New Arm Tumbleweed snapshot 20240107 released!
Please note that this mail was generated by a script.
The described changes are computed based on the aarch64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=3&version=Tumbleweed&build=20240107
Please do not reply to this email to report issues, rather file a bug
on bugzilla.opensuse.org. For more information on filing bugs please
see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
7zip
ImageMagick (7.1.1.21 -> 7.1.1.25)
Mesa-demo
MozillaFirefox (120.0.1 -> 121.0)
apache2-mod_php8 (8.2.13 -> 8.2.14)
bind (9.18.20 -> 9.18.21)
bluez (5.70 -> 5.71)
cfitsio (4.3.0 -> 4.3.1)
ell (0.60 -> 0.61)
emacs
evolution (3.50.2 -> 3.50.3)
evolution-data-server (3.50.2 -> 3.50.3)
evolution-ews (3.50.2 -> 3.50.3)
ffmpeg-4
fltk (1.3.8 -> 1.3.9)
frameworkintegration
fwupd (1.9.10 -> 1.9.11)
ghostscript
gnome-control-center
gnome-settings-daemon (45.0 -> 45.1)
gnustep-base
gpgme
gpgmeqt
grub2
gstreamer (1.22.7 -> 1.22.8)
gstreamer-plugins-bad (1.22.7 -> 1.22.8)
gstreamer-plugins-base (1.22.7 -> 1.22.8)
gstreamer-plugins-good (1.22.7 -> 1.22.8)
gstreamer-plugins-libav (1.22.7 -> 1.22.8)
gstreamer-plugins-rs (0.11.2 -> 0.11.3)
gstreamer-plugins-ugly (1.22.7 -> 1.22.8)
gtk-layer-shell (0.8.1 -> 0.8.2)
gucharmap (15.1.1 -> 15.1.2)
guestfs-tools (1.51.6 -> 1.52.0)
hplip (3.23.8 -> 3.23.12)
hxtools (20231101 -> 20231224)
icewm (3.4.4 -> 3.4.5)
inotify-tools (3.22.6.0 -> 4.23.9.0)
iputils (20221126 -> 20231222)
iw (5.19 -> 6.7)
kernel-firmware (20231214 -> 20240102)
kernel-source (6.6.6 -> 6.6.9)
kmozillahelper
libHX (4.19 -> 4.21)
libarchive (3.7.0 -> 3.7.2)
libavif (1.0.2 -> 1.0.3)
libdrm (2.4.118 -> 2.4.119)
libebml (1.4.4 -> 1.4.5)
libguestfs (1.51.9 -> 1.52.0)
libheif (1.17.5 -> 1.17.6)
libical (3.0.16 -> 3.0.17)
libical-glib (3.0.16 -> 3.0.17)
libjcat (0.1.14 -> 0.2.0)
libjpeg-turbo (8.2.2 -> 8.3.2)
libntlm (1.6 -> 1.7)
libportal
libqt5-qtbase (5.15.11+kde138 -> 5.15.12+kde147)
libqt5-qtconnectivity (5.15.11+kde6 -> 5.15.12+kde6)
libqt5-qtdeclarative (5.15.11+kde30 -> 5.15.12+kde31)
libqt5-qtgraphicaleffects (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtimageformats (5.15.11+kde12 -> 5.15.12+kde10)
libqt5-qtlocation (5.15.11+kde4 -> 5.15.12+kde6)
libqt5-qtmultimedia (5.15.11+kde2 -> 5.15.12+kde2)
libqt5-qtnetworkauth (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtquickcontrols (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtquickcontrols2 (5.15.11+kde5 -> 5.15.12+kde5)
libqt5-qtscript (5.15.15 -> 5.15.16)
libqt5-qtsensors (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtserialport (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtspeech (5.15.11+kde1 -> 5.15.12+kde1)
libqt5-qtsvg (5.15.11+kde6 -> 5.15.12+kde6)
libqt5-qttools (5.15.11+kde3 -> 5.15.12+kde4)
libqt5-qttranslations (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtvirtualkeyboard (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtwayland (5.15.11+kde59 -> 5.15.12+kde60)
libqt5-qtwebchannel (5.15.11+kde3 -> 5.15.12+kde3)
libqt5-qtwebsockets (5.15.11+kde2 -> 5.15.12+kde2)
libqt5-qtwebview (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtx11extras (5.15.11+kde0 -> 5.15.12+kde0)
libqt5-qtxmlpatterns (5.15.11+kde0 -> 5.15.12+kde0)
libraw (0.21.1 -> 0.21.2)
librsvg (2.57.0 -> 2.57.1)
libstorage-ng (4.5.163 -> 4.5.170)
libxmlb (0.3.14 -> 0.3.15)
libzypp (17.31.25 -> 17.31.27)
lsof (4.99.0 -> 4.99.3)
lttng-ust (2.13.5 -> 2.13.6)
mozilla-nss
multipath-tools (0.9.7+76+suse.5f857af -> 0.9.7+93+suse.e2f2272)
newt (0.52.23 -> 0.52.24)
nftables
nodejs21
open-iscsi
openblas_openmp
openblas_pthreads
osinfo-db (20231027 -> 20231215)
perl-HTTP-Cookies (6.10 -> 6.110.0)
perl-IO-Socket-SSL
perl-IO-Tty (1.180.0 -> 1.200.0)
perl-MIME-tools (5.510 -> 5.511.0)
perl-XML-Parser (2.46 -> 2.470.0)
perl-ldap
php8 (8.2.13 -> 8.2.14)
plasma5-workspace
poppler (23.11.0 -> 23.12.0)
poppler-qt5 (23.11.0 -> 23.12.0)
postfix (3.8.3 -> 3.8.4)
protobuf
protobuf-c (1.4.1 -> 1.5.0)
pulseaudio
python-Babel (2.13.1 -> 2.14.0)
python-M2Crypto
python-Pillow (10.0.1 -> 10.1.0)
python-SQLAlchemy (2.0.23 -> 2.0.24)
python-alembic (1.13.0 -> 1.13.1)
python-argcomplete (3.1.6 -> 3.2.1)
python-atpublic
python-configobj
python-distro (1.8.0 -> 1.9.0)
python-dkimpy (1.0.5 -> 1.1.5)
python-falcon
python-flufl.i18n (4.1.1 -> 5.0.2)
python-flufl.lock (7.1.1 -> 8.0.2)
python-hiredis
python-httpx (0.25.2 -> 0.26.0)
python-importlib-metadata (7.0.0 -> 7.0.1)
python-numpy
python-psutil (5.9.6 -> 5.9.7)
python-psycopg2
python-pycryptodome (3.19.0 -> 3.19.1)
python-pycups
python-pygit2 (1.12.2 -> 1.13.3)
python-python-slugify (5.0.2 -> 8.0.1)
python-pyzmq (25.1.1 -> 25.1.2)
python-redis
python-setuptools (68.1.2 -> 69.0.2)
python-six
python-tornado6 (6.3.3 -> 6.4)
python-unicodedata2 (15.0.0 -> 15.1.0)
python-zope.configuration (4.4.1 -> 5.0)
python-zope.hookable (5.4 -> 6.0)
python-zope.i18nmessageid (6.0.1 -> 6.1.0)
python-zope.interface (6.0 -> 6.1)
qca-qt5 (2.3.7 -> 2.3.7+git12)
qpdf (11.6.4 -> 11.7.0)
qt6-base
rubygem-agama (6 -> 7)
sdbootutil (1+git20231214.b186b2d -> 1+git20231221.42797ab)
sendmail
spamassassin
sudo (1.9.15p4 -> 1.9.15p5)
supermin (5.2.2 -> 5.3.3)
suse-module-tools (16.0.39 -> 16.0.42)
thunar (4.18.8 -> 4.18.10)
timezone (2023c -> 2023d)
traceroute (2.1.3 -> 2.1.5)
tracker-miners
unbound (1.18.0 -> 1.19.0)
vim (9.0.2181 -> 9.1.0000)
virt-v2v (2.2.0 -> 2.4.0)
wireless-regdb (20230901 -> 20231201)
wireplumber (0.4.16 -> 0.4.17)
xerces-c (3.2.4 -> 3.2.5)
xmlsec1 (1.2.37 -> 1.2.38)
xorg-x11-server
yast2-firstboot (5.0.0 -> 5.0.1)
yast2-installation (5.0.2 -> 5.0.3)
yast2-journal (5.0.0 -> 5.0.1)
yast2-trans (84.87.20231216.c47de7a4bf -> 84.87.20231230.7bdda36766)
=== Details ===
==== 7zip ====
- Add missing man pages for 7z / 7za / 7zr / 7zz.
