin sub-package, and drop the hard gstreamer-plugins-bad-chromaprint Requires from our devel sub-package. This is a "stand alone" plugin, and this way packages depending on gstreamer-plugins-bad during build avoids pulling in libavcodec and libavfilter + ffmpeg-mini-devel packages for no reason. ==== gstreamer-plugins-base ==== Version update (1.22.1 -> 1.22.2) Subpackages: libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstfft-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgstrtp-1_0-0 libgstrtsp-1_0-0 libgstsdp-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 typelib-1_0-GstTag-1_0 - Update to version 1.22.2: + alsasink: Fix for being stuck in stop_streaming_threads state + decodebin3: fix hang when removing a failing stream + gl: wayland: cleanup on close + parsebin: Improve elementary stream handling + playbin: fix deadlock when stopping stream with subtitles visible even more + sdp: Skip source-specific caps fields when creating an SDP media from caps + urisourcebin: - Propagate sticky events from parsebin - Activate pad before transferring sticky events + typefinding: fix failure to recognize application/dash+xml in some cases - Rebase patches with quilt. ==== gstreamer-plugins-good ==== Version update (1.22.1 -> 1.22.2) Subpackages: gstreamer-plugins-good-gtk - Update to version 1.22.2: + osxvideosink: fix broken aspect ratio and frame drawing region + qtdemux: Fix seek adjustment with SNAP_AFTER flag + rtpopusdepay, matroskamux: Fix invalid rate while muxing Opus in Matroska + rtpmanager: twcc: Fix duplicate packet handling + rtsp: url: fix incorrect request URI scheme for TLS transport methods (regression) + rtspsrc: - Consider "451: Parameter Not Understood" when handling broken control urls - fix behavior change with URI protocols in OPTIONS requests - Skip PTs with caps incompatible to the global caps - rtpjpegdepay: fix logic error when checking if an end of image (EOI) tag is present + v4l2: - Add support for YVU420M format - mark JPEG as parsed - Rebase patch with quilt. ==== gtk4 ==== Subpackages: gtk4-schema gtk4-tools libgtk-4-1 typelib-1_0-Gtk-4_0 - Place English translations in the tools sub-package instead of lang. This should offer translations for the main English locales without the need to install any additional package by default. - Add "file-not-in-%lang" RPM Lint warning to rpmlintrc file for the reason above. - Drop "shlib-policy-name-error" unused filter from rpmlintrc. - Disable vulkan support, stop passing vulkan=enabled to meson. Disable vulkan-devel Requires and BuildRequires. - Disable pkgconfig(libavfilter) BuildRequires, upstream do not enable ffmpeg support by default and we do not enable it, so no need to carry the dependency. - Use ldconfig_scriptlets macro. - Pass build-testsuite=false, build-tests=false and build-examples=false to meson, no longer build these as we are not running or installing them anyway, save a lot on buildtime. ==== gvfs ==== Subpackages: gvfs-backend-afc gvfs-backend-goa gvfs-backend-samba gvfs-backends gvfs-fuse - Add 41862c0179f834d8bc3bd84ce78ee495050f2676.patch: trash: Sync trash dir items when files change. - Use auto(setup|patch) macros. ==== hwdata ==== Version update (0.368 -> 0.369) - update to 0.369: * Update pci, usb and vendor ids ==== ibus ==== Subpackages: libibus-1_0-5 typelib-1_0-IBus-1_0 - Fix key typing order * This prevents that keys get stuck in games with wine/proton (steam) * Added ibus-fix-key-release.patch ==== isl ==== Version update (0.25 -> 0.26) - update to 0.26: * fix inherited overloaded methods in Python bindings * decompose topological sort of clusters in incremental scheduler * improved isl_pw_aff_list_{min,max} * add some convenience functions * more exports to (templated C++) bindings * slightly improved conversion from binary relation to function ==== kactivities-stats ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kactivities5 ==== Version update (5.104.0 -> 5.105.0) Subpackages: kactivities5-imports libKF5Activities5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Remove unused CI dep ==== kactivitymanagerd ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== karchive ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kauth ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Auth5 libKF5Auth5-lang libKF5AuthCore5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kbookmarks ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kcm_flatpak ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Too many changes to list here ==== kcm_sddm ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== kcmutils ==== Version update (5.104.0 -> 5.105.0) Subpackages: kcmutils-imports libKF5KCMUtils5 libKF5KCMUtilsCore5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kcodecs ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kcompletion ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kconfig ==== Version update (5.104.0 -> 5.105.0) Subpackages: kconf_update5 libKF5ConfigCore5 libKF5ConfigGui5 libKF5ConfigQml5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kconfigwidgets ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * KColorSchemeManager: don't override color scheme set by platform theme (kde#447029) * CommandBar: Fix lastUsedActions not restored * KCModule: Add porting aid for KF6 changes ==== kcoreaddons ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5CoreAddons5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Prevent KSignalHandler leaking signalfd file descriptors ==== kcrash ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kdbusaddons ==== Version update (5.104.0 -> 5.105.0) Subpackages: kdbusaddons-tools libKF5DBusAddons5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kde-cli-tools5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== kde-gtk-config5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: kde-gtk-config5-gtk3 - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * kded: provide `org.gtk.Settings` when `GTK_USE_PORTAL` is not set on Wayland (kde#421745) * gtkconfig: set `color-scheme` when current color scheme changes * gsettings: check param exists before setting value * Beside monitor scaling factors, a user may specify a preferred text DPI size from the system configuration utility (KCM fonts) That setting is stored inside the kcmfonts configuration file; one entry is kept for Plasma/X11 sessions, "forceFontDPI", and another for Plasma/Wayland sessions, "forceFontDPIWayland". (kde#466463,kde#461106) ==== kdeclarative ==== Version update (5.104.0 -> 5.105.0) Subpackages: kdeclarative-components libKF5CalendarEvents5 libKF5Declarative5 libKF5QuickAddons5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * API dox: add some minimal docs to namespace & classes to trigger coverage * API dox: cover CalendarEvents in generated QCH file * Overhaul configmodule docs ==== kded ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kdelibs4support ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5KDELibs4Support5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kdesu ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Have KDE4 compat header emit compiler warnings about their use ==== kdnssd-framework ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kdoctools ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5DocTools5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * kdoctools_install: fix doc detection in path with special chars ==== kernel-firmware ==== Version update (20230320 -> 20230406) Subpackages: kernel-firmware-all kernel-firmware-amdgpu kernel-firmware-ath10k kernel-firmware-ath11k kernel-firmware-atheros kernel-firmware-bluetooth kernel-firmware-bnx2 kernel-firmware-brcm kernel-firmware-chelsio kernel-firmware-dpaa2 kernel-firmware-i915 kernel-firmware-intel kernel-firmware-iwlwifi kernel-firmware-liquidio kernel-firmware-marvell kernel-firmware-media kernel-firmware-mediatek kernel-firmware-mellanox kernel-firmware-mwifiex kernel-firmware-network kernel-firmware-nfp kernel-firmware-nvidia kernel-firmware-platform kernel-firmware-prestera kernel-firmware-qcom kernel-firmware-qlogic kernel-firmware-radeon kernel-firmware-realtek kernel-firmware-serial kernel-firmware-sound kernel-firmware-ti kernel-firmware-ueagle kernel-firmware-usb-network - Update to version 20230406 (git commit 86da2ac9b4e5): * linux-firmware: update firmware for MT7916 * rtw89: 8852b: update format-1 fw to v0.29.29.1 * rtw89: 8852c: update fw to v0.27.56.13 * ath11k: WCN6855 hw2.0: update board-2.bin * ath11k: WCN6750 hw1.0: update to WLAN.MSL.1.0.1-01160-QCAMSLSWPLZ-1 * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 * ath11k: IPQ8074 hw2.0: update board-2.bin * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 * ath11k: IPQ6018 hw1.0: update board-2.bin * ath10k: QCA99X0 hw2.0: update board-2.bin * ath10k: QCA9984 hw1.0: update board-2.bin * ath10k: QCA9888 hw2.0: update board-2.bin * ath10k: QCA6174 hw3.0: update board-2.bin * ath10k: QCA4019 hw1.0: update board-2.bin * nvidia: update Tu10x and Tu11x signed firmware to support newer Turing HW * linux-firmware: update firmware for MT7922 WiFi device * linux-firmware: update firmware for mediatek bluetooth chip (MT7922) * linux-firmware: Amphion: Update vpu firmware * iwlwifi: add new FWs from core78-32 release * iwlwifi: update 9000-family firmwares to core78-32 * amdgpu: Update SDMA 6.0.1 firmware * amdgpu: Add PSP 13.0.11 firmware * amdgpu: Update PSP 13.0.4 firmware * amdgpu: Update GC 11.0.1 firmware * amdgpu: Update DCN 3.1.4 firmware * amdgpu: Add GC 11.0.4 firmware * rtw88: 8822c: Update normal firmware to v9.9.15 ==== kernel-source ==== Version update (6.2.9 -> 6.2.10) - Linux 6.2.10 (bsc#1012628). - thunderbolt: Limit USB3 bandwidth of certain Intel USB4 host routers (bsc#1012628). - cifs: update ip_addr for ses only for primary chan setup (bsc#1012628). - cifs: prevent data race in cifs_reconnect_tcon() (bsc#1012628). - cifs: avoid race conditions with parallel reconnects (bsc#1012628). - zonefs: Reorganize code (bsc#1012628). - zonefs: Simplify IO error handling (bsc#1012628). - zonefs: Reduce struct zonefs_inode_info size (bsc#1012628). - zonefs: Separate zone information from inode information (bsc#1012628). - zonefs: Fix error message in zonefs_file_dio_append() (bsc#1012628). - btrfs: rename BTRFS_FS_NO_OVERCOMMIT to BTRFS_FS_ACTIVE_ZONE_TRACKING (bsc#1012628). - btrfs: zoned: count fresh BG region as zone unusable (bsc#1012628). - btrfs: zoned: drop space_info->active_total_bytes (bsc#1012628). - fsverity: don't drop pagecache at end of FS_IOC_ENABLE_VERITY (bsc#1012628). - cifs: fix missing unload_nls() in smb2_reconnect() (bsc#1012628). - xfrm: Zero padding when dumping algos and encap (bsc#1012628). - ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds (bsc#1012628). - ASoC: Intel: avs: max98357a: Explicitly define codec format (bsc#1012628). - ASoC: Intel: avs: da7219: Explicitly define codec format (bsc#1012628). - ASoC: Intel: avs: rt5682: Explicitly define codec format (bsc#1012628). - ASoC: Intel: avs: ssm4567: Remove nau8825 bits (bsc#1012628). - ASoC: Intel: avs: nau8825: Adjust clock control (bsc#1012628). - lib: zstd: Backport fix for in-place decompression (bsc#1012628). - zstd: Fix definition of assert() (bsc#1012628). - ACPI: video: Add backlight=native DMI quirk for Dell Vostro 15 3535 (bsc#1012628). - ACPI: x86: Introduce an acpi_quirk_skip_gpio_event_handlers() helper (bsc#1012628). - ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 7 B1-750 (bsc#1012628). - ACPI: x86: Add skip i2c clients quirk for Lenovo Yoga Book X90 (bsc#1012628). - ASoC: SOF: ipc3: Check for upper size limit for the received message (bsc#1012628). - ASoC: SOF: ipc4-topology: Fix incorrect sample rate print unit (bsc#1012628). - ASoC: SOF: Intel: pci-tng: revert invalid bar size setting (bsc#1012628). - ASoC: SOF: Intel: hda-dsp: harden D0i3 programming sequence (bsc#1012628). - ASoC: SOF: Intel: hda-ctrl: re-add sleep after entering and exiting reset (bsc#1012628). - ASoC: SOF: IPC4: update gain ipc msg definition to align with fw (bsc#1012628). - ASoC: hdmi-codec: only startup/shutdown on supported streams (bsc#1012628). - wifi: mac80211: check basic rates validity (bsc#1012628). - md: avoid signed overflow in slot_store() (bsc#1012628). - x86/PVH: obtain VGA console info in Dom0 (bsc#1012628). - drm/amdkfd: Fix BO offset for multi-VMA page migration (bsc#1012628). - drm/amdkfd: fix a potential double free in pqm_create_queue (bsc#1012628). - drm/amdgpu/vcn: custom video info caps for sriov (bsc#1012628). - drm/amdkfd: fix potential kgd_mem UAFs (bsc#1012628). - drm/amd/display: Fix HDCP failing to enable after suspend (bsc#1012628). - net: hsr: Don't log netdev_err message on unknown prp dst node (bsc#1012628). - ALSA: asihpi: check pao in control_message() (bsc#1012628). - ALSA: hda/ca0132: fixup buffer overrun at tuning_ctl_set() (bsc#1012628). - fbdev: tgafb: Fix potential divide by zero (bsc#1012628). - ACPI: tools: pfrut: Check if the input of