This solves bsc#1204856.
==== ImageMagick ====
Version update (7.1.1.21 -> 7.1.1.25)
Subpackages: ImageMagick-config-7-SUSE ImageMagick-extra libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10
- drop update-alternatives for config; use exactly one of configuration
package provided
- version update to 7.1.1.25
https://github.com/ImageMagick/Website/blob/main/ChangeLog.md
- update to 7.1.1.24:
* Added extra check for rare case when ImageMagick is build without
any delegates.
* Corrected order to fix invalid matches.
* only fill the alpha channel for alpha floodfill
* Make sure we use the lt_ methods like we do elsewhere.
* support dng:max-raw-memory define (ImageMagick/ImageMagick#6922)
* properly export YUV JP2 images (ImageMagick/ImageMagick#6943)
* use : specifier
* correct display program name
* check for corrupt DJVU images
* support UTF-8 comments (ImageMagick/ImageMagick#6949)
* do not prefix iTxt key with 'png:'
* enhance sampling factor parser (ImageMagick/ImageMagick#6943)
* Switch to ubuntu 20.04 in the app-image build.
* Corrected packages that need to be install due to ubuntu upgrade.
* improve accuracy of image statistics
* fx calculations of skewness and kurtosis
* Only write comments as itxt when the string contains non ansi
chars.
* check if the string contains non-Latin1 characters
* Corrected patch to check for non-Latin1 characters.
* invalid JSON with -ping (ImageMagick/ImageMagick#6966)
* throw exception if # of meta channels exceed max
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hx5j-pxv...
* multiplication result converted to larger type
* invalid HTTPS certificates are no longer ignored
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3r24-6m6...
* multiplication result converted to larger type
* eliminate compiler warning
* don't include the index channel in the overall image statistics
* multiplication result converted to larger type
- version update to 7.1.1.23
https://github.com/ImageMagick/Website/blob/main/ChangeLog.md
- modified patches
% ImageMagick-library-installable-in-parallel.patch (refreshed)
- deleted patches
- ImageMagick-infinite-resource-time-limit.patch (upstreamed)
==== Mesa-demo ====
Subpackages: Mesa-demo-egl Mesa-demo-es Mesa-demo-x
- Remove old rpm constructs that are long defaulted.
- Remove legalese from descriptions as per our wiki guidelines.
==== MozillaFirefox ====
Version update (120.0.1 -> 121.0)
- Mozilla Firefox 121.0
https://www.mozilla.org/en-US/firefox/121.0/releasenotes
MFSA 2023-56 (bsc#1217974)
* CVE-2023-6856 (bmo#1843782)
Heap-buffer-overflow affecting WebGL DrawElementsInstanced
method with Mesa VM driver
* CVE-2023-6135 (bmo#1853908)
NSS susceptible to "Minerva" attack
* CVE-2023-6865 (bmo#1864123)
Potential exposure of uninitialized data in EncryptingOutputStream
* CVE-2023-6857 (bmo#1796023)
Symlinks may resolve to smaller than expected buffers
* CVE-2023-6858 (bmo#1826791)
Heap buffer overflow in nsTextFragment
* CVE-2023-6859 (bmo#1840144)
Use-after-free in PR_GetIdentitiesLayer
* CVE-2023-6866 (bmo#1849037)
TypedArrays lack sufficient exception handling
* CVE-2023-6860 (bmo#1854669)
Potential sandbox escape due to VideoBridge lack of texture
validation
* CVE-2023-6867 (bmo#1863863)
Clickjacking permission prompts using the popup transition
* CVE-2023-6861 (bmo#1864118)
Heap buffer overflow affected nsWindow::PickerOpen(void) in
headless mode
* CVE-2023-6868 (bmo#1865488)
WebPush requests on Firefox for Android did not require VAPID key
* CVE-2023-6869 (bmo#1799036)
Content can paint outside of sandboxed iframe
* CVE-2023-6870 (bmo#1823316)
Android Toast notifications may obscure fullscreen event
notifications
* CVE-2023-6871 (bmo#1828334)
Lack of protocol handler warning in some instances
* CVE-2023-6872 (bmo#1849186)
Browsing history leaked to syslogs via GNOME
* CVE-2023-6863 (bmo#1868901)
Undefined behavior in ShutdownObserver()
* CVE-2023-6864 (bmo#1736385, bmo#1810805, bmo#1846328, bmo#1856090,
bmo#1858033, bmo#1858509, bmo#1862777, bmo#1864015)
Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6,
and Thunderbird 115.6
* CVE-2023-6873 (bmo#1855327, bmo#1862089, bmo#1862723)
Memory safety bugs fixed in Firefox 121
- requires NSS 3.95
==== apache2-mod_php8 ====
Version update (8.2.13 -> 8.2.14)
- version update to 8.2.14
* This is a bug fix release.
https://www.php.net/ChangeLog-8.php#8.2.14
==== bind ====
Version update (9.18.20 -> 9.18.21)
Subpackages: bind-doc bind-utils
- Update to release 9.18.21
Removed Features:
* Support for using AES as the DNS COOKIE algorithm
(cookie-algorithm aes;) has been deprecated and will be removed
in a future release. Please use the current default,
SipHash-2-4, instead.
* The resolver-nonbackoff-tries and resolver-retry-interval
statements have been deprecated. Using them now causes a
warning to be logged.
==== bluez ====
Version update (5.70 -> 5.71)
Subpackages: bluez-auto-enable-devices bluez-cups libbluetooth3
- add fix-link-key-address-type.patch - thanks to
pallaswept for identifying the right patch for the pairing
regression
- update to 5.71:
* Fix issue with not registering CSIS service.
* Fix issue with registering pairing callbacks.
* Fix issue with corruption during discovery filter parsing.
- drop CVE-2023-45866.patch,
Fix-.device_probe-failing-if-SDP-record-is-not.patch: upstream
- update bluez-disable-broken-tests.diff: disable failing vcp test
==== cfitsio ====
Version update (4.3.0 -> 4.3.1)
- Update to version 4.3.1:
* Improve longstring keyword functions
==== ell ====
Version update (0.60 -> 0.61)
- Update to release 0.61
* netconfig: Always set DHCP MAC address on start
* netlink: Add workaround for missing NLM_F_ACK_TLVS
and NLM_F_CAPPED
==== emacs ====
Subpackages: emacs-el emacs-eln emacs-info emacs-nox emacs-x11 etags
- fix typo in %{ext_info} macro usage
==== evolution ====
Version update (3.50.2 -> 3.50.3)
Subpackages: evolution-plugin-spamassassin
- Update to version 3.50.3:
+ rss: Ensure feed icon size to not be too large.
+ Bug Fixes:
- Calendar: Improve print of the Month view
- rss: Better parse itunes feeds
- Drag and drop images in HTML composer from Chrome
- EMFolderTree: Do not expand to-be-selected folder
+ Updated translations.
==== evolution-data-server ====
Version update (3.50.2 -> 3.50.3)
Subpackages: libcamel-1_2-64 libebackend-1_2-11 libebook-1_2-21 libebook-contacts-1_2-4 libecal-2_0-2 libedata-book-1_2-27 libedata-cal-2_0-2 libedataserver-1_2-27 libedataserverui-1_2-4
- Update to version 3.50.3:
+ Camel: Ignore errors about missing messages during filtering.
+ Bug Fixes:
- sqlite3_enable_shared_cache is deprecated
- Camel: Hide errors from for-offline download
- IMAP: Copy/move messages in smaller batches
+ Updated translations.
==== evolution-ews ====
Version update (3.50.2 -> 3.50.3)
- Update to version 3.50.3:
+ Bug Fixes:
- Mail: Calendar attachments can be broken by the server.
- Workaround Outlook 2019 ORGANIZER and ATTENDEE addition into
plain events.
+ Updated translations.
==== ffmpeg-4 ====
Subpackages: libavcodec58_134 libavformat58_76 libavutil56_70 libpostproc55_9 libswresample3_9 libswscale5_9
- Update ffmpeg-glslang-cxx17.patch to build with glslang 14
- Disable vmaf integration as ffmpeg-4 cannot handle vmaf>=3
- Delete vmaf-trim-usr-local.patch
==== fltk ====
Version update (1.3.8 -> 1.3.9)
- update to 1.3.9:
* Support macOS up to macOS 14 "Sonoma".
* Update bundled libraries to current versions (see below).
* Introduce bundled image library "prefixing" to avoid
conflicts with system libraries.
* Bundled library versions (see also README.bundled-libs.txt):
* Library Version Release date
* jpeg jpeg-9e 2022-01-16
* png libpng-1.6.40 2023-06-21
* zlib zlib-1.3 2023-08-18
* Backport X11 INCR protocol fixes from 1.4.0 (issue #451)
* X11: Suppress compiler warnings when using gcc or clang
* Fix crash if a program exits before it opens a window
* Fix compilation error with current Visual Studio 2022
* Backport warning fixes from 1.4.0 in src/fl_draw.cxx
* Fix compiler warning as pointed out in PR #693
* Fix another compiler warning (#693)
* Remove unused variable, fix "type issue" (#445, part 2)
* Fix stack buffer overflow found by address sanitizer
* Fix "gtk+ rendering" (GitHub Issue #443)
* Fix doxygen warnings
* Bump version numbers, prepare release 1.3.9
* Fix several compiler warnings
* Update bundled image libraries and zlib to current
versions
* Update README, README.CMake.txt, and some support files
* Fix compiler warnings: backported from 1.4 (git 'master')
* CMake/MSVC: remove confusing recommendation to rerun
* Documentation: remove dark color on title page
* Raise CMake minimum required version to 3.15 and more
* macOS platform: Issue #325 "Disabling IM disables Greek
and Cyrillic layouts"
* Fix fullscreen window level corner cases on macOS
* Fix issue #373 apparent with macOS platform and SDK â¤
* Issue #452: Fl::get_font_name failure on OS-X.
* Issue #454: crash in Fl::get_font_name().
* Issue #469: Fl_Sys_Menu_Bar menu item shortcuts using Esc
Tab don't work on Mac
* Fix "Focus is lost leaving full screen on macOS 13"
* Add support of macOS Ventura 13.0 and macOS Sonoma 14.0
* macOS: remove configure option --enable-x11 and CMake
OPTION_APPLE_X11; this functionality remains in FLTK 1.4.
* configure.ac: make sure local-png and local-zlib always
run together
* Remove the -mwindows argument from CFLAGS and CXXFLAGS
==== frameworkintegration ====
Subpackages: frameworkintegration-plugin libKF5Style5
- Update appstream build requirement for compatibility with 1.0.0
==== fwupd ====
Version update (1.9.10 -> 1.9.11)
Subpackages: fwupd-bash-completion libfwupd2 typelib-1_0-Fwupd-2_0
- Update to version 1.9.11:
+ This release adds the following features:
- Allow exporting 'offline' reports for manual upload
+ This release fixes the following bugs:
- Add some recovery partition names to ignore for ESP selection
- Check for CET and SMAP on non-Intel x86 processors too
- Correctly mark the CPU as supported in the HSI tests
- Do not fail on probing downstream Synaptics MST ports
- Do not offer to change BIOS settings that are already set
- Do not prefer msftdata when choosing the default ESP
- Do not show spurious device request flags
- Fix a missing build dependency to fwupdplugin-self-test
- Fix a segfault when using zlib-ng instead of zlib
- Fix updating Jabra 410, 510, 710 and 810 devices
- Match more community-supported branches
- Remove the Intel SPIBAR proxy support as the mtd module works
- Show a better error when the ESP is missing
- Show an error if the post-update version does not match exactly
- Speed up Synaptics MST device enumeration
+ This release adds support for the following hardware:
- Algoltek USB devices
- Luxshare Quad USB4 Dock
==== ghostscript ====
Subpackages: ghostscript-x11
- CVE-2023-46751.patch is
https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=dcdbc595c13
adapted for Ghostscript-9.56.1 that fixes
https://bugs.ghostscript.com/show_bug.cgi?id=707264
which includes a fix for CVE-2023-46751
"dangling pointer in gdev_prn_open_printer_seekable()"
(bsc#1217871)
==== gnome-control-center ====
Subpackages: gnome-control-center-color gnome-control-center-goa gnome-control-center-user-faces
- Add gnome-control-center-fix-region-preview-crash.patch:
nl_langinfo's returned pointer could be invalid after switching
locale, so we have to save the result before switch locale to
prevent the crash (bsc#1218528,
glgo#GNOME/gnome-control-center!2122).
==== gnome-settings-daemon ====
Version update (45.0 -> 45.1)
- Update to version 45.1:
+ Power: Compiler warning fixes.
+ Smartcard: Error handling fix.
+ USB Protection: Comment clean up.
+ Updated translations.