level and type is in the right numeric range (bsc#1012628). - sched_getaffinity: don't assume 'cpumask_size()' is fully initialized (bsc#1012628). - nvme-pci: fixing memory leak in probe teardown path (bsc#1012628). - nvme-pci: add NVME_QUIRK_BOGUS_NID for Lexar NM620 (bsc#1012628). - drm/amdkfd: Fixed kfd_process cleanup on module exit (bsc#1012628). - net/mlx5e: Lower maximum allowed MTU in XSK to match XDP prerequisites (bsc#1012628). - fbdev: nvidia: Fix potential divide by zero (bsc#1012628). - fbdev: intelfb: Fix potential divide by zero (bsc#1012628). - fbdev: lxfb: Fix potential divide by zero (bsc#1012628). - fbdev: au1200fb: Fix potential divide by zero (bsc#1012628). - tools/power turbostat: Fix /dev/cpu_dma_latency warnings (bsc#1012628). - tools/power turbostat: fix decoding of HWP_STATUS (bsc#1012628). - tracing: Fix wrong return in kprobe_event_gen_test.c (bsc#1012628). - btrfs: fix uninitialized variable warning in ... changelog too long, skipping 235 lines ... - commit f0487ac ==== kexec-tools ==== - Update kexec-tools-SYS_getrandom.patch to fix build errors on old x86_64 distributions ==== kfilemetadata5 ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kgamma5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== kglobalaccel ==== Version update (5.104.0 -> 5.105.0) Subpackages: kglobalaccel5 libKF5GlobalAccel5 libKF5GlobalAccelPrivate5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kguiaddons ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5GuiAddons5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kholidays ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== khotkeys5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== khtml ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== ki18n ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Use compat headers with deprecation warnings for KuitMarkup/kuitmarkup.h * cmake: Do not rebuild po and ts files if they did not change ==== kiconthemes ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Add missing comma between enum values - Drop patch, merged upstream: * 0001-Add-missing-comma-between-enum-values.patch ==== kidletime ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kimageformats ==== Version update (5.104.0 -> 5.105.0) - Add support for RAW image formats - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * psd: Fix alpha blending (KF5) ==== kinfocenter5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: kinfocenter5-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * energy: Use text colour for the grid lines ==== kinit ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kio ==== Version update (5.104.0 -> 5.105.0) Subpackages: kio-core - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * CommandLauncher: call emitResult() as soon as process has started (kde#466359) * Also handle copy_file_range failing with ENOENT * widgets/renamefiledialog: set number limit again (kde#466636) ==== kirigami2 ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Kirigami2-5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Fix quit action code * GlobalDrawer: Fix header with invisible content taking up space * ColorUtils: Handle cases where hue is -1 in linearInterpolate * NavigationTabBar: Fix imports in doc example * NavigationTabBar: Factor out minDelegateWidth part of expression * Action Name Not required KF5 * Default page categorized settings * Show back button when pushing a pagerow * shadowed*rectangle: Don't use base class result if materials are different * Set fallback theme path when a custom icon theme is used ==== kitemmodels ==== Version update (5.104.0 -> 5.105.0) Subpackages: kitemmodels-imports libKF5ItemModels5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kitemviews ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kjobwidgets ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kjs ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kmenuedit5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== knewstuff ==== Version update (5.104.0 -> 5.105.0) Subpackages: knewstuff-imports libKF5NewStuff5 libKF5NewStuffCore5 libKF5NewStuffWidgets5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * QtQuickDialogWrapper: Print out errors if component creation failed * Deprecate knewstuffcore_version.h & knewstuffquick_version.h * Add missing deps to KF5NewStuffCoreConfig ==== knotifications ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== knotifyconfig ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kpackage ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kparts ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kpeople5 ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kpipewire ==== Version update (5.27.3 -> 5.27.4) Subpackages: kpipewire-imports libKPipeWire5 libKPipeWireDmaBuf5 libKPipeWireRecord5 - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * source: Handle BGRA buffers gracefully * record: Only create the sws_context when necessary * record: Use a good amount of threads as recommended by QThread * record: Make sure we process all the frames before leaving * record: Improve packet fetching * Use a different API call to make importing DmaBufs work on Nvidia (kde#448839) * options to disable motion estimation and in-loop filtering * record: Refactor thread distribution * record: Allocate SwsContext only when necessary * recording: Allocate frames when we render * recording: Extend the encoders API ==== kpty ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kquickcharts ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== krunner ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kscreen5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: kscreen5-plasmoid - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * OSD: Do not connect to member QObject's destroyed signal (kde#466914) * Display connector name instead of type name when serial number is identical (kde#466046) ==== kscreenlocker ==== Version update (5.27.3 -> 5.27.4) Subpackages: kscreenlocker-lang libKScreenLocker5 - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== kservice ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Remove unused include ==== ksshaskpass5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: ksshaskpass5-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== ksystemstats5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== ktexteditor ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * try to improve test stability * autoindent: fix indentation when "keep extra spaces" is enabled * Julia indent: fix indentation when "keep extra spaces" is enabled, also fix indentation when a line ends with a string assignment ==== ktextwidgets ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kunitconversion ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kwallet ==== Version update (5.104.0 -> 5.105.0) Subpackages: kwallet-tools kwalletd5 libKF5Wallet5 libkwalletbackend5-5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kwayland ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kwayland-integration ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * Implement SkipSwitcher state for plasma surfaces ==== kwidgetsaddons ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Allow searching 2-character strings (kde#449003) * Initialize KCharSelectTablePrivate::chr ==== kwin5 ==== Version update (5.27.3 -> 5.27.4) - Add patch to fix monitor settings issue on amdgpu (kde#468235): * 0001-backends-drm-set-the-scaling-mode-to-none.patch - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * Revert "backends/libinput: don't multiply v120 value by scroll speed" (kde#464592) * Improve Workspace::outputAt() * workspace: prevent dangling pointers in output order list * dpms: Make sure we are not calling the interface after the output is gone (kde#466346) * backends/drm: restrict common mode generation to drivers that support scaling * kcms/rules: Make Comboboxes bordered again * backends/drm: consider color property changes as failed when the output is off * wayland: Handle xdg_wm_base being destroyed before surface role * Avoid accidental creation of backing stores for offscreen surfaces (kde#465790) * inputmethod: Properly report that it's not visible * wayland: Truncate strings sent via plasmawindowmanager interface (kde#465775) * Simplify tile dismissal (kde#465740) * Fix picking drag target * Screencast: avoid using DMABufs exclusively to allow renegotiation ==== kwindowsystem ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== kwrited5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== kxmlgui ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== layer-shell-qt ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== lcms2 ==== Version update (2.14 -> 2.15) - update to 2.15: * New MESON build system, many thanks to amispark and Lovell Fuller for bringing this. * Fixed a bug that caused memory corruption on colord * cmsReadRawTag can read portions of tags again. Removing this caused colord to segfault when dumping profiles * Added more checks based of fuzzer discoveries. * MSYS2 can now compile lcms2 * Checked on Apple Silicon M1 and M2 * Fixed a bug of fastfloat plug-in that affected Krita CMYK color selector - drop 0001-fix-memory-corruption-when-unregistering-plugins.patch (upstream) ==== libKF5ModemManagerQt ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== libKF5NetworkManagerQt ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== libXfixes ==== Version update (6.0.0 -> 6.0.1) - add keyring validation - modernize spec file. install license and documentation - Update to version 6.0.1 * Fix spelling/wording issues * gitlab CI: add a basic build test * Remove unnecessary casts from malloc & free calls * Variable scope reduction as recommended by cppcheck * Mark two dpy parameters const as suggested by cppcheck * Quiet -Wconditional-uninitialized warnings from clang * Resolve 36 of 40 -Wextra-semi-stmt warnings from clang * Handle 63 of 63 -Wshorten-64-to-32 warnings from clang * Handle 60 of 60 -Wimplicit-int-conversion warnings from clang * Handle 6 of 9 -Wsign-conversion warnings from clang * XFixesCloseDisplay: Mark codes as unused * Require LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL * Remove "All rights reserved" from Oracle copyright notices ==== libXft ==== Version update (2.3.7 -> 2.3.8) - Updat to version 2.3.8 * configure: Use LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL * add check for missing glyph in XftFontCheckGlyph() * issue 17: libxft-2.3.7: Bold fonts in urxvt missing leftmost pixels * issue 18: Problems with rotated text (monospace font only) ==== libXpm ==== Version update (3.5.14 -> 3.5.16) - update to 3.5.16: * test: skip compressed file tests when --disable-open-zfile is used * gitlab CI: build with each of --enable-open-zfile & --disable-open-zfile * configure: correct error message to suggest --disable-open-zfile * open-zfile: Make compress & uncompress commands optional * Require LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL * XpmCreateDataFromXpmImage: Fix misleading indentation * parse.c: Wrap FREE_CIDX definition in do { ... } while(0) * parse.c: remove unused function xstrlcpy() * test: Use PACKAGE_BUGREPORT instead of hard-coded URL's * test: Add simple test cases for functions in src/rgb.c * xpmReadRgbNames: constify filename argument * Fix a memleak in ParsePixels error code path - with switching to suggests making use of (n)compress no longer needs to be limited to openSUSE - suggests instead of require compress (see changelog below) - require compress (ncompress package) on openSUSE; it's not supported on SLE - Drop n_no-compress-on-sle.patch and set XPM_PATH_COMPRESS instead (xpmPipeThrough function returns NULL when the command is not available; so same result as with the patch applied; that the child process for executing 'compress' returns with exit(1) doesn't matter much; it might even be useful to see the error message ...) - Depend also on /usr/bin/uncompress, not only /usr/bin/gzip; Requiring binaries instead of packages resolves the file conflict with busybox-gzip, which is used when building nginx opensuse images; dep chain was: nginx -> libdg3 -> libXpm4 -> gzip ==> conflict with busybox-gzip - Depend on /usr/bin/gzip, not gzip - n_no-compress-on-sle.patch * we can't handle .Z files, since we don't have ncompress package on SLE; so disable this feature as before (bsc#1207031) - BuildRequires * removed again ncompress * added again autoconf, automake, libtool - run again autoreconf due to patch above - update to 3.5.15: * Use gzip -d instead of gunzip * Prevent a double free in the error code path * Fix CVE-2022-4883: compression commands depend on $PATH * Fix CVE-2022-44617: Runaway loop with width of 0 and enormous height * test: add test cases for CVE-2022-44617 (zero-width w/enormous height) * Fix CVE-2022-46285: Infinite loop on unclosed comments * test: add test case for CVE-2022-46285 (unclosed comments) * cxpm: getc/ungetc wrappers