- Drop upstream fixed patches:
+ 41d0dc1db4d75c37ba67fe903105b4e162d42f1a.patch
+ 538816ff42f682fc4b541810ca107486abab9976.patch
+ a059909d62da0c11774f1089d02937699fabf150.patch
==== gnustep-base ====
- Add 295.patch: Fix build with libxml2 2.11.0+.
==== gpgme ====
Subpackages: libgpgme11 libgpgmepp6
- Python 3.12 has dropped distutils
* Build require python-setuptools instead
* Drop old gpgme-D545-python310.patch
* Replace with gpgme-D545-obsolete-distutils.patch
==== gpgmeqt ====
- Python 3.12 has dropped distutils
* Build require python-setuptools instead
* Drop old gpgme-D545-python310.patch
* Replace with gpgme-D545-obsolete-distutils.patch
==== grub2 ====
Subpackages: grub2-arm64-efi grub2-snapper-plugin grub2-systemd-sleep-plugin
- grub2.spec: Add ofnet to signed grub.elf to support powerpc net boot
installation when secure boot is enabled (bsc#1217761)
- Improved check for disk device when looking for PReP partition
* 0004-Introduce-prep_load_env-command.patch
==== gstreamer ====
Version update (1.22.7 -> 1.22.8)
Subpackages: gstreamer-utils libgstreamer-1_0-0 typelib-1_0-Gst-1_0
- Update to version 1.22.8:
+ Highlighted bugfixes in 1.22.8
- Security fixes for the AV1 video codec parser
- avdec video decoder: fix another possible deadlock with
FFmpeg 6.1
- qtdemux: reverse playback and seeking fixes for files with
raw audio streams
- v4l2: fix "newly allocated buffer ... is not free" warning
log flood
- GstPlay + GstPlayer library fixes
- dtls: Fix build failure on Windows when compiling against
OpenSSL 3.2.0
- d3d11screencapturesrc: Fix wrong color with HDR enabled
- Cerbero build tool: More python 3.12 string escape warning
fixes; make sure to bundle build tools as well
- various bug fixes, build fixes, memory leak fixes, and other
stability and reliability improvements
+ gstreamer
- buffer: Unref memories before metas
- pad: Recheck pads when linking after temporary unlock
- baseparse: Fixes to buffers extracted from adapter
- Rebase reduce-required-meson.patch
==== gstreamer-plugins-bad ====
Version update (1.22.7 -> 1.22.8)
Subpackages: libgstadaptivedemux-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstplayer-1_0-0 libgstsctp-1_0-0 libgsttranscoder-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0
- Update to version 1.22.8:
+ aesenc: Fix IV length addition to output buffer length
+ av1parser: Fix array sizes in scalability structure
(ZDI-CAN-22300 bsc#1218534)
+ camerabin: Fix source updates with user filters
+ codecparsers: av1: Clip max tile rows and cols values
+ dtlscertificate: Define WINSOCKAPI before including windows.h
+ d3d11: fix building with address sanitizer
+ d3d11screencapturesrc: Fix wrong color with HDR enabled
+ h264decoder: Fix GstVideoCodecFrame leak
+ ladspa: Make RDF parsing truly optional
+ rtponviftimestamp: Fix drop-out-of-segment=false mode
+ qsvdecoder: Fix stream format detection
+ webrtcsdp: Remove fingerprint validation that doesn't make
sense
+ GstPlay: Automatically flush the bus when disposing the
signal adapter
+ GstPlayer: Without dispatcher emit signals directly instead
of via the default main context
- Rebase reduce-required-meson.patch
==== gstreamer-plugins-base ====
Version update (1.22.7 -> 1.22.8)
Subpackages: libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstfft-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgstrtp-1_0-0 libgstrtsp-1_0-0 libgstsdp-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 typelib-1_0-GstAudio-1_0 typelib-1_0-GstPbutils-1_0 typelib-1_0-GstTag-1_0 typelib-1_0-GstVideo-1_0
- Update to version 1.22.8:
+ appsrc: Fix flow return when buffer is dropped
+ audioringbuffer: Don't try to map MONO channel
+ encoding-target: Properly free when missing type field in
parse_encoding_profile
+ pbutils: Don't include default vp9 parameters in resulting
codec mime string
+ videorate: Don't forget last_ts on caps changes
- Rebase reduce-required-meson.patch
==== gstreamer-plugins-good ====
Version update (1.22.7 -> 1.22.8)
Subpackages: gstreamer-plugins-good-extra gstreamer-plugins-good-gtk gstreamer-plugins-good-jack gstreamer-plugins-good-qtqml
- Update to version 1.22.8:
+ dcaparse: keep upstream buffer meta
+ rtpklvdepay: Recover after invalid fragmented KLV unit
+ matroska-demux: fix accumulated base offset in segment seeks
+ qtdemux: fix bug report URL
+ qtdemux: Don't overflow sample index
+ qtdemux: Fix reverse playback for pcm audio stream
+ qtdemux: Ignore raw audio streams when adjusting seek
+ qtdemux: Under-seeking to a key unit in certain (encoded by
Adobe products) ProRes movies (macOS x86_64 & arm64,
Windows x86_64, ...)
+ rtpac3depay: should output audio/x-ac3 not audio/ac3
+ rtp: Fix incorrect RTP channel order lookup by name
+ v4l2bufferpool: add lock as atomic operation for seek
- Rebase reduce-required-meson.patch
==== gstreamer-plugins-libav ====
Version update (1.22.7 -> 1.22.8)
- Update to version 1.22.8:
+ avviddec: Unlock stream lock while waiting for decoded frame.
Fixes potential deadlock
+ avviddec: Calculate latency only for fixed framerate
- Rebase reduce-required-meson.patch.
==== gstreamer-plugins-rs ====
Version update (0.11.2 -> 0.11.3)
- Update to version 0.11.3:
+ Fixed
- ndi: Mark a private type as such and remove a wrong `Clone`
impl of internal types.
- uriplaylistbin: Fix a minor clippy warning.
- fallbacksrc: Fix error during badly timed timeout scheduling.
- webrtcsink: Fail gracefully if webrtcbin pads can't be
requested instead of panicking.
- threadshare: Fix deadlock in `ts-udpsrc`
`notify::used-socket` signal emission.
+ Changed
- Update to AWS SDK 1.0.
- Update to windows-sys 0.52.
- Update to async-tungstenite 0.24.
- Update to bitstream-io 2.0.
- tttocea608: De-duplicate some functions.
- gtk4: Use async-channel instead of deprecated GLib main
context channel.
- Update BuildRequires on cargo-c >= 0.9.21.
==== gstreamer-plugins-ugly ====
Version update (1.22.7 -> 1.22.8)
- Update to version 1.22.8:
+ No changes, stable bump only.
- Rebase reduce-required-meson.patch.
==== gtk-layer-shell ====
Version update (0.8.1 -> 0.8.2)
- Update to 0.8.2:
* Compat: bump supported GTK to v3.24.39
* Compat: NOTE: GTK v3.24.40 may break previous version and work
with this one, but we won't know for sure until it's released
==== gucharmap ====
Version update (15.1.1 -> 15.1.2)
Subpackages: libgucharmap_2_90-7
- Update to version 15.1.2:
+ Updated translations.