should not adjust position when c == EOF * test: Add unit tests using glib framework * configure: add --disable-open-zfile instead of requiring -DNO_ZPIPE * man pages: Apply standard man page style/formatting * man pages: Replace "See Also" entries with more useful ones * man pages: Fix typos and other minor editing - drop U_0001-configure-add-disable-open-zfile-instead-of-requirin.patch, U_0002-Fix-CVE-2022-46285-Infinite-loop-on-unclosed-comment.patch, U_0004-Fix-CVE-2022-44617-Runaway-loop-with-width-of-0-and-.patch, U_0005-Fix-CVE-2022-4883-compression-commands-depend-on-PAT.patch, U_regression-bug1207029_1207030_1207031.patch U_regression2-bug1207029_1207030_1207031.patch: upstream - switch urls to https - spec file cleanups - add gpg keyring validation ==== libXt ==== Version update (1.2.1 -> 1.3.0) - update to 1.3.0 * gitlab CI: add a basic build test * Fix spelling/wording issues * gitlab CI: stop requiring Signed-off-by in commits * Use memcpy() instead of memmove() when buffers are known not to overlap * Use memcpy() instead of XtMemmove() when buffers are known to differ * tests: update g_test_bug_base url from bugzilla to gitlab * tests: Use XORG_MEMORY_CHECK_FLAGS from xorg-macros 1.16 * tests: Replace g_assert() calls with g_assert_*() calls * configure.ac: Replace HAVE_LIBRARY with AC_CHECK_LIB * Add xfilesearchpath to xt.pc * TMstate.c: Handle -Wduplicated-branches warnings * Remove "All rights reserved" from Oracle copyright notices * configure: Use LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL * test: Add unit tests for XtMalloc, XtCalloc, & XtRealloc * Add XtReallocArray() for overflow checking of multiplied args * Replace XtRealloc() calls with XtReallocArray() * Replace XtMalloc() calls with XtMallocArray() * Define LONG64 if __SIZEOF_LONG__ indicates 64-bit long * XtArgVal: Support architectures where pointers are bigger than long * Use XtUIntPtr for integer types that can hold pointers * Cast via intptr_t when converting integers to pointers * Fix XrmResource layout if pointers are bigger than long * Fix InternalCallbackRec layout if pointers are bigger than 64 bits * Support buttons > 5 in translation tables [v2] * add _X_NORETURN to agree with header-file * codespell-fixes * cppcheck and clang --analyze fixes * fixes for gcc13 warnings * cppcheck fixes (const, null dereferencing, uninitialized, scope) * cppcheck (revise IsDescendant() to fix possible null-dereference) * update copyright-date ==== libgcrypt ==== Version update (1.10.1 -> 1.10.2) - Update to 1.10.2: * Bug fixes: - Fix Argon2 for the case output > 64. [rC13b5454d26] - Fix missing HWF_PPC_ARCH_3_10 in HW feature. [rCe073f0ed44] - Fix RSA key generation failure in forced FIPS mode. [T5919] - Fix gcry_pk_hash_verify for explicit hash. [T6066] - Fix a wrong result of gcry_mpi_invm. [T5970] - Allow building with --disable-asm for HPPA. [T5976] - Allow building with -Oz. [T6432] - Enable the fast path to ChaCha20 only when supported. [T6384] - Use size_t to avoid counter overflow in Keccak when directly feeding more than 4GiB. [T6217] * Other: - Do not use secure memory for a DRBG instance. [T5933] - Do not allow PKCS#1.5 padding for encryption in FIPS mode. [T5918] - Fix the behaviour for child process re-seeding in the DRBG. [rC019a40c990] - Allow verification of small RSA signatures in FIPS mode. [T5975] - Allow the use of a shorter salt for KDFs in FIPS mode. [T6039] - Run digest+sign self tests for RSA and ECC in FIPS mode. [rC06c9350165] - Add function-name based FIPS indicator function. GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION. This is not considered an ABI changes because the new FIPS features were not yet approved. [rC822ee57f07] - Improve PCT in FIPS mode. [rC285bf54b1a, rC4963c127ae, T6397] - Use getrandom (GRND_RANDOM) in FIPS mode. [rCcf10c74bd9] - Disable RSA-OAEP padding in FIPS mode. [rCe5bfda492a] - Check minimum allowed key size in PBKDF in FIPS mode. [T6039,T6219] - Get maximum 32B of entropy at once in FIPS mode. [rCce0df08bba] - Prefer gpgrt-config when available. [T5034] - Mark AESWRAP as approved FIPS algorithm. [T5512] - Prevent usage of long salt for PSS in FIPS mode. [rCfdd2a8b332] - Prevent usage of X9.31 keygen in FIPS mode. [rC392e0ccd25] - Remove GCM mode from the allowed FIPS indicators. [rC1540698389] - Add explicit FIPS indicators for hash and MAC algorithms. [T6376] * Release-info: https://dev.gnupg.org/T5905 * Rebase FIPS patches: - libgcrypt-FIPS-SLI-hash-mac.patch - libgcrypt-FIPS-SLI-kdf-leylength.patch - libgcrypt-FIPS-SLI-pk.patch ==== libgpg-error ==== Version update (1.46 -> 1.47) - Update to 1.47: * New error codes for PUKs and reset codes. [T6421] * Avoid segv in logging with improper use of the "socket://". * Fixed translation of argparse's internal option --help. * Interface changes relative to the 1.46 release: - GPG_ERR_SOURCE_TKD NEW. - GPG_ERR_BAD_PUK NEW. - GPG_ERR_NO_RESET_CODE NEW. - GPG_ERR_BAD_RESET_CODE NEW. - GPGRT_SPAWN_KEEP_STDIN NEW. - GPGRT_SPAWN_KEEP_STDOUT NEW. - GPGRT_SPAWN_KEEP_STDERR NEW. - GPGRT_SPAWN_INHERIT_FILE NEW. * Release-info: https://dev.gnupg.org/T6231 ==== libkdecoration2 ==== Version update (5.27.3 -> 5.27.4) Subpackages: libkdecorations2-5 libkdecorations2-5-lang libkdecorations2private10 - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== libkscreen2 ==== Version update (5.27.3 -> 5.27.4) Subpackages: libKF5Screen8 libKF5ScreenDpms8 libkscreen2-plugin - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== libksysguard5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: ksysguardsystemstats-data libKSysGuardSystemStats1 libksysguard5-imports libksysguard5-plugins - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * Add translation domain before diving in subdirectories ==== libmemcached ==== Version update (1.0.18 -> 1.1.4) - Re-enable SASL support (boo#1210290) - Add requirement for libmemcachedprotocol0 to devel package - Update to new maintained fork of libmemcached - Update to 1.1.4: * Lot of bugfixes * Have a look at Changelog-1.1.md for the complete list of changes - Removed patches: * libmemcached-pthread.patch * libmemcached-automake1_14.diff * libmemcached-no-docs-available.patch * libmemcached-1.0.18-fix-build-gcc7.patch - Remove libmemcached.keyring ==== libnice ==== Subpackages: gstreamer-libnice libnice10 - Add libnice-port-gupnp-igd-bump.patch: Port to new gupnp-igd. - Replace libgupnp-igd-devel and gobject-introspection-devel with pkgconfig(gupnp-igd-1.6) and pkgconfig(gobject-introspection-1.0) BuildRequires, align with what meson checks for. - Use ldconfig_scriptlets macro. - Enable meson_test macro in check section, run tests during build. Remove the single test that does not work in the build service via sed call. ==== libopenmpt ==== Version update (0.6.9 -> 0.6.10) - Update to 0.6.10 * [Bug] File probing and loading results could be inconsistent for SFX files, so that probing could claim that a file is definitely not playable even if it would be. * MOD: VBlank heuristics are now applied to MOD files with M!K! signature. Fixes mod.siedler ii. * NoiseTracker MODs are now always played with VBlank timing. * MED: Add support for default instrument pitch. * MED: Global play transpose value was not considered for MMD0 files. * 669: Reject files with lots of control characters in song message. * mpg123: Update to v1.31.3 (2023-03-19). ==== libpcap ==== Version update (1.10.3 -> 1.10.4) - update to 1.10.4: * rpcap: Fix name of launchd service. * documentation updates and build system tweaks ==== libqmi ==== Version update (1.30.8 -> 1.32.4) Subpackages: libqmi-glib5 libqmi-tools - Update to version 1.32.4: * libqmi-glib: Schedule indications with G_PRIORITY_DEFAULT to ensure correct processing order between responses and ndications. * build: If QRTR enabled the pkg-config should publicly require libqrtr-glib. - Changes from version 1.32.2: * libqmi-glib: fixed message header validation to avoid reading out of bounds. * qmi-proxy: added --verbose-full flag to allow printing logs with personal info included. - Changes from version 1.32.0: * There is no longer an upstream-provided source tarball, please use the signed git tag '1.32.0' instead to refer to the sources of this release. * The verbose message logging will now by default hide all fields that are considered personal information. Extended message logging including all field contents should be explicitly requested. * Build: - The GNU autotools (autoconf/automake/libtool) support has been fully removed, this release requires the use of the meson build system. - The 'instrospection' meson option is now a boolean. - New boolean 'man' meson option to allow disabling the man page generation. * New services: New 'FOX' service for operations defined by Foxconn, including "Get Firmware Version" for now. * qmicli: - New '--verbose-full' option to request enabling logs that include personal information. - New '--pdc-monitor-refresh' command. - New '--gas-dms-set-usb-composition' and '--gas-dms-get-usb-composition' commands. - New '--wms-set-routes' command. - New '--dsd-get-system-status' command. - Updated the '--wda-set-data-format' command with new optional fields to configure the uplink data aggregation max size and max datagrams. * Several other minor improvements and fixes. - Switch to meson buildsystem, add meson BuildRequires and macros. - Add help2man, pkgconfig(bash-completion) and pkgconfig(gobject-introspection-1.0) BuildRequires: New dependencies. - Use ldconfig_scriptlets macro. - New home, URL and Source. - Drop sig and keyfile, no longer available. ==== libqt5-qtbase ==== Version update (5.15.8+kde183 -> 5.15.8+kde185) Subpackages: libQt5Concurrent5 libQt5Core5 libQt5DBus5 libQt5Gui5 libQt5Network5 libQt5PrintSupport5 libQt5Sql5 libQt5Sql5-sqlite libQt5Test5 libQt5Widgets5 libQt5Xml5 libqt5-qtbase-platformtheme-gtk3 - Update to version 5.15.8+kde185: * QFSFileEngine: fix overflow bug when using lseek64 * Add QImage null check when QOpenGLTexture converts - Add patch to fix return key handling in QGroupBox on GNOME (bsc#1209364): * 0001-Revert-QGnomeTheme-Allow-Space-Return-Enter-and-Sele.patch - Add patch to fix XInput2 events in big-endian X11 clients (bsc#1204883, QTBUG-105157): * big-endian-scroll.patch ==== libqt5-qtwebengine ==== - Add patch to fix build with GCC 13 (boo#1207469): * 0001-Fixes-for-building-with-GCC-13.patch ==== libsolv ==== Version update (0.7.23 -> 0.7.24) Subpackages: libsolv-tools python3-solv ruby-solv - handle learnt rules in solver_alternativeinfo() - support x86_64_v[234] architecture levels - implement decision sorting for package decisionlists - add back findutils requires for the libsolv-tools packagse [bsc#1195633] - bump version to 0.7.24 ==== libstorage-ng ==== Version update (4.5.92 -> 4.5.96) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Georgian) (bsc#1149754) - 4.5.96 - merge gh#openSUSE/libstorage-ng#925 - disable NVMe detection since it is not correct - 4.5.95 - merge gh#openSUSE/libstorage-ng#924 - added GitHub Action using Fedora - 4.5.94 - merge gh#openSUSE/libstorage-ng#923 - detect transport for NVMe disks (bsc#1210144) - cleanup - 4.5.93 ==== libtomcrypt ==== - Modernise spec file - Run tests during build ==== libva ==== Version update (2.17.0 -> 2.18.0) Subpackages: libva-drm2 libva-x11-2 libva2 - Update to version 2.18.0: * doc: Add build and install libva informatio in home page. * fix: - Add libva.def into distribution package - NULL check before calling strncmp. - Remove reference to non-existent symbol * meson: docs: - Add encoder interface for av1 - Use libva_version over project_version() * va: - Add VAProfileH264High10 - Always build with va-messaging API - Fix the codying style of CHECK_DISPLAY - Remove Android pre Jelly Bean workarounds - Remove dummy isValid() hook - Remove unused drm_sarea.h include & ANDROID references in va_dricommon.h - va/sysdeps.h: remove Android section * x11: - Allow disabling DRI3 via LIBVA_DRI3_DISABLe env var - Use LIBVA_DRI3_DISABLE in GetNumCandidates - Switch to multibuild style. Drop libva-gl.spec|changes and pre_checkin.sh. - Switch to meson build system, add meson BuildRequires, drop libtool and xz BuildRequires, and replace gcc-c++ with generic c++_compiler. - Use autosetup and ldconfig_scriptlets macros. - Add libva-wayland to baselibs.conf, now that its build have moved to the main part of spec, source validator should no longer complain on SLE. - Drop propagate-dpy.patch: The upstream issue was closed without the patch ever getting applied, and the issue that it fixed was deemed to not be a libva issue. See upstream issue: https://github.com/intel/libva/issues/479 ==== libva-gl ==== Version update (2.17.0 -> 2.18.0) - Update to version 2.18.0: * doc: Add build and install libva informatio in home page. * fix: - Add libva.def into distribution package - NULL check before calling strncmp. - Remove reference to non-existent symbol * meson: docs: - Add encoder interface for av1 - Use libva_version over project_version() * va: - Add VAProfileH264High10 - Always build with va-messaging API - Fix the codying style of CHECK_DISPLAY - Remove Android pre Jelly Bean workarounds - Remove dummy isValid() hook - Remove unused drm_sarea.h include & ANDROID references in va_dricommon.h - va/sysdeps.h: remove Android section * x11: - Allow disabling DRI3 via LIBVA_DRI3_DISABLe env var - Use LIBVA_DRI3_DISABLE in GetNumCandidates - Switch to multibuild style. Drop libva-gl.spec|changes and pre_checkin.sh. - Switch to meson build system, add meson BuildRequires, drop libtool and xz BuildRequires, and replace gcc-c++ with generic c++_compiler. - Use autosetup and ldconfig_scriptlets macros. - Add libva-wayland to baselibs.conf, now that its build have moved to the main part of spec, source validator should no longer complain on SLE. - Drop propagate-dpy.patch: The upstream issue was closed without the patch ever getting applied, and the issue that it fixed was deemed to not be a libva issue. See upstream issue: https://github.com/intel/libva/issues/479 - update to 2.17.0: * win: Simplify signature for driver name loading * win: Rewrite driver registry query and fix some bugs/leaks/inefficiencies * win: Add missing null check after calloc * va: Update security disclaimer * dep:remove the file .cvsignore * pkgconfig: add 'with-legacy' for emgd, nvctrl and fglrx * meson: add 'with-legacy' for emgd, nvctrl and fglrx * x11: move all FGLRX code to va_fglrx.c * x11: move all NVCTRL code to va_nvctrl.c * meson: stop using deprecated meson.source_root() * meson: stop using configure_file copy=true * va: correctly include the win32 (local) headers * win: clean-up the coding style * va: dos2unix all the files * drm: remove unnecessary dri2 version/extension query * trace: annotate internal functions with DLL_HIDDEN * build/sysdeps: Remove HAVE_GNUC_VISIBILITY_ATTRIBUTE and use _GNUC_ support level attribute instead * meson: Check support for -Wl,-version-script and build link_args accordingly * meson: Set va_win32 soversion to '' and remove the install_data rename * fix: resouce check null * va_trace: Add Win32 memory types in va_TraceSurfaceAttributes * va_trace: va_TraceSurfaceAttributes should check the VASurfaceAttribMemoryType * va: Adds Win32 Node and Windows build support * va: Adds compat_win32 abstraction for Windows build and prepares va common code for windows build * pkgconfig: Add Win32 package for when WITH_WIN32 is enabled * meson: Add with_win32 option, makes libdrm non-mandatory on Win * x11: add basic DRI3 support * drm: remove VA_DRM_IsRenderNodeFd() helper * drm: add radeon drm + radeonsi mesa combo ==== libyui ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libyui-ncurses ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libyui-ncurses-pkg ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libyui-qt ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libyui-qt-graph ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libyui-qt-pkg ==== Version update (4.5.0 -> 4.5.1) - Qt UI: Fixed loading icons from an absolute path (bsc#1210591) https://github.com/libyui/libyui/pull/94 - 4.5.1 ==== libzypp ==== Version update (17.31.8 -> 17.31.10) - BuildRequires: libsolv-devel >= 0.7.24 for x86_64_v[234] support. - version 17.31.10 (22) - Workround bsc#1195633 while libsolv <= 0.7.23 is used. - Fix potential endless loop in new ZYPP_MEDIANETWORK. - ZYPP_METALINK_DEBUG=1: Log URL and priority of the mirrors parsed from a metalink file. - multicurl: propagate ssl settings stored in repo url (boo#1127591) Closes #335. - Teach MediaNetwork to retry on HTTP2 errors. - fix CapDetail to return Rel::NONE if an EXPRESSION is used as a NAMED cap. - Capability: support parsing richdeps from string. - defaultLoadSystem: default to LS_NOREFRESH if not root. - Detect x86_64_v[234]: Fix LZCNT bit used in detection (fixes [#439]) Merges rpm-software-management/rpm#2412: The bit for LZCNT is in CPUID 0x80000001, not 1. - Detect x86_64_v[234] architecture levels (fixes #439) - Support x86_64_v[234] architecture levels (for #439) - version 17.31.9 (22) ==== llvm16 ==== Version update (16.0.0 -> 16.0.1) - Update to version 16.0.1. * This release contains bug-fixes for the LLVM 16.0.0 release. This release is API and ABI compatible with 16.0.0. - Rebase llvm-do-not-install-static-libraries.patch. ==== lua54 ==== - Added more numbered patches from upstream: * luabugs11.patch ==== mdadm ==== - sysconfig.mdadm: Remove ServiceRestart line to mdadm since there is not such systemd service. (bsc#1203491) ==== microos-tools ==== Version update (2.20 -> 2.20+git20230413.2a43cdb) - Update to version 2.20+git20230413.2a43cdb: * Drop extra sysctl file for coredumps (boo#1091684) - remove conflict with systemd-coredump (boo#1091684). There is no actual conflict. It actually works fine to install systemd-coredump in addition. ==== milou5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: milou5-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== mobile-broadband-provider-info ==== Version update (20221107 -> 20230416) - Update to version 20230416: * MAINTAINERS: update from mobile-broadband-provider-info.doap * ua: fix +7Telecom * all: include a in * ru: add Vainah Telecom * ru: add Tinkoff Mobile * ru: add STS * ru: add SberMobile * ru: add Phoenix * ru: add Letai * ru: add Gazprombank Mobile * ru: add +7Telecom * ru: add VTB Mobile * ua: add Win Mobile * ua: add Volna mobile * ua: add Krymtelekom * ru: update operators * ru: clean up old operators * ca: add Rogers LTE APNs * gb:Add Superdrug Mobile * dk: Update Telenor DNS * pk: unbreak Pakistani MCC * doap: add Guido to maintainer list * us: AT&T: add RESELLER as MVNO APN ==== mozilla-nss ==== Version update (3.88.1 -> 3.89) Subpackages: libfreebl3 libfreebl3-hmac libsoftokn3 libsoftokn3-hmac mozilla-nss-certs - update to NSS 3.89 * bmo#1820834 - revert freebl/softoken RSA_MIN_MODULUS_BITS increase * bmo#1820175 - PR_STATIC_ASSERT is cursed * bmo#1767883 - Need to add policy control to keys lengths for signatures * bmo#1820175 - Fix unreachable code warning in fuzz builds * bmo#1820175 - Fix various compiler warnings in NSS * bmo#1820175 - Enable various compiler warnings for clang builds * bmo#1815136 - set PORT error after sftk_HMACCmp failure * bmo#1767883 - Need to add policy control to keys lengths for signatures * bmo#1804662 - remove data length assertion in sec_PKCS7Decrypt * bmo#1804660 - Make high tag number assertion failure an error * bmo#1817513 - CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384 * bmo#1815167 - Tolerate certificate_authorities xtn in ClientHello * bmo#1789436 - Fix build failure on Windows * bmo#1811337 - migrate Win 2012 tasks to Azure * bmo#1810702 - fix title length in doc * bmo#1570615 - Add interop tests for HRR and PSK to GREASE suite * bmo#1570615 - Add presence/absence tests for TLS GREASE * bmo#1804688 - Correct addition of GREASE value to ALPN xtn * bmo#1789436 - CH extension permutation * bmo#1570615 - TLS GREASE (RFC8701) * bmo#1804640 - improve handling of unknown PKCS#12 safe bag types * bmo#1815870 - use a different treeherder symbol for each docker image build task * bmo#1815868 - pin an older version of the ubuntu:18.04 and 20.04 docker images * bmo#1810702 - remove nested table in rst doc * bmo#1815246 - Export NSS_CMSSignerInfo_GetDigestAlgTag * bmo#1812671 - build failure while implicitly casting SECStatus to PRUInt32 ==== mozjs102 ==== Version update (102.9.0 -> 102.10.0) - Update to version 102.10.0: + Various security fixes. + CVE-2023-29531: Out-of-bound memory access in WebGL on macOS + CVE-2023-29532: Mozilla Maintenance Service Write-lock bypass + CVE-2023-29533: Fullscreen notification obscured + MFSA-TMP-2023-0001: Double-free in libwebp + CVE-2023-29535: Potential Memory Corruption following Garbage Collector compaction + CVE-2023-29536: Invalid free from JavaScript code + CVE-2023-29539: Content-Disposition filename truncation leads to Reflected File Download + CVE-2023-29541: Files with malicious extensions could have been downloaded unsafely on Linux + CVE-2023-29542: Bypass of file download extension restrictions + CVE-2023-29545: Windows Save As dialog resolved environment variables + CVE-2023-1945: Memory Corruption in Safe Browsing Code + CVE-2023-29548: Incorrect optimization result on ARM64 + CVE-2023-29550: Memory safety bugs fixed in Firefox 112 and Firefox ESR 102.10 - Replace clang-devel and llvm-devel with clang and llvm-gold BuildRequires. ==== mutter ==== Version update (44.0+18 -> 44.0+54) - Update to version 44.0+54: + backends/stage: Pass ClutterFrame to MetaStageWatchFunc + clutter/paint-context: Allow assigning a ClutterFrame + clutter/stage: Assign frames to paint context + core: - Create passive button grab on topmost Window - Minor refactor - Pass MetaWindow on passive button grab machinery + cursor-tracker: Enhance the documentation and increase annotation coverage + dnd: Clear Wayland drag source when cancelled from stage grab context + frames/content: Use gtk_widget_compute_point() + frames: Forward _NET_WM_STATE during frame initialization + output-xrandr: - Consistently return -1 on error - Don't treat 0 as invalid backlight value + screen-cast/monitor-src: - Record DMA-BUF frames immediately - Record frames with presentation time + screen-cast/src: - Add frame recording variant with timestamp - Clean up DMA-BUF only error paths + screen-cast-stream-src: - Shuffle a variable around - Export damaged video regions - Minor adjustment + stage-impl: Do clipped redraws when drawing offscreen + wayland/data-device: Clear data source when cancelling drag with ESC + wayland: - Don't leak XDnD mime type strings - Set compositor when creating MetaWaylandDataSourceXWayland + wayland/xdg-shell: - Dismiss instead of destroy invalid popup - Ignore reposition if popup was dismissed + workspace: Only consider windows that should be showing as focusable + x11: - Fix remaining leaks from switch to XGetAtomName() - Remove unused member variables from MetaX11SelectionInputStream - Use Atoms when constructing a new MetaX11SelectionOutputStream + xdg-shell: Early out of apply if dismissed - Add 2963.patch: xdg-shell: Always handle frame callbacks in popup_apply_state(). Fixes a crash in mutter. - Use auto(setup|patch) macros. - Update to version 44.0+24: + x11: Wrap X call with error traps. And pass Atom directly. This should make Mutter more resilient and avoid a type of crash on gnome-shell. + frames/window-tracker: Select StructureNotifyMask X11 events. + Updated translations. ==== ncurses ==== Version update (6.4.20230311 -> 6.4.20230408) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20230408 + document limitations of tparm, and error-returns in curs_terminfo.3x + document limitations of tgoto, and error-returns in curs_termcap.3x + add xterm+focus to alacritty+common (patch by Christian Duerr). + add "-v" option to tput, to show warnings. > improve checks for malformed terminfo data (report/analysis by Jonathan Bar Or, Michael Pearse, Emanuele Cozzi). + make the parameter type/count checks in _nc_tiparm() more stringent + update tgoto() to account for _nc_tiparm() changes + add checks in tparm() and tiparm() for misuse of string parameters + add special cases in tput to handle extensions Cs/Ms parameters + ignore compiled-terminfo where the array sizes exceed the standard - Skip gzipping manual pages as brp-compress does the job - Add ncurses patch 20230401 + modify experimental Windows driver to work with xterm mouse protocol. + remove DECCOLM+DECSCLM from foot (patch by Daniel Ekloef). ==== nghttp2 ==== Version update (1.51.0 -> 1.52.0) - update to 1.52.0: * https://nghttp2.org/blog/2023/02/13/nghttp2-v1-52-0/ * sphinx_rtd_theme has been removed from the repository and archive. * The deprecated Python bindings has been removed. * The deprecated libnghttp2_asio has been removed. * llhttp and neverbleed have been updated. * This release fixes the bug that stalls TLS connection. * This release adds more http3 integration tests. - drop nghttp2-remove-python-build.patch: obsolete as the code got removed ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0 - Remove "--strip" in SPEC file for meson build, so that debuginfo is generated. (from mwilck) (bsc#1210536) ==== open-vm-tools ==== Subpackages: libvmtools0 open-vm-tools-desktop - As per jsc-PED-1344, update spec file to only build the containerinfo plugin for TW/SLES 15 SP5 and newer. ==== openexr ==== Version update (3.1.6 -> 3.1.7) Subpackages: libIex-3_1-30 libIlmThread-3_1-30 libOpenEXR-3_1-30 - update to 3.1.7: * Patch release that fixes a build regression on ARMv7, and fixes a build issue with zlib. ==== openldap2 ==== Version update (2.6.3 -> 2.6.4) Subpackages: libldap-data libldap2 openldap2-client - update to 2.6.4: * Fixed client tools to remove 'h' and 'p' options * Fixed ldapsearch memory leak with paged results (ITS#9860) * Fixed libldap ldif_open_urlto check for failure (ITS#9904) * Fixed libldap ldap_url_parsehosts check for failure * Fixed liblunicode UTF8bvnormalize buffer size (ITS#9955) * Fixed lloadd memory leaks (ITS#9907) * Fixed lloadd shutdown code to protect memory correctly * Fixed lloadd race in epoch.c (ITS#9947) * Fixed lloadd potential deadlock with cn=monitor (ITS#9951) * Fixed lloadd to keep listener base around when not active * Fixed lloadd object reclamation sequencing (ITS#9983) * Fixed slapd memory leak with olcAuthIDRewrite (ITS#6035) * Fixed slapd free of redundant cmdline option (ITS#9912) * Fixed slapd transactions extended operations cleanup after * Fixed slapd deadlock with replicated cn=config * Fixed slapd connection close logic (ITS#9991) * Fixed slapd bconfig locking of cn=config entries (ITS#9045) * Fixed slapd-mdb max number of index databases to 256 * Fixed slapd-mdb to always release entries from ADD operations * Fixed slapd-mdb to fully init empty DN in tool_entry_get * Fixed slapd-monitor memory leaks with lloadd (ITS#9906) * Fixed slapd-monitor to free remembered cookies (ITS#9339) * Fixed slapo-accesslog reqStart ordering matching rule * Fixed slapo-deref memory leak (ITS#9924) * Fixed slapo-dynlist to ignore irrelevant objectClasses * Fixed slapo-dynlist to avoid unnecessary searches (ITS#9929) * Fixed slapo-dynlist to mark internal searches as such * Fixed slapo-pcache crash in consistency_check (ITS#9966) * Fixed slapo-remoteauth memory leaks (ITS#9438) * Fixed slapo-rwm memory leaks (ITS#9817) * Build Environment * Fixed ancient DOS related ifdef checks (ITS#9925) * Fixed build process to not use gmake specific features * Fixed source tree to remove symlinks (ITS#9926) * Fixed slapo-otp testdir creation (ITS#9437) * Fixed slapd-tester memory leak (ITS#9908) * Fixed usage of non-standard C syntax (ITS#9898, ITS#9899, ITS#9901) * Fixed usage of bashism (ITS#9900) * Fixed test suite portability (ITS#9931) * Documentation * Fixed ldap_bind(3) to document ber_bvfree in ldap_sasl_bind (ITS#9976) * Fixed slapo-asyncmeta(5) to clarify scheduling for target connections (ITS#9941) * Fixed slapo-dynlist(5) to clarify configuration settings (ITS#9957) * Fixed slapo-unique(5) to clarify when quoting should be used (ITS#9915) * Minor cleanup ==== openldap2-contrib-src ==== Version update (2.6.3 -> 2.6.4) - update to 2.6.4: * Fixed client tools to remove 'h' and 'p' options * Fixed ldapsearch memory leak with paged results (ITS#9860) * Fixed libldap ldif_open_urlto check for failure (ITS#9904) * Fixed libldap ldap_url_parsehosts check for failure * Fixed liblunicode UTF8bvnormalize buffer size (ITS#9955) * Fixed lloadd memory leaks (ITS#9907) * Fixed lloadd shutdown code to protect memory correctly * Fixed lloadd race in epoch.c (ITS#9947) * Fixed lloadd potential deadlock with cn=monitor (ITS#9951) * Fixed lloadd to keep listener base around when not active * Fixed lloadd object reclamation sequencing (ITS#9983) * Fixed slapd memory leak with olcAuthIDRewrite (ITS#6035) * Fixed slapd free of redundant cmdline option (ITS#9912) * Fixed slapd transactions extended operations cleanup after * Fixed slapd deadlock with replicated cn=config * Fixed slapd connection close logic (ITS#9991) * Fixed slapd bconfig locking of cn=config entries (ITS#9045) * Fixed slapd-mdb max number of index databases to 256 * Fixed slapd-mdb to always release entries from ADD operations * Fixed slapd-mdb to fully init empty DN in tool_entry_get * Fixed slapd-monitor memory leaks with lloadd (ITS#9906) * Fixed slapd-monitor to free remembered cookies (ITS#9339) * Fixed slapo-accesslog reqStart ordering matching rule * Fixed slapo-deref memory leak (ITS#9924) * Fixed slapo-dynlist to ignore irrelevant objectClasses * Fixed slapo-dynlist to avoid unnecessary searches (ITS#9929) * Fixed slapo-dynlist to mark internal searches as such * Fixed slapo-pcache crash in consistency_check (ITS#9966) * Fixed slapo-remoteauth memory leaks (ITS#9438) * Fixed slapo-rwm memory leaks (ITS#9817) * Build Environment * Fixed ancient DOS related ifdef checks (ITS#9925) * Fixed build process to not use gmake specific features * Fixed source tree to remove symlinks (ITS#9926) * Fixed slapo-otp testdir creation (ITS#9437) * Fixed slapd-tester memory leak (ITS#9908) * Fixed usage of non-standard C syntax (ITS#9898, ITS#9899, ITS#9901) * Fixed usage of bashism (ITS#9900) * Fixed test suite portability (ITS#9931) * Documentation * Fixed ldap_bind(3) to document ber_bvfree in ldap_sasl_bind (ITS#9976) * Fixed slapo-asyncmeta(5) to clarify scheduling for target connections (ITS#9941) * Fixed slapo-dynlist(5) to clarify configuration settings (ITS#9957) * Fixed slapo-unique(5) to clarify when quoting should be used (ITS#9915) * Minor cleanup ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Rename sshd.pamd to sshd-sle.pamd and fix order of pam_keyinit - Add new sshd.pamd including postlogin-* config files ==== oxygen5-sounds ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== pam-config ==== Version update (2.2 -> 2.4) - Update to version 2.4 - Read postlogin files, too - Update to version 2.3 - Add silent_if option for pam_lastlog2 ==== pam_kwallet ==== Version update (5.27.3 -> 5.27.4) Subpackages: pam_kwallet-common - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * Exit early if the target user is root * Don't do anything if the password is empty * Verify that XDG_RUNTIME_DIR is usable - Drop patches, now upstream: * 0001-Verify-that-XDG_RUNTIME_DIR-is-usable.patch * 0002-Don-t-do-anything-if-the-password-is-empty.patch * 0003-Exit-early-if-the-target-user-is-root.patch ==== patterns-base ==== Subpackages: patterns-base-base patterns-base-bootloader patterns-base-documentation patterns-base-enhanced_base patterns-base-minimal_base patterns-base-sw_management patterns-base-x11 patterns-base-x11_enhanced - base: Add lastlog2 as Y2038 safe lastlog replacement ==== patterns-gnome ==== Subpackages: patterns-gnome-gnome_basic patterns-gnome-gnome_basis patterns-gnome-gnome_basis_opt patterns-gnome-sw_management_gnome - Replace gedit with gnome-text-editor as default editor. Following this, drop all gedit-plugins Suggests. - Downgrade glade Recommends to Suggests in gnome_ide pattern. ==== patterns-kde ==== Version update (20221001 -> 20230403) Subpackages: patterns-kde-kde_plasma patterns-kde-kde_yast - Add the qt6-grpc and qt6-location devel packages to the Qt6 pattern. ==== patterns-microos ==== Subpackages: patterns-microos-alt_onlyDVD patterns-microos-apparmor patterns-microos-base patterns-microos-base-microdnf patterns-microos-base-packagekit patterns-microos-base-zypper patterns-microos-basesystem patterns-microos-cloud patterns-microos-cockpit patterns-microos-defaults patterns-microos-desktop-common patterns-microos-desktop-gnome patterns-microos-desktop-kde patterns-microos-hardware patterns-microos-ima_evm patterns-microos-onlyDVD patterns-microos-ra_agent patterns-microos-ra_verifier patterns-microos-selinux patterns-microos-sssd_ldap - Add discover-backend-fwupd for automated firmware updates on plasma - Use lastlog2 as Y2038 safe lastlog replacement - Add Requires kio-fuse and kdenetwork-filesharing to kde pattern (boo#1210125) - Add systemd-coredump to defaults (boo#1091684) - remove systemd-logger requirement from defaults. It got merged into the main package meanwhile. ==== pipewire ==== Version update (0.3.67 -> 0.3.69) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add patch from upstream for https://bugs.archlinux.org/task/78195 * 0001-Revert-alsa-mixer-allow-to-re-attach-the-mixer-control.patch - Add patch from upstream to fix some potentially broken devices: * 0002-alsa-fix-area-pointers.patch - Only apply reduce-meson-dependency.patch when meson present during build is too old. - Add patch to build pipewire in Leap 15.4: * reduce-meson-dependency.patch - Update to version 0.3.69: * Highlights: - Reverted the UCM changes, they seem to cause regressions causing audio to be muted in some cases. - Fix a regression in the scheduler where a driver node might not be marked as runnable in some cases, like when echo-cancel is used. - Handle links from the driver to itself. This makes the midi bridge work again. - ALSA rate matching for sources was fixed. It would previously wait too long for rate matching and then cause drift. This should reduce crackling and stuttering whan capturing in low latency. - Fix the GStreamer clock to make cheese video recording work again. - More fixes and improvements. * PipeWire: - Fix a regression in the scheduler where a driver node might not be marked as runnable in some cases, like when echo-cancel is used. - Handle links from the driver to itself. This makes the midi bridge work again. - Some man pages were improved. - Fix a potential crash when thread-loop is destroyed before the loop. * Modules: - A new raw biquad filter was added to filter-chain. You can manually set the 6 parameters and you can use this to create custom filters per sample rate. - The echo-canceller now supports different channels for the capture and playback streams. * SPA: - A SB Audigy specific profile set was added to make better use of the controls. - More ALSA IRQ based scheduling improvements. - ALSA rate matching for sources was fixed. It would previously wait too long for rate matching and then cause drift. This should reduce crackling and stuttering whan capturing in low latency. - The echo-cancel plugin API has a new method to make it possible to have different channels for capture, source and playback. - Reverted the UCM changes, they seem to cause regressions causing audio to be muted in some cases. * Bluetooth: - Many more BAP fixes and improvements. Devices are now created as a set and can be combined into one device by the session manager. * GStreamer: - Fix the GStreamer clock to make cheese video recording work again. - Enable gstreamer-device-provider (rh#2183691). - Update to version 0.3.68: * Highlights: - Symbolic links to the pipewire binary are now used instead of recompiling the same binary multiple times. - Changes to the graph scheduler related to quantum/rate updates and calculation of the node states. Things should start and switch between quantums and rates more smoothly now and especially virtual devices should now only run when required. - A new RTP session module was added. This uses the Apple MIDI protocol to configure low-latency bidirectional MIDI (and with a PipeWire specific extension, also audio) between machines. OPUS encoding was added to the RTP formats. The SAP module was separated from the rtp-sink/source module to make it more usable. - A new runtime debug property was added to all streams and nodes to trigger a save of the raw samples to a wav file. Support for this has also been added to the echo-canceler to debug potential issues. - Module pulse-tunnel has improved rate matching and synchronisation support. It should also not drift anymore for capture devices. - The link-factory now ignores by default the link.passive property. This means that tools like pw-link or jack clients and wireplumber can't make passive links anymore. The reason is that there is now much more advanced logic in PipeWire itself to handle passive links based on node and port properties. - The RAOP sink was ported to new OpenSSL functions. Digest passwords are handled correctly now and support for more devices was added. - The ACP code was updated with new PulseAudio UCM code: "Create multiple profiles per verb for conflicting devices". This might change the names of devices, profiles and ports so scripts might need to be updated. - Upmixing is disabled again by default. We now ship config files that distros can install to enable upmixing again. The reason being that PipeWire should not apply fancy DSP processing to audio by default. ... changelog too long, skipping 101 lines ... - Sort the device by priority in deviceprovider. ==== plasma-browser-integration ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma-framework ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Plasma5 plasma-framework-components - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * DataEngines: Add forward compatibility as a porting aid * containmentinterface: get applet position when menu key is pressed ==== plasma-nm5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: plasma-nm5-openconnect plasma-nm5-openvpn - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma5-addons ==== Version update (5.27.3 -> 5.27.4) Subpackages: plasma5-addons-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * wallpapers/potd: replace `anchor.