==== guestfs-tools ====
Version update (1.51.6 -> 1.52.0)
- Update to version 1.52.0
* mltools/libosinfo-c.c: Fix off-by-one error
* Documentation fixes
* Fix bugs-in-changelog.sh: Use grep -E instead of egrep
==== hplip ====
Version update (3.23.8 -> 3.23.12)
Subpackages: hplip-hpijs hplip-sane hplip-udev-rules
- Update to hplip 3.23.12
* del fix-printer-attributes-parsing.patch (merged upstream)
* del hppsfilter-booklet-printing-change-insecure-fixed-tm.patch
(merged upstream)
- Added support for new printers:
* HP OfficeJet Pro 9130b series
* HP OfficeJet Pro 9120b series
* HP OfficeJet Pro 9110b series
* HP Color LaserJet Enterprise Flow MFP X58045z
* HP Color LaserJet Enterprise Flow MFP X58045zs
* HP Color LaserJet Enterprise MFP X58045dnâ
* HP Color LaserJet Enterprise MFP X58045
* HP LaserJet Pro P1106 plus
* HP LaserJet Pro P1108 plus
==== hxtools ====
Version update (20231101 -> 20231224)
Subpackages: fd0ssh ofl
- Update to release 20231224
* Add gh-trim-workflowruns script
* git-forest: port to Perl 5.38
==== icewm ====
Version update (3.4.4 -> 3.4.5)
Subpackages: icewm-config-upstream icewm-default icewm-lang icewm-lite
- Update to 3.4.5:
* Fix for centering the clock LED digits vertically
* Fix the KeyWinTile commands for multi-mon setups
* Fix the workspace buttons for right-to-left languages
==== inotify-tools ====
Version update (3.22.6.0 -> 4.23.9.0)
Subpackages: libinotifytools0
- update to 4.23.9.0:
* support cross compile for Android
* libinotifytools: Rename init variable to fix conflict with
entry point
* Add CodeQL workflow for GitHub code scanning
* Fix build with musl and add Alpine buildnode to CI
* Update Cirrus CI FreeBSD images
* Fix enabling of fanotify/fsnotify.
* Fix fanotify_supported()
* Combine to one build machine, reduce test iteration to 64
* Add -fanalyzer to build
* Enable CentOS Stream 9 build
* Add debian 12
* Ensure C++ libraries are not linked in
==== iputils ====
Version update (20221126 -> 20231222)
- Update to version 20231222
https://github.com/iputils/iputils/releases/tag/20231222
- Use tar.xz instead of tar.gz
- Update source URL
==== iw ====
Version update (5.19 -> 6.7)
- Update to version 6.7:
* update nl80211.h
* bump version to 6.7
* update nl80211.h
* iw: allow extra cflags
* iw: S1G: add 802.11ah support for link command display
* update nl80211.h
* iw: connect: Fix segfault during open authentication
* iw: fix attribute size mismatch
* iw: add more extended capa bits
* iw: Fix EHT rates printing.
* iw: S1G: add list command support for 802.11ah
* iw: S1G: add parsing for 802.11ah scan IE's
* iw: S1G: add frequency set in kHz and offset options
* util: don't print EHT info if not present
* interface: print links
* link: update for MLO
* link: fix some formatting
* iw: scan: set NL80211_SCAN_FLAG_COLOCATED_6GHZ in case of full sched scan
* util: add support for 320MHz bandwidth without cf1
* util: add support for 320Mhz bandwidth
* update nl80211.h
* iw: event: fix printf format error
* iw: add support for retrieving keys
* iw: info: fix bug reading preambles and bandwidths
* iw: add cac background command
* iw: info: print PMSR capabilities
==== kernel-firmware ====
Version update (20231214 -> 20240102)
Subpackages: kernel-firmware-all kernel-firmware-amdgpu kernel-firmware-ath10k kernel-firmware-ath11k kernel-firmware-atheros kernel-firmware-bluetooth kernel-firmware-bnx2 kernel-firmware-brcm kernel-firmware-chelsio kernel-firmware-dpaa2 kernel-firmware-i915 kernel-firmware-intel kernel-firmware-iwlwifi kernel-firmware-liquidio kernel-firmware-marvell kernel-firmware-media kernel-firmware-mediatek kernel-firmware-mellanox kernel-firmware-mwifiex kernel-firmware-network kernel-firmware-nfp kernel-firmware-nvidia kernel-firmware-platform kernel-firmware-prestera kernel-firmware-qcom kernel-firmware-qlogic kernel-firmware-radeon kernel-firmware-realtek kernel-firmware-serial kernel-firmware-sound kernel-firmware-ti kernel-firmware-ueagle kernel-firmware-usb-network
- Update to version 20240102 (git commit b83108216200):
* linux-firmware: add firmware for mediatek bluetooth chip (MT7925)
* linux-firmware: add firmware for MT7925
* ASoC: tas2563: Add dsp firmware for laptops or other mobile devices
* QCA: Add bluetooth firmware nvm files for QCA2066
* QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00629
- Update aliases
- Update to version 20231226 (git commit abfcad8b1405):
* rtl_bt: Add firmware and config files for RTL8852BT/RTL8852BE-VT
* ASoC: tas2781: Add dsp firmware for different laptops
* ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.36
* ath11k: WCN6855 hw2.0: update board-2.bin
* ath11k: WCN6750 hw1.0: update board-2.bin
* ath11k: IPQ8074 hw2.0: update board-2.bin
* ath10k: WCN3990 hw1.0: update board-2.bin
* ath10k: QCA9888 hw2.0: update board-2.bin
* ath10k: QCA4019 hw1.0: update board-2.bin
* ath10k: QCA6174 hw3.0: update firmware-6.bin to WLAN.RM.4.4.1-00309-
* ath12k: add new driver and firmware for WCN7850
* iwlwifi: update gl FW for core80-165 release
* intel: vsc: Add firmware for Visual Sensing Controller
* cirrus: Add CS35L41 firmware and tunings for ASUS Zenbook 2023 Models
* cirrus: Add CS35L41 firmware and tunings for ASUS Zenbook 2022 Models
* amdgpu: DMCUB updates for various AMDGPU ASICs
- New subpackag kernel-firmware-ath12k
- Update aliases
==== kernel-source ====
Version update (6.6.6 -> 6.6.9)
- Linux 6.6.9 (bsc#1012628).
- bpf: Fix prog_array_map_poke_run map poke update (bsc#1012628).
- mm/damon/core: use number of passed access sampling as a timer
(bsc#1012628).
- mm/damon/core: make damon_start() waits until kdamond_fn()
starts (bsc#1012628).
- btrfs: qgroup: iterate qgroups without memory allocation for
qgroup_reserve() (bsc#1012628).
- btrfs: qgroup: use qgroup_iterator in qgroup_convert_meta()
(bsc#1012628).
- btrfs: free qgroup pertrans reserve on transaction abort
(bsc#1012628).
- drm/amd/display: fix hw rotated modes when PSR-SU is enabled
(bsc#1012628).
- drm/i915: Fix FEC state dump (bsc#1012628).
- drm/i915: Introduce crtc_state->enhanced_framing (bsc#1012628).
- drm/i915/edp: don't write to DP_LINK_BW_SET when using rate
select (bsc#1012628).
- drm: Update file owner during use (bsc#1012628).
- drm: Fix FD ownership check in drm_master_check_perm()
(bsc#1012628).
- spi: spi-imx: correctly configure burst length when using dma
(bsc#1012628).
- arm64: dts: allwinner: h616: update emac for Orange Pi Zero 3
(bsc#1012628).
- ARM: dts: dra7: Fix DRA7 L3 NoC node register size
(bsc#1012628).
- ARM: OMAP2+: Fix null pointer dereference and memory leak in
omap_soc_device_init (bsc#1012628).
- reset: Fix crash when freeing non-existent optional resets
(bsc#1012628).
- s390/vx: fix save/restore of fpu kernel context (bsc#1012628).
- platform/x86/intel/pmc: Fix hang in pmc_core_send_ltr_ignore()
(bsc#1012628).
- SUNRPC: Revert 5f7fc5d69f6e92ec0b38774c387f5cf7812c5806
(bsc#1012628).
- wifi: ieee80211: don't require protected vendor action frames
(bsc#1012628).
- wifi: iwlwifi: pcie: add another missing bh-disable for
rxq->lock (bsc#1012628).
- wifi: mac80211: check if the existing link config remains
unchanged (bsc#1012628).
- wifi: mac80211: don't re-add debugfs during reconfig
(bsc#1012628).
- wifi: mac80211: check defragmentation succeeded (bsc#1012628).
- wifi: mac80211: mesh: check element parsing succeeded
(bsc#1012628).
- wifi: mac80211: mesh_plink: fix matches_local logic
(bsc#1012628).
- ice: fix theoretical out-of-bounds access in ethtool link modes
(bsc#1012628).
- bpf: syzkaller found null ptr deref in unix_bpf proto add
(bsc#1012628).
- Revert "net/mlx5e: fix double free of encap_header in update
funcs" (bsc#1012628).
- Revert "net/mlx5e: fix double free of encap_header"
(bsc#1012628).
- net/mlx5e: Fix slab-out-of-bounds in
mlx5_query_nic_vport_mac_list() (bsc#1012628).
- net/mlx5e: Fix a race in command alloc flow (bsc#1012628).
- net/mlx5e: fix a potential double-free in fs_udp_create_groups
(bsc#1012628).
- net/mlx5e: Fix overrun reported by coverity (bsc#1012628).
- net/mlx5e: Decrease num_block_tc when unblock tc offload
(bsc#1012628).
- net/mlx5e: XDP, Drop fragmented packets larger than MTU size
(bsc#1012628).
- net/mlx5: Fix fw tracer first block check (bsc#1012628).
- net/mlx5: Refactor mlx5_flow_destination->rep pointer to vport
num (bsc#1012628).
- net/mlx5e: Fix error code in mlx5e_tc_action_miss_mapping_get()
(bsc#1012628).
- net/mlx5e: Fix error codes in alloc_branch_attr() (bsc#1012628).
- net/mlx5e: Correct snprintf truncation handling for fw_version
buffer (bsc#1012628).
- net/mlx5e: Correct snprintf truncation handling for fw_version
buffer used by representors (bsc#1012628).
- net: mscc: ocelot: fix eMAC TX RMON stats for bucket 256-511
and above (bsc#1012628).
- net: mscc: ocelot: fix pMAC TX RMON stats for bucket 256-511
and above (bsc#1012628).
- octeontx2-pf: Fix graceful exit during PFC configuration failure
(bsc#1012628).
- net: Return error from sk_stream_wait_connect() if
sk_wait_event() fails (bsc#1012628).
- net: sched: ife: fix potential use-after-free (bsc#1012628).
- ethernet: atheros: fix a memleak in atl1e_setup_ring_resources
(bsc#1012628).
- net/rose: fix races in rose_kill_by_device() (bsc#1012628).
- Bluetooth: Fix not notifying when connection encryption changes
(bsc#1012628).
- Bluetooth: Fix deadlock in vhci_send_frame (bsc#1012628).
- Bluetooth: hci_event: shut up a false-positive warning
(bsc#1012628).
- Bluetooth: hci_core: Fix hci_conn_hash_lookup_cis (bsc#1012628).
- bnxt_en: do not map packet buffers twice (bsc#1012628).
- net: phy: skip LED triggers on PHYs on SFP modules
(bsc#1012628).
- ice: stop trashing VF VSI aggregator node ID information
... changelog too long, skipping 898 lines ...
- commit 59f1683
==== kmozillahelper ====
- BuildRequire rpm_macro(cmake_kf5): we call cmake_kf5 to build and
thus need to ensure the macro to be known.
- Add extra-cmake-modules BuildRequires: fix build after recent KDE
Frameworks update.
==== libHX ====
Version update (4.19 -> 4.21)
- Update to release 4.21
* Resolve compile error when signed_cast macro is used.
==== libarchive ====
Version update (3.7.0 -> 3.7.2)
- skip write tests on 32bit, they OOM
- update to 3.7.2:
* Multiple vulnerabilities have been fixed in the PAX writer
* bsdunzip(1) now correctly handles arguments following an
- x after the zipfile
* zstd filter now supports the "long" write option
* SEGV and stack buffer overflow in verbose mode of cpio
* bsdunzip updated to match latest upstream code
* miscellaneous functional bugfixes
==== libavif ====
Version update (1.0.2 -> 1.0.3)
- update to 1.0.3:
* Rewrite the fix for memory errors fixed in 1.0.2
* CVE-2023-6704: Fix use-after-free errors (boo#1218303)
* src/reformat.c: Allocate the threadData array directly
==== libdrm ====
Version update (2.4.118 -> 2.4.119)
Subpackages: libdrm2 libdrm_amdgpu1 libdrm_nouveau2 libdrm_radeon1
- update to 2.4.119:
* add amdgpu_va_get_start_addr
==== libebml ====
Version update (1.4.4 -> 1.4.5)
- update to 1.4.5 (bsc#1218432):
* Fix invalid memory access (reading beyond allocated memory)
due to missing integer overflow check.
==== libguestfs ====
Version update (1.51.9 -> 1.52.0)
Subpackages: libguestfs-appliance libguestfs-xfs libguestfs0
- Update to version 1.52.0
* The Python bindings now use bytes (instead of str) for the
event callback message, since it may contain arbitrary 8 bit
data
Fix a rare crash, and avoid memory leaks in event callbacks
* Support for OCaml 5, and OCaml ⥠4.07 is now the minimum
* The OCaml bindings now release the runtime lock around calls
to guestfs_close, since that call might be long-running (for
example it might have to shut down the appliance and synch disks).
* Support OpencloudOS
* SELinux relabelling now runs in parallel, meaning it's a lot
quicker
* Add support for lzma and zstd compression methods in tar APIs
(like guestfs_tar_in)
* guestfs_pvs_full previously didn't always return the correct
device names. This has now been fixed.
* guestfs_btrfs_filesystem_balance fixed so it now works with
more modern btrfs tools (Jürgen Hötzel).
* The guestfish(1) --key option now recognizes LVM names like
/dev/mapper/rhel_bootp--73--75--123-root
* guestfish --key option also supports a new --key all:...
selector to try the same key on all devices.
* In guestmount(1) avoid calling fclose(NULL) on error paths,
which might have caused a crash on some platforms.
==== libheif ====
Version update (1.17.5 -> 1.17.6)
Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openjpeg libheif-rav1e libheif1
- update to 1.17.6:
* A couple of build fixes and bug fixes detected by fuzzing.
* Corrects these issues:
* CVE-2023-49462 - #1043
* CVE-2023-49463 - #1042
- drop libheif-CVE-2023-49462.patch,
libheif-CVE-2023-49464.patch,
libheif-CVE-2023-49460.patch: upstream
- security update
- added patches
fix CVE-2023-49460 [bsc#1217902], segmentation violation in decode_uncompressed_image()
+ libheif-CVE-2023-49460.patch
- sync ExclusiveArch with SVT-AV1
- move HEIF plugins from examples to separate package
- make sure all subpackages use the same libheif1 ABI
==== libical ====
Version update (3.0.16 -> 3.0.17)
- update to 3.0.17:
* Escape commas in x-property TEXT values
* Built-in timezones updated to tzdata2023c
* icalparser_ctrl setting defines how to handle invalid CONTROL
characters during parsing
* New publicly available functions:
+ get_zone_directory()
+ icalparser_get_ctrl
+ icalparser_set_ctrl
==== libical-glib ====
Version update (3.0.16 -> 3.0.17)
- update to 3.0.17:
* Escape commas in x-property TEXT values
* Built-in timezones updated to tzdata2023c
* icalparser_ctrl setting defines how to handle invalid CONTROL
characters during parsing
* New publicly available functions:
+ get_zone_directory()
+ icalparser_get_ctrl
+ icalparser_set_ctrl
==== libjcat ====
Version update (0.1.14 -> 0.2.0)
- Update to version 0.2.0:
+ New Features:
- Add support for verifying firmware transparency checkpoints
- Add various bitcounting functions for future use
- Allow creating and validating SHA512 checksums
- Allow verifying the checksum of a payload
+ Bugfixes:
- Sprinkle attribute((nonnull)) to give a little more
compile-time safety
==== libjpeg-turbo ====
Version update (8.2.2 -> 8.3.2)
- update to 3.0.1 (bsc#1211542, CVE-2023-2804):
* The x86-64 SIMD functions now use a standard stack frame,
prologue, and epilogue so that debuggers and profilers can
reliably capture backtraces from within the functions.
* Fixed two minor issues in the interblock smoothing algorithm
that caused mathematical (but not necessarily perceptible)
edge block errors when decompressing progressive JPEG images
exactly two MCU blocks in width or that use vertical
chrominance subsampling.
* The TurboJPEG API now supports 4:4:1 (transposed 4:1:1)
chrominance subsampling, which allows losslessly transposed or
rotated 4:1:1 JPEG images to be losslessly cropped, partially
decompressed, or decompressed to planar YUV images.
* Fixed various segfaults and buffer overruns (CVE-2023-2804)
* that occurred when attempting to decompress various
specially-crafted malformed 12-bit-per-component and
16-bit-per-component lossless JPEG images using color
quantization or merged chroma upsampling/color conversion. The
underlying cause of these issues was that the color
quantization and merged chroma upsampling/color conversion
algorithms were not designed with lossless decompression
in mind. Since libjpeg-turbo explicitly does not support color
conversion when compressing or decompressing lossless JPEG
images, merged chroma upsampling/color conversion never should
have been enabled for such images. Color quantization is a
legacy feature that serves little or no purpose with lossless
JPEG images, so it is also now disabled when decompressing such
images. (As a result, djpeg can no longer decompress a
lossless JPEG image into a GIF image.)
* Fixed an oversight in 1.4 beta1[8] that caused various
segfaults and buffer overruns when attempting to decompress
various specially-crafted malformed 12-bit-per-component JPEG
images using djpeg with both color quantization and RGB565
color conversion enabled.
* Fixed an issue whereby `jpeg_crop_scanline()` sometimes
miscalculated the downsampled width for components with 4x2 or
2x4 subsampling factors if decompression scaling was enabled.
This caused the components to be upsampled incompletely, which
caused the color converter to read from uninitialized memory.
With 12-bit data precision, this caused a buffer overrun or
underrun and subsequent segfault if the sample value read from
uninitialized memory was outside of the valid sample range.
* Fixed a long-standing issue whereby the `tj3Transform()`
function, when used with the `TJXOP_TRANSPOSE`,
`TJXOP_TRANSVERSE`, `TJXOP_ROT90`, or `TJXOP_ROT270` transform
operation and without automatic JPEG destination buffer
(re)allocation or lossless cropping, computed the worst-case
transformed JPEG image size based on the source image
dimensions rather than the transformed image dimensions. If a
calling program allocated the JPEG destination buffer based on
the transformed image dimensions, as the API documentation
instructs, and attempted to transform a specially-crafted
4:2:2, 4:4:0, 4:1:1, or 4:4:1 JPEG source image containing a
large amount of metadata, the issue caused `tj3Transform()` to
overflow the JPEG destination buffer rather than fail
gracefully. The issue could be worked around by setting
`TJXOPT_COPYNONE`. Note that, irrespective of this issue,
`tj3Transform()` cannot reliably transform JPEG source images
that contain a large amount of metadata unless automatic JPEG
destination buffer (re)allocation is used or `TJXOPT_COPYNONE`
is set.
* Significantly sped up the computation of optimal Huffman
tables. This speeds up the compression of tiny images by as
much as 2x and provides a noticeable speedup for images as
large as 256x256 when using optimal Huffman tables.
* All deprecated fields, constructors, and methods in the
TurboJPEG Java API have been removed.
* Arithmetic entropy coding is now supported with
12-bit-per-component JPEG images.
* Overhauled the TurboJPEG API to address long-standing
limitations and to make the API more extensible and intuitive.
==== libntlm ====
Version update (1.6 -> 1.7)
- update to 1.7:
* Moved GitLab URL to https://gitlab.com/gsasl/libntlm.
* Use gnulib ./bootstrap for building from version
controlled sources.
* API and ABI modifications:
+ No changes since last version.
==== libportal ====
Subpackages: libportal-gtk3-1 libportal-gtk4-1 libportal1 typelib-1_0-Xdp-1_0
- Replace copypasted summaries by something more concrete
==== libqt5-qtbase ====
Version update (5.15.11+kde138 -> 5.15.12+kde147)
Subpackages: libQt5Concurrent5 libQt5Core5 libQt5DBus5 libQt5Gui5 libQt5Network5 libQt5OpenGL5 libQt5PrintSupport5 libQt5Sql5 libQt5Sql5-mysql libQt5Sql5-sqlite libQt5Test5 libQt5Widgets5 libQt5Xml5 libqt5-qtbase-platformtheme-gtk3
- Update to version 5.15.12+kde147:
* Http2: fix potential overflow in assemble_hpack_block()
(bsc#1218413, CVE-2023-51714)
* HPack: fix incorrect integer overflow check
* HPack: fix a Yoda Condition
- Update to version 5.15.12+kde144, rebased upstream:
* QMimeDatabase: handle buggy type definitions with circular inheritance
* xcb: only set base size when it's valid
* QPixmapCache: fix leaking of QStrings and Keys on clear()
* OpenFile portal: do not use O_PATH fds
* QSystemTrayIcon: properly disconnect old menu in setContextMenu()
* Guard QTabBar against nested event processing during moving tabs
* QDial: don't crash when min==max and setting a value != min & max
* QStandardItemModel: don't leak in mimeData()
* SQL/MySQL: properly initialize variable
* QWidgetTextControl: ignore invalid input method event
* Update the LGPL license header
* SQL/MySQL: fix handling of json column
* Remove QMAKE_RANLIB and QMAKE_LINK_SHLIB from android/default_pre.prf
* macOS: Fix less common writing systems on Catalina and later
* Blacklist 1 tests in tst_QFtp on ubuntu-20.04
* Update bundled libpng to version 1.6.39
* Android: Fix signing of APKs that are generated when an AAB is also built
* Update bundled zlib to version 1.2.13
* doc: update the limitation of QSystemTrayIcon on X11
* Blacklist 1 tests in tst_QTimer on ubuntu-20.04
* Add benchmarks for QLocale number parsing
* Add benchmarks for QString number parsing
* Android: Fix incorrect fullscreen dimensions
* Gtk3Theme: set XCURSOR_SIZE and XCURSOR_THEME for wayland sessions
* xcb: Flush Display when processing xcb events
* xcb: Add xlib wrapper for XFlush()
* QHostAddress: Fix incorrect comparison against 'Any'
* QSsl[OpenSSL/Android]: Fix hardcoded 1_1 suffix
* BLACKLIST: tst_QApplication::sendEventsOnProcessEvents for RHEL 9.0
* QMacStyle: do not set white color for grayed out button
* Work round macOS's omission of en_DE from its own uiLanguages()
* Suppress a deprecation warning in tst_QDateTime::toString_enumformat()
* QJsonValue: fix incorrect to{Array,Object} when the value is empty
* QGtk3Dialog: remove the #include for empty moc
* Remove unneeded QWindow from QGtk3Dialog
* tst_QSslSocket: Delete sslOptions
* tst_QSslServer: Make the in-process server use TLS1.2
* Android: fix Gradle warning about using enableUncompressedNativeLibs
* Mention limitation of QDir::drives() on Windows
* QFileSystemEngine/Win: fix incorrect buffer size in currentPath()
* Android: properly retrieve mime type of uri to for openUrl()
* Android: Fix clipboard issue with urls
* Android: Add a way to disable accessibility via an environment var
* Update bundled libpng to version 1.6.38
* QIOSMessageDialog::exec - work around 'windowsless' exec
* QIosScreen: retain the right window
* tst_Q{BitArray,ContiguousCache}: check not only count(), but size(), too
* QIosTextResponder: stop using deprecated constants and type
* qcompilerdetection.h: detect Coverity
* Android: Fix Display.getRealMetrics deprecation
* Fix broken Text rendering when noantialiased NativeRendering is used
* forkfd: fix Clang 15 ATOMIC_VAR_INIT deprecation warning
* eglfs: Add env.var. to disable the dedicated drmHandleEvent thread
* doc: Don't put strings into QVector<double>
* Remove focusProxyAndInputMethods from tst_QWidget
* Bump version to 5.15.12
* Update documentation of qWaitForWindowActive / qWaitForWindowExposed
* QtHttp: Lower the severity of some log output
* StyleSheetStyle: Fix color of placeholder texts in text edits
* Android: Fix flickering on split screen mode
* Update url to IAccessible2 Specification
==== libqt5-qtconnectivity ====
Version update (5.15.11+kde6 -> 5.15.12+kde6)
Subpackages: libQt5Bluetooth5 libQt5Bluetooth5-imports libQt5Nfc5 libQt5Nfc5-imports libqt5-qtconnectivity-tools
- Update to version 5.15.12+kde6, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtdeclarative ====
Version update (5.15.11+kde30 -> 5.15.12+kde31)
- Update to version 5.15.12+kde31, rebased upstream:
* QML: Fortify qmlExecuteDeferred some more
* QV4: Avoid memory corruption in Reflect.apply
* Blacklist 1 tests in tst_qquickanimations on macos
* doc: Add note to PinchHandler.translation property about macOS trackpad
* Revert "masm: Treat Android as generic Posix regarding mmap and friends"
* QML: Check for stack overflows when creating objects
* Fix wrong item-sizeHint-cache when StackLayout children were reordered
* Doc: Add missing QQuickWindow constructor
* Handle missing stops gracefully in Shape gradients
* Do not crash if madvise() fails on MADV_WILLNEED
* Blacklist 1 tests in tst_qquickbehaviors on macos
* Avoid double applyDelegateChange in QQIV::setDelegate
* QSGGeometry: add Q_DISABLE_COPY_MOVE
* Qml: Don't crash on bad grouped properties
* Fix TypeError in dynamicview1 example
* Fix broken Text rendering when noantialiased NativeRendering is used
* Trim file names before adding them to qml components and scripts
* masm: Treat Android as generic Posix regarding mmap and friends
* Bump version to 5.15.12
* Move StackLayout tests from qtquickcontrols.git (5.15)
==== libqt5-qtgraphicaleffects ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtimageformats ====
Version update (5.15.11+kde12 -> 5.15.12+kde10)
- Update to version 5.15.12+kde10, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtlocation ====
Version update (5.15.11+kde4 -> 5.15.12+kde6)
Subpackages: libQt5Location5 libQt5Positioning5 libQt5PositioningQuick5
- Update to version 5.15.12+kde6, rebased upstream:
* Fix HereMap plugin not supporting authentication via apiKey
* Fix build of Qt.labs.location QML plugin
* PositionSource: fix lastKnownPosition request at startup
* Bump version to 5.15.12
- Drop patches, now upstream:
* 0001-Fix-build-of-Qt.labs.location-QML-plugin.patch
==== libqt5-qtmultimedia ====
Version update (5.15.11+kde2 -> 5.15.12+kde2)
- Update to version 5.15.12+kde2, rebased upstream:
* Fix crash on macos13 with iphone camera
* VideoOutput: Always update geometry when video surface format changes
* VideoOutput: fix resize of a finished video
* Bump version to 5.15.12
* Windows: Fix cropping for HEVC-encoded videos
==== libqt5-qtnetworkauth ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtquickcontrols ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
* Remove tests for StackLayout
==== libqt5-qtquickcontrols2 ====
Version update (5.15.11+kde5 -> 5.15.12+kde5)
Subpackages: libQt5QuickControls2-5 libQt5QuickTemplates2-5
- Update to version 5.15.12+kde5, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtscript ====
Version update (5.15.15 -> 5.15.16)
- Update to version 5.15.16:
* Bump version to 5.15.16
- Update to version 5.15.15+kde0, rebased upstream:
* No code changes
- Commits dropped by the rebase:
* Bump version to 5.15.15
* Bump version to 5.15.14
* Bump version to 5.15.13
* Bump version to 5.15.12
* Bump version to 5.15.11
* Bump version to 5.15.10
==== libqt5-qtsensors ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
Subpackages: libQt5Sensors5 libQt5Sensors5-imports
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtserialport ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtspeech ====