{left,right}` with `Layout.fillWidth` * ProfilesModel: Add placeholder for option "Start Kate (no arguments)" (kde#464724) ==== plasma5-desktop ==== Version update (5.27.3 -> 5.27.4) Subpackages: plasma5-desktop-emojier - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * applets/taskmanager: don't refresh virtual desktop info when menu item is not enabled * applets/taskmanager: skip updating tooltip when it's disabled (kde#467709) * Divide minimum panel size by two when not floating (kde#466098) * applets/taskmanager: press menu key to open task menu * applets/kicker: Hide separators when sorted alphabetically (kde#465865) * Activate Emoji Selector using emoji key ==== plasma5-disks ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma5-integration ==== Version update (5.27.3 -> 5.27.4) Subpackages: plasma5-integration-plugin plasma5-integration-plugin-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma5-openSUSE ==== Subpackages: plasma5-defaults-openSUSE plasma5-theme-openSUSE plasma5-workspace-branding-openSUSE sddm-theme-openSUSE - Update to 5.27.4 ==== plasma5-pa ==== Version update (5.27.3 -> 5.27.4) Subpackages: plasma5-pa-lang - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * kcm: stop setting sourceSize in avatar * kcm/DeviceListItem: Set width for comboboxes, with correctly sized popup * applet: add missing function for "Show virtual devices" menu item (kde#465996) ==== plasma5-systemmonitor ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma5-thunderbolt ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== plasma5-workspace ==== Version update (5.27.3 -> 5.27.4.1) Subpackages: gmenudbusmenuproxy plasma5-session plasma5-session-wayland plasma5-workspace-libs xembedsniproxy - Recommend filelight (boo#1210331) - Update to 5.27.4.1 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * applets/systemtray: press and hold to open context menu for plasmoids * applets/digital-clock: reload timezone after saving in Datetime KCM (kde#467494) * components/keyboardlayout: Fix forced activation of vkbd * Create directory before installing session-local * applets/systemtray: fix menu key not working in SNI * Find PkgConfig before first call to pkg_check_modules * sddm-theme: Populate keyboard layouts menu only on first show * [dashboard] Skip task switcher * klipper: test bug 465225 * systemtraytest: take screenshot only when test fails * kcms/nightcolor: fix timing strings with narrow window widths * libtaskmanager: simplify `test_openCloseWindow` ==== podman ==== Version update (4.4.4 -> 4.5.0) Subpackages: podman-cni-config - Update to version 4.5.0: * Release v4.5.0 * [CI:DOCS] Final release notes for v4.5.0 * Quadlet - do not set log-driver by default * Return title fields as a list * Bump to v4.5.0-dev * Bump to v4.5.0-RC2 * Final release notes for v4.5.0-RC2 * test/e2e: remove unnecessary SkipIfNetavark() calls * test/e2e: deduplicated network test * docs: update podman-network-create.1 * network create: add --interface-name * test/system/252-quadlet.bats: fix flake * Read kube_generate_type from containers.conf * Debian setup: workaround for runc /dev/char/10:200 bug * pkg/rootless: use catatonit from /usr/libexec/podman * rootless: make sure we only use a single pause process * Use atomic config writing strategy for podman machine config files * Add remaining release notes for v4.5.0-RC2 * GHA: Use version instead of SHA for actions * chore(deps): update dependency containers/automation_images to v20230405 * build: pass env by reference * test: retrofit error message * test/system: expect 12 char for short id * vendor: bump containers/(storage, common, buildah, image) * [skip-ci] Update actions/upload-artifact action to v3 * [skip-ci] Update actions/stale action to v8 * [skip-ci] Update actions/setup-go action to v4 * [skip-ci] Update github/issue-labeler action to v2.6 * Fix up codespell errors * Capitalize all uid,gid and id words that are not options in docs * build(deps): bump golang.org/x/tools from 0.7.0 to 0.8.0 in /test/tools * Properly remove the service container during kube down * quadlet: add `UserNS` option key * [CI:DOCS] Release notes for 4.5.0 Part 1 * "podman pull by digest and list --all" test: untag instead of rmi * build(deps): bump golang.org/x/text from 0.8.0 to 0.9.0 * Add renovate.json configuration * CI: postbuild step: skip under nightly treadmill * The `--ulimit` option accepts the name with an `RLIMIT_` prefix both upper and lower case * test/e2e: use custom network config dir where needed * chore: replace `github.com/ghodss/yaml` with `sigs.k8s.io/yaml` * update completion scripts for cobra v1.7.0 * libpod.storageService.CreateContainerStorage(): retrieve ID maps * Fix invalid pod name and hostname during kube generate * e2e tests: fix racy flakes * Cirrus: Enable labeling of EC2 VMs * Cirrus: Fix aarch64 clone_script 404 errors * e2e: GinkgoParallelNode() -> ...Process() * build(deps): bump github.com/spf13/cobra from 1.6.1 to 1.7.0 * build(deps): bump golang.org/x/sys from 0.6.0 to 0.7.0 * [CI:DOCS] --creds and registries * Copr: fix build deps for /usr/bin/envsubst * Don't error when removing non-existant env vars * e2e: healthcheck on stopped container: fix flake * test/apiv2/80-kube.at * test/apiv2/80-kube.at * system service: do not close Body * rm `hack/release.sh` * build(deps): bump github.com/onsi/gomega from 1.27.5 to 1.27.6 * add `quadlet -version` flag * add version/rawversion package * quadlet: use `Flag` suffix for variables * quadlet: implement `Tmpfs` option * Bump to v4.5.0-dev * Bump to 4.5.0-rc1 * Update release notes from 4.4 branch * rootless netns: recover from invalid netns * System tests: unverbosify a flake log * Add support for secret exists * Fix Win install task failures with large PR bodies * docs: add `starting` to `HealthCheckResults.Status` * Add support for cgroup_config from containers.conf * libpod: mount safely subpaths * Support Deployment generation with kube generate * Use secret.items to create volume mounts if present * [CI:DOCS] fix typo in --systemd option * rootless: drop preexec hook error message * Edit the docker wrapper to use the install prefix * Update podman-for-windows.md * Quadlet: RemapUsers documentation fixes * speed up image listing * vendor containers/common@e27c30ee9b1b * fix volume-plugin-test flake * Document building Podman remote on Windows hosts * test/e2e: gpg keep stdout/err attached * auto-update: stop+start instead of restart sytemd units * [CI:DOCS] Improve basic tutorial * Update docs/source/markdown/podman-network.1.md * Add debug to --wait test * fix slirp4netns resolv.conf ip with a userns * Quadlet: add support for keep-id with mapping values * Quadlet E2E test - run quadlet as user generator * sqlite: do not `Ping()` after connecting * Quadlet - treat paths starting with systemd specifiers as absolute * Update docs/source/markdown/podman-kube-play.1.md.in * system tests: use CONTAINERS_CONF_OVERRIDE * implement podman machine set for hyperv * [CI:DOCS] Add network subnets info to network man page ... changelog too long, skipping 332 lines ... - Don't build against EoL go versions, fixes bsc#1210299 ==== polkit-kde-agent-5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== poppler ==== Version update (23.03.0 -> 23.04.0) Subpackages: libpoppler-cpp0 libpoppler-glib8 poppler-tools - update to 23.04.0: * Fix memory issue when signing fails. Issue #1372 * Internal improvements of signature related code * CairoOutputDev: improve type3 font rendering * Fix memory leak in GlobalParams::findSystemFontFileForFamilyAndStyle * pdftocairo: Fix crash in some special situations * pdfsig: allow holes in -dump signature list * pdfsig: Support --help ==== poppler-qt5 ==== Version update (23.03.0 -> 23.04.0) - update to 23.04.0: * Fix memory issue when signing fails. Issue #1372 * Internal improvements of signature related code * CairoOutputDev: improve type3 font rendering * Fix memory leak in GlobalParams::findSystemFontFileForFamilyAndStyle * pdftocairo: Fix crash in some special situations * pdfsig: allow holes in -dump signature list * pdfsig: Support --help ==== powerdevil5 ==== Version update (5.27.3 -> 5.27.4) Subpackages: powerdevil5-lang - Cleanup build dependencies: * Remove unused KDELibs4Support and KF5Wayland * Explicitly add KF5Crash, KF5DocTools and KF5Notifications * Update required versions. - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== prison-qt5 ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Prison5 prison-qt5-imports - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== publicsuffix ==== Version update (20230226 -> 20230414) - Update to version 20230414: * util: gTLD data autopull updates for 2023-04-14T15:13:16 UTC (#1738) * Change - update comments/policy for the French ccTLDs (`.fr`, `.pm`, `.re`, `.tf`, `.wf`, `.yt`) by Administrator (#1732) * New policy for .museum, without all the SLD (Second-Level Domains) (#1729) * Add ladesk.com (#1538) * util: gTLD data autopull updates for 2023-03-18T15:13:12 UTC (#1723) * util: gTLD data autopull updates for 2023-03-08T15:15:40 UTC (#1714) * Additional ngrok domains - more `ngrok.io` from #48 + `ngrok.app` `ngrok-free.app` `ngrok.dev` `ngrok-free.dev` `ngrok.pizza` (#1653) * Add `ie.ua` (#1597) ==== purpose ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Purpose5 libKF5PurposeWidgets5 - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== python-cryptography ==== Version update (40.0.1 -> 40.0.2) - update to 40.0.2: * Fixed compilation when using LibreSSL 3.7.2. - rebase patch remove_python_3_6_deprecation_warning.patch ==== python-pexpect ==== - Skip REPLWrapTestCase.test_existing_spawn which seems to still fail on s390x (gh#pexpect/pexpect#750, bsc#1209560). ==== python-pytz ==== Version update (2023.2 -> 2023.3) - update to 2023.3: * Update to IANA 2023c ==== python-redis ==== Version update (4.3.3 -> 4.5.4) - Update to 4.5.4: * Security + Cancelling an async future does not, properly trigger, leading to a potential data leak in specific cases. (CVE-2023-28858, bsc#1209811) + Cancelling an async future does not, properly trigger, leading to a potential data leak in specific cases. (CVE-2023-28859, bsc#1209812) * New Features + Introduce AbstractConnection so that UnixDomainSocketConnection can call super().init (#2588) + Added queue_class to REDIS_ALLOWED_KEYS (#2577) + Made search document subscriptable (#2615) + Sped up the protocol parsing (#2596) + Use hiredis::pack_command to serialized the commands. (#2570) + Add support for unlink in cluster pipeline (#2562) * Bug Fixes + Fixing cancelled async futures (#2666) + Fix: do not use asyncio's timeout lib before 3.11.2 (#2659) + Fix UDS in v4.5.2: UnixDomainSocketConnection missing constructor argument (#2630) + CWE-404 AsyncIO Race Condition Fix (#2624, #2579) + Fix behaviour of async PythonParser to match RedisParser as for issue #2349 (#2582) + Replace async_timeout by asyncio.timeout (#2602) + Update json().arrindex() default values (#2611) + Fix #2581 UnixDomainSocketConnection object has no attribute _command_packer (#2583) + Fix issue with pack_commands returning an empty byte sequence (#2416) + Async HiredisParser should finish parsing after a Connection.disconnect() (#2557) + Check for none, prior to raising exception (#2569) + Tuple function cannot be passed more than one argument (#2573) + Synchronise concurrent command calls to single-client to single-client mode (#2568) + Async: added 'blocking' argument to call lock method (#2454) + Added a replacement for the default cluster node in the event of failure. (#2463) + Fixed geosearch: Wrong number of arguments for geosearch command (#2464) - Clean up BuildRequires and Requires. - Disable broken test test_xautoclaim gh#redis/redis-py#2554 - udpate to 4.3.5: * Add support for TIMESERIES 1.8 (#2296) * Graph - add counters for removed labels and properties (#2292) * Add support for TDIGEST.QUANTILE extensions (#2317) * Add TDIGEST.TRIMMED_MEAN (#2300) * Add support for async GRAPH module (#2273) * Support TDIGEST.MERGESTORE and make compression optional on TDIGEST.CREATE (#2319) * Adding reserve as an alias for create, so that we have BF.RESERVE and CF.RESERVE accuratenly supported (#2331) * Fix async connection.is_connected to return a boolean value (#2278) * Fix: workaround asyncio bug on connection reset by peer (#2259) * Fix crash: key expire while search (#2270) * Async cluster: fix concurrent pipeline (#2280) * Fix async SEARCH pipeline (#2316) * Fix KeyError in async cluster - initialize before execute multi key commands (#2439) * Supply chain risk reduction: remove dependency on library named deprecated (#2386) * Search test - Ignore order of the items in the response (#2322) * Fix GRAPH.LIST & TDIGEST.QUANTILE tests (#2335) * Fix TimeSeries range aggregation (twa) tests (#2358) * Mark TOPK.COUNT as deprecated (#2363) - update to 4.3.4: * Fix backward compatibility from 4.3.2 in Lock.acquire() * Fix XAUTOCLAIM to return the full response, instead of only keys 2+ * Added dynamic_startup_nodes configuration to RedisCluster. * Fix retries in async mode * Async cluster: fix simultaneous initialize * Uppercased commands in CommandsParser.get_keys * Late eval of the skip condition in async tests * Reuse the old nodes' connections when a cluster topology refresh is being done * Docs: add pipeline examples * Correct retention_msecs value * Cluster: use pipeline to execute split commands * Docs: Add a note about client_setname and client_name difference ==== python-setuptools ==== Version update (67.6.0 -> 67.6.1) - update to 67.6.1: * #3865: Fixed ``_WouldIgnoreField`` warnings for ``scripts`` and ``gui_scripts``, when ``entry-points`` is not listed in dynamic. * #3875: Update code generated by ``validate-pyproject`` to use v0.12.2. * This should fix default license patterns when ``pyproject.toml`` is used. ==== qqc2-desktop-style ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * CheckIndicator: Allow exclusive buttons to be detected via their ButtonGroup (kde#467390) ==== raspberrypi-firmware ==== Version update (2023.02.22 -> 2023.03.22) - Update to c4122b870 (2023-03-22): * firmware: gencmd: Add a fallback to mailbox interface if vchiq is not available * firmware: Handle 64-bitness of named kernels See: #1792 * firmware: bootloader: Fix automatic 64bit selection on Pi3s See: https://forums.raspberrypi.com/viewtopic.php?p=2089764#p2089764 * firmware: bootloader: Raise CMA cap to 512MB on a 64-bit Pi4 * firmware: bootloader: Prefer 64-bit kernels on Pi 4s See: https://forums.raspberrypi.com/viewtopic.php?p=2088935#p2088935 * firmware: platform: clocks: Replace m2mc with hdmi for state machine clock on 2711 ==== raspberrypi-firmware-config ==== Version update (2023.02.22 -> 2023.03.22) - Update to c4122b870 (2023-03-22): * firmware: gencmd: Add a fallback to mailbox interface if vchiq is not available * firmware: Handle 64-bitness of named kernels See: #1792 * firmware: bootloader: Fix automatic 64bit selection on Pi3s See: https://forums.raspberrypi.com/viewtopic.php?p=2089764#p2089764 * firmware: bootloader: Raise CMA cap to 512MB on a 64-bit Pi4 * firmware: bootloader: Prefer 64-bit kernels on Pi 4s See: https://forums.raspberrypi.com/viewtopic.php?p=2088935#p2088935 * firmware: platform: clocks: Replace m2mc with hdmi for state machine clock on 2711 ==== rav1e ==== Version update (0.6.2+0 -> 0.6.4+0) - Update to version 0.6.4+0: * Safety critical bounds checking is off-by-one in sgrproj_box_ab_internal * Initialize `low` array in a more rust-like way in `kmeans` * Rework mutable borrows for symbol_with_update * Drop explicit size for macro symbol_with_update * Use const generics for CDFContextLog * Fix undefined behavior in CDFContextLogOps * ec: Simplify lr_compute function * Use a bit counter instead of a byte counter in WriterRecorder * Minimize bounds checks in pred functions * Use generics for BD-8 on sgrproj functions * Use saturating_sub in sgrproj_sum_finish * Move bounds checks out of hot loop in sgrproj * Ensure quantizer values are non-zero with a const fn * Optimize base quants using NonZero integers (#3115) * Move quant tables to separate file to improve organization (#3113) * Use is_power_of_two method in divu_gen * Fix rounding issue in HBD CDEF code * Hint that creating a region from an empty plane is unlikely * Minor optimization to take_slice * Clean up cdef_dist * Minor optimizations * Optimizations for weighted_sse * Add HBD AVX2 assembly for SAD (#3099) * ec: Manually inline `msb()` and `ilog()` for clarity (#3104) * Comment regarding cnt being unused * Improve naming * Use a bit counter instead of a byte counter in EC * Add 10-bit cdef_dist ASM * Optimise sad_plane_internal * Save some bounds checks on me_stats * Minor optimization to av1_get_mv_joint * Use chunks_exact for performance in diff method * Integrate CfL AC x86 assembly functions * benches: Fix alignment issue for cfl_rdo * Move luma_ac to predict module * Extract luma_ac_internal with const generics * Optimise plane::as_region * Optimise BlockSize::from_width_and_height_opt * Improve vectorization in get_sad * Template entropy coding functions to help optimiser * Enable SSE2/AVX512ICL put/prep/avg x86 assembly * Enable AVX2 12-bit Inverse Transform x86 assembly * Enable new SSE4.1 HBD Inverse Transform x86 assembly * Pin assert_cmd, predicates and clap in Cargo.toml for rust 1.60.0 * Prepare for release * Fix header coding for level_idx < 7. ==== redis ==== Version update (7.0.8 -> 7.0.11) - redis 7.0.11 - (CVE-2023-28856) Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access (boo#1210548) - Add a missing fsync of AOF file in rare cases - Disconnect pub-sub subscribers when revoking allchannels permission - Fix a compiler fortification induced crash when used with link time optimizations - Drop get-old-size-calculations.patch: replaced with proper fix - Added get-old-size-calculations.patch: my workaround for https://github.com/redis/redis/issues/11965 - redis 7.0.10 * CVE-2023-28425: Specially crafted MSETNX command can lead to assertion and denial-of-service (boo#1209528) * Large blocks of replica client output buffer may lead to psync loops and unnecessary memory usage * Fix CLIENT REPLY OFF|SKIP to not silence push notifications * Trim excessive memory usage in stream nodes when exceeding `stream-node-max-bytes` * Fix module RM_Call commands failing with OOM when maxmemory is changed to zero - redis 7.0.9 * CVE-2023-25155: Specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. Previously patched, drop Integer-Overflow-in-RAND-commands-can-lead-to-assert.patch * CVE-2022-36021: String matching commands (like SCAN or KEYS) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. Previously upatched, drop String-pattern-matching-had-exponential-time-complex.patch * Fix a crash when reaching the maximum invalidations limit of client-side tracking * Fix a crash when SPUBLISH is used after passing the cluster-link-sendbuf-limit * Fix possible memory corruption in FLUSHALL when a client watches more than one key * Fix cluster inbound link keepalive time * Flush propagation list in active-expire of writable replicas to fix an assertion * Avoid propagating DEL of lazy expire from SCAN and RANDOMKEY as MULTI-EXEC * Avoid realloc to reduce size of strings when it is unneeded * Improve CLUSTER SLOTS reply efficiency for non-continuous slots ==== rsync ==== - Switch rsyncd symlink to a wrapper script to allow setting a distinct SELinux type (bsc#1209654) ==== rubygem-ruby-dbus ==== Version update (0.20.0 -> 0.21.0) - 0.21.0 Features: * Respect env RUBY_DBUS_ENDIANNESS=B (or =l) for outgoing messages. Bug fixes: * Reduce socket buffer allocations (gh#mvidner/ruby-dbus#129). * Message#marshall speedup: don't marshall the body twice. ==== runc ==== Version update (1.1.5 -> 1.1.6) - Update to runc v1.1.6. Upstream changelog is available from . ==== rust-keylime ==== Version update (0.2.0+git.1677691779.f7edd9a -> 0.2.0+git.1681457715.54484b7) Subpackages: keylime-ima-policy - Update to version 0.2.0+git.1681457715.54484b7: * build(deps): bump h2 from 0.3.14 to 0.3.17 (CVE-2023-26964, bsc#1210344) * build(deps): bump reqwest from 0.11.15 to 0.11.16 - Update to version 0.2.0+git.1681223954.646cf61: * Allow setting measured boot log path for testing * build(deps): bump base64 from 0.13.1 to 0.21.0 * build(deps): bump wiremock from 0.5.14 to 0.5.18 * Build Fedora and CentOS packages on Copr using packit * build(deps): bump serde_json from 1.0.91 to 1.0.95 * build(deps): bump actix-rt from 2.7.0 to 2.8.0 * build(deps): bump base64 from 0.13.1 to 0.21.0 * build(deps): bump serde from 1.0.147 to 1.0.159 * build(deps): bump glob from 0.3.0 to 0.3.1 * Add missing test from keylime testsuite to e2e plan * Fix typo in name of test for generating coverage * build(deps): bump thiserror from 1.0.38 to 1.0.40 * build(deps): bump base64 from 0.13.1 to 0.21.0 * build(deps): bump actix-web from 4.2.1 to 4.3.1 * build(deps): bump serde from 1.0.145 to 1.0.147 * build(deps): bump libc from 0.2.139 to 0.2.140 * build(deps): bump futures from 0.3.25 to 0.3.27 * build(deps): bump reqwest from 0.11.12 to 0.11.15 * build(deps): bump config from 0.13.2 to 0.13.3 * build(deps): bump openssl from 0.10.45 to 0.10.48 * build(deps): bump tokio from 1.24.2 to 1.26.0 * Cargo: Update tempfile to 3.4.0 version ==== sddm ==== Subpackages: sddm-branding-openSUSE - Replace proper_pam.diff with installation of source files: * sddm.pam, sddm-autologin.pam, sddm-greeter.pam - PAM services: * Make use of substack for common-* * Include postlogin-* * Run pam_keyinit before common-session * Deny password in sddm-greeter - /run/sddm is owned by root:root - Add patch to fix possible deadlock: * 0001-Process-all-available-auth-messages-in-a-loop.patch - Add missing dependencies on update-alternatives - Migration of PAM settings to /usr/lib/pam.d. ==== shadow ==== Subpackages: libsubid4 login_defs - Rename lastlog to lastlog.legacy to be able to switch to Y2038 safe lastlog2 as default [jsc#PED-3144] ==== shim ==== - Removed POST_PROCESS_PE_FLAGS=-N from the build command in shim.spec to enable the NX compatibility flag when using post-process-pe after discussed with grub2 experts in mail. It's useful for further development and testing. (bsc#1205588) - Updated shim signature after shim 15.7 of SLE be signed back: signature-sles.x86_64.asc, signature-sles.aarch64.asc (bsc#1198458) ==== snapper ==== Subpackages: snapper-zypp-plugin - allow to show read-only state in list output and allow to change read-only state (gh#openSUSE/snapper#804) - support read-only options for LVM - allow to set a snapshot as default (gh#openSUSE/snapper#803) - avoid stale btrfs qgroups on transactional systems (bsc#1210151) - fixed error message (gh#openSUSE/snapper#801) ==== solid ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5Solid5 solid-imports solid-tools - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Remove some obsolete and incorrect code from UPower and UDisks2 backend * Deprecate "Recall" API for batteries * Avoid synchronous DBus calls for devices list * Initialize supported interfaces with member initializer list * Replace generic UPower QDBusInterface with concrete implementation * Remove support for UPower < 0.99 * Remove invalid Refresh DBus call from UPower backend ==== sonnet ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5SonnetCore5 libKF5SonnetUi5 sonnet-imports - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== sudo ==== Subpackages: sudo-plugin-python - sudo.pamd: Use common-session-nonlogin for >15 codestreams More info in https://github.com/SUSE/pam-config/pull/16 ==== syndication ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== syntax-highlighting ==== Version update (5.104.0 -> 5.105.0) Subpackages: libKF5SyntaxHighlighting5 syntax-highlighting-imports - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - Changes since 5.104.0: * Highlight the QML "required" keyword, added in Qt 5.15 ==== systemd ==== Version update (253.1 -> 253.3) Subpackages: libsystemd0 libudev1 systemd-coredump systemd-doc udev - testsuite: TEST-75-RESOLVED needs knot DNS server - Import commit 66f3a8a47d5bf6aea3f6fb181c01550a1a54406e (merge of v253.3) This merge also includes the following fix, which is not part of the stable release: d2413cec02 test/test-functions: fix typo in install_suse_systemd() For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/03cfbe767327d01d5a71131d91bf06fdc0047ca1...66f3a8a47d5bf6aea3f6fb181c01550a1a54406e - Import commit 03cfbe767327d01d5a71131d91bf06fdc0047ca1 03cfbe7673 test: use setpriv instead of su for user switch from root 857843834c test: wrap mkfs.*/mksquashfs/mkswap binaries when running w/ ASan be7388f8c5 test: do not remove state directory on failure 1b2885bd16 test: fix regexp in testsuite-74.mount.sh 41142f8013 test: drop extraneous bracket in testsuite-74.mount.sh - systemd.spec: add files.coredump - Import commit b63f58661b08037d8cb04ed97b5e39d9bf415fdc (merge of v253.2) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/8b01686dd20124efc300d21ef38d85c1f75c372f...b63f58661b08037d8cb04ed97b5e39d9bf415fdc - Move systemd-fsck stuff to udev sub-package. - Include pam_keyinit.so in our systemd-user PAM service (bsc#1209741) That way "systemd --user" instances get their own session keyring instead of the user default session keyring. For some reasons cifscreds refuses to work with the latter. That's what is expected for every PAM session anyway. - Import commit 8b01686dd20124efc300d21ef38d85c1f75c372f 8b01686dd2 test: don't export $TOOLS_DIR 7a56b1b2f0 test: clean up $STATEDIR too 324bb19eb8 test: $STATEDIR should not point to /usr/lib/systemd/tests when NO_BUILD=1 2251735482 test: install symlinks with valid targets on SUSE and Debian c30905a269 test: on openSUSE install the collection of unit test binaries in the target only for TEST-02-UNITTESTS 797ced15d8 meson: make sure the unit test scripts find testdata/ even if they are not installed in the same directory 04dc5b44b7 meson: define testdata_dir globally 69643c6c96 test: install unit tests in a dedicated subdirectory below '$testsdir' ==== systemsettings5 ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - Changes since 5.27.3: * Cancel pending resolveChanges dialog when a new one is started (kde#465510) * Include version number in bug report URL (kde#466881) ==== talloc ==== Subpackages: libtalloc2 python3-talloc - Build AVX2 enabled hwcaps library for x86_64-v3 ==== tcl ==== - Update tcl-refchan-mode-needed.patch to the upstream version. ==== texlive ==== - Really update biber to version 2.19 (boo#1210257) - Use ERR trap in bash used by spec file to catch rare and random bibtexu/bibtex8 FAILS - Do not build nor test bibtex8/bibtexu in parallel - Support mkiv as well as lmtx ConTeXt formats - Enlarge main memory of xmltex to get a format - Modify patch source-warns.dif * Remove change for decNumber.h from icu library source as it is incompatible with icu 72 ans above - Add patch source-decNumber.dif * make libmp and libcu using the same decNumber scheme to get e.g. bibtex8 working on all architectures - Add patch luametatex.dif * Also use the same decNumber scheme here - Add patch biblatex-ms-missing.dif * Allow two biber binbaries with different perl includes - Add patch biblatex-ms-encoding.dif * Make it work - Delete patch biber-missing-semicolon.patch now upstream - Update to final TeXLive 2023 - Do not touch libs/icu/icu-src/source/i18n/decNumber.h in source-warns.dif as otherwise libicu does not compile - Update to pretest TeXLive 2023 ==== texlive-specs-n ==== Version update (2022.196.2.005svn61719 -> 2023.201.2.005svn65956) - Support mkiv as well as lmtx ConTeXt formats - Correct supplements tags of texlive packages to use the new texlive-alldocuments meta package - Move cenccmn.tex fro mdoc to tex tree to let be find by the ucs font definitions - Move pgfPT.input.library.tex from doc to tex tree to make it visible for the pgf-PeriodicTable.sty - Enlarge main memory of xmltex to get a format - Update to final TeXLive 2023 - Add fix for boo#1204746 * New meta package texlive-documentation which triggers installation of documentation packages of already installed packages - Ported changes * kpathsea_cnf.dif * latexmk_conf.dif * latexpand_perl.dif * luaotfload_varfonts.dif * luatex_cnf.dif * texlive-scripts_scripts.dif - New change context_cnf.dif * help ConteXt to find its system wide files - Upstream dropped packages * aleph.tar.xz * ametsoc.doc.tar.xz * ametsoc.tar.xz * amscls-doc.tar.xz * amslatex-primer.tar.xz * amsldoc-it.tar.xz * amsldoc-vn.tar.xz * amsmath-it.tar.xz * amsthdoc-it.tar.xz * anufinalexam.tar.xz * apprends-latex.tar.xz * around-the-bend.tar.xz * ascii-chart.tar.xz * asymptote-by-example-zh-cn.tar.xz * asymptote-faq-zh-cn.tar.xz * asymptote-manual-zh-cn.tar.xz * autosp.tar.xz * beamer-FUBerlin.doc.tar.xz * beamer-FUBerlin.tar.xz * beamer-tut-pt.tar.xz * biber.tar.xz * biblatex-cheatsheet.tar.xz * bibtexu.tar.xz * booktabs-de.tar.xz * booktabs-fr.tar.xz * components-of-TeX.doc.tar.xz * components-of-TeX.tar.xz * comprehensive.tar.xz * context-inifile.doc.tar.xz * context-inifile.tar.xz * context-notes-zh-cn.doc.tar.xz * context-notes-zh-cn.tar.xz * csquotes-de.tar.xz * cstex.tar.xz * ctan_chk.tar.xz * ctex-faq.tar.xz * ctie.tar.xz * cursolatex.tar.xz * detex.tar.xz * dickimaw.tar.xz * doc-pictex.tar.xz * docsurvey.tar.xz * dtl.tar.xz * dtxgallery.tar.xz * dtxtut.tar.xz * dvi2tty.doc.tar.xz * dvi2tty.tar.xz * dvicopy.tar.xz * dvidvi.tar.xz * dviljk.tar.xz * dviout-util.tar.xz * dvipng.tar.xz * dvipos.tar.xz * dvisvgm.tar.xz * ebong.doc.tar.xz * ebong.tar.xz * ecothesis.tar.xz * ednotes.doc.tar.xz * ednotes.tar.xz * elegantbook.doc.tar.xz * elegantbook.tar.xz * elegantnote.doc.tar.xz * elegantnote.tar.xz * elegantpaper.doc.tar.xz * elegantpaper.tar.xz * epslatex-fr.tar.xz * es-tex-faq.tar.xz * etdipa.tar.xz * etoolbox-de.tar.xz * expkv-cs.doc.tar.xz * expkv-cs.tar.xz * expkv-def.doc.tar.xz * expkv-def.tar.xz * expkv-opt.doc.tar.xz * expkv-opt.tar.xz * expkv.doc.tar.xz * expkv.tar.xz ... changelog too long, skipping 546 lines ... - For dvips do not require but recommend metapost (boo#1206850) ==== threadweaver ==== Version update (5.104.0 -> 5.105.0) - Update to 5.105.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/5/5.105.0 - No code change since 5.104.0 ==== tigervnc ==== Subpackages: libXvnc1 xorg-x11-Xvnc xorg-x11-Xvnc-module - xorg-x11-Xvnc requires dbus-1-x11 (bsc#1207730) - Fixes for bsc#1209283 * Drop chown vnc:vnc calls in with-vnc-key.sh * Add TLSNone to -securitytypes to increase security in xvnc@.service ==== util-linux ==== Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - su.pamd: Fixup common-session-nonlogin usage - runuser.pamd, su.pamd: Guard common-session-nonlogin away for <=15 codestreams More info in https://github.com/SUSE/pam-config/pull/16 ==== util-linux-systemd ==== - su.pamd: Fixup common-session-nonlogin usage - runuser.pamd, su.pamd: Guard common-session-nonlogin away for <=15 codestreams More info in https://github.com/SUSE/pam-config/pull/16 ==== vim ==== Version update (9.0.1430 -> 9.0.1443) Subpackages: vim-data vim-data-common vim-small xxd - Updated to version 9.0.1443, fixes the following problems * Livebook files are not recognized. * getscriptinfo() loops even when specific SID is given. * Completion popup in wrong position with virtual text "above". * On some systems the Lua library is not found. * Crash when adding package already in 'runtimepath'. * Scrolling too many lines when 'wrap' and 'diff' are set. * Cannot compare a typed variable with v:none. * Test fails with different error number. * .fs files are falsely recognized as forth files. * Start Insert mode when accessing a hidden prompt buffer. * "rvim" can execute a shell through :diffpatch. * mapset() does not restore non-script context. * Ending Insert mode when accessing a hidden prompt buffer. ==== vte ==== Version update (0.72.0 -> 0.72.1) - Update to version 0.72.1: + emulation: Fix invalid mouse scroll event on window edge + widget: - Fix compilation - Fix setting clipboard with html data - Fix introspection warnings - Fix cursor blink timeout + Updated translations. ==== webkit2gtk3 ==== Subpackages: libjavascriptcoregtk-4_1-0 libwebkit2gtk-4_1-0 typelib-1_0-JavaScriptCore-4_1 typelib-1_0-WebKit2-4_1 webkit2gtk-4_1-injected-bundles - Add fix-gst-crash.patch: Fix crash in webkit_media_stream_src_class_init(). https://bugs.webkit.org/show_bug.cgi?id=254025 - Add reproducibility.patch: Make build more reproducible. Still not there yet though. Inject fixed year in file. ==== webkit2gtk4 ==== Subpackages: libjavascriptcoregtk6_0-1 libwebkitgtk6_0-4 webkitgtk-6_0-injected-bundles - Add fix-gst-crash.patch: Fix crash in webkit_media_stream_src_class_init(). https://bugs.webkit.org/show_bug.cgi?id=254025 - Add reproducibility.patch: Make build more reproducible. Still not there yet though. Inject fixed year in file. ==== wireplumber ==== Version update (0.4.13 -> 0.4.14) Subpackages: libwireplumber-0_4-0 wireplumber-audio - Update to version 0.4.14: * Additions - Add support for managing Bluetooth-MIDI, complementing the parts that were merged in PipeWire recently. - Add a default volume configuration option for streams whose volume has never been saved before; that allows starting new streams at a lower volume than 100% by default, if desired. - Add support for managing link errors and propagating them to the client(s) involved. This allows better error handling on the application side in case a format cannot be negotiated - useful in video streams. - snd_aloop devices are now described as being "Loopback" devices. - ALSA nodes in the pro audio profile now get increased graph priority, so that they are more likely to become the driver in the graph. - Add support for disabling libcamera nodes & devices with node.disabled and device.disabled, like it works for ALSA and V4L2. - Drop reduce-meson-required-version.patch: openSUSE Leap 15.3 is no longer supported. - Drop patches already included upstream: * 0001-alsa-monitor-handle-snd_aloop-devices-better.patch * 0001-spa-json-make-sure-we-only-add-encoded-string-data.patch * 0001-m-lua-scripting-ignore-string-integer-table-keys-when-constructing-a-JSON-Array-Object.patch ==== wsdd ==== Version update (0.7.0 -> 0.7.1) - Fix previous change: really limit the forced change to python 3.10 on suse_version <= 1500 (up to SLE/Leap 15); newer products already use python 3.10 (or newer) as default. - Force the use of python 3.10 for openSUSE Leap - Update to version 0.7.1 * GitHub workflow for static analyses added (syntax, format, and type checks are performed). * Added EnvironmentFile and according example for systemd-based distros. * Make wsdd work (again) on MacOS (#139). Thanks to Eugene Gershnik. * Application profile for UFW has been added (#169) * Use of implicitly present async I/O loop instead created one for API servers. Fixes regression due to changed API in Python 3.10 (see #162) * Source code is spiced with type hints now. * man page moved to section 8. ==== xdg-desktop-portal-gtk ==== - Change Supplements: Replace gtk3 with gtk3-schema, ensure the supplements gets triggered. - Add (gtk4-schema and (flatpak or snapd)) Supplements: Futureproof the supplements, as more and more of GNOME moves to gtk4. ==== xdg-desktop-portal-kde ==== Version update (5.27.3 -> 5.27.4) - Update to 5.27.4 * New bugfix release * For more details please see: * https://kde.org/announcements/plasma/5/5.27.4 - No code changes since 5.27.3 ==== xdm ==== - Create two set of pam configuration files: + *.sle15 are for SLES15 and older + add postlogin-* includes to the others as required by new openSUSE's PAM config policy ==== xf86-input-libinput ==== Version update (1.2.1 -> 1.3.0) - Update to version 1.3.0 The main feature in this version is support for the new 'custom' pointer acceleration profile in libinput 1.23.0. This acceleration profile is quite flexible, so it is exposed via several properties: - "libinput Accel Custom Fallback Points" and "libinput Accel Custom Fallback Step" - "libinput Accel Custom Motion Points" and "libinput Accel Custom Motion Step" - "libinput Accel Custom Scroll Points" and "libinput Accel Custom Scroll Points" For details on what these mean, please see the man page and the libinput documentation: https://wayland.freedesktop.org/libinput/doc/latest/pointer-acceleration.html In addition, the "libinput Accel Profiles Available" and "libinput Accel Profile Enabled" properties have been expanded to 3 values. For backwards compatibility, the "libinput Accel Profile Enabled" continues to support setting 2 values only. ==== xz ==== Subpackages: liblzma5 - Update license tag, there is GPL-3.0-or-later code too. ==== yast2-installation ==== Version update (4.6.1 -> 4.6.2) - yupdate - improved Live ISO detection, added "--force" option (related to bsc#1206927) - 4.6.2 ==== yast2-packager ==== Version update (4.6.0 -> 4.6.1) - Adapt test to changes in ruby-bindings when detecting Yast modules using public only methods (related to bsc#1210051) - Comment out expensive debug calls to improve performance (bsc#1210051) - 4.6.1 ==== yast2-pkg-bindings ==== Version update (4.6.0 -> 4.6.1) - Pkg.TargetInitializeOptions() - added a new option for rebuilding the RPM database (--rebuilddb) (bsc#1209565) - 4.6.1 ==== yast2-ruby-bindings ==== Version update (4.6.1 -> 4.6.2) - Improve YaST memory consumption related to import+publish (bsc#1210051) - 4.6.2 ==== yast2-snapper ==== Version update (4.6.0 -> 4.6.1) - Fixed translations: Moved variable message part out of _(...) (bsc#1209956) - 4.6.1 ==== yast2-storage-ng ==== Version update (4.6.3 -> 4.6.5) - Adjusted detection of Dell BOSS devices (bsc#1200975). - Partitioner: improved column Type for disks (bsc#1200975). - 4.6.5 - AutoYaST: export thin LVM volumes when cloning (bsc#1209725) - 4.6.4 ==== yast2-update ==== Version update (4.6.0 -> 4.6.1) - Rebuild the RPM database during upgrade (--rebuilddb) (bsc#1209565) - 4.6.1 ==== yast2-users ==== Version update (4.6.0 -> 4.6.1) - Stop mangling the value of "Create as Btrfs Subvolume" for new users when clicking on "Edit -> Details" (bsc#1209377). - 4.6.1 - AutoYaST: Fix creation of home for system users (bsc#1202974). ==== zlib-ng-compat ==== Version update (2.0.6 -> 2.0.7) - Update to 2.0.7: * Fix CVE-2022-37434 #1328 * Fix chunkmemset #1196 * Fix deflateBound too small #1236 * Fix Z_SOLO #1263 * Fix ACLE variant of crc32 #1274 * Fix inflateBack #1311 * Fix deflate_quick windowsize #1431 * Fix DFLTCC bugs related to adler32 #1349 and #1390 * Fix warnings #1194 #1312 #1362 * MacOS build fix #1198 * Add invalid windowBits handling #1293 * Support for Force TZCNT #1186 * Support for aligned_alloc() #1360 * Minideflate improvements #1175 #1238 * Dont use unaligned access for memcpy #1309 * Build system #1209 #1233 #1267 #1273 #1278 #1292 #1316 #1318 #1365 * Test improvements #1208 #1227 #1241 #1353 * Cleanup #1266 * Documentation #1205 #1359 * Misc improvements #1294 #1297 #1306 #1344 #1348 * Backported zlib fixes * Backported CI workflows from Develop branch - Drop upstream patches: * 1297.patch * 0001-Add-one-extra-byte-to-return-value-of-compressBound-.patch ==== zvbi ==== - Set minimum version for gettext ==== zypper ==== Version update (1.14.59 -> 1.14.60) Subpackages: zypper-log zypper-needs-restarting - Fix selecting installed patterns from picklist (bsc#1209406) - man: better explanation of --priority (fixes #480) - version 1.14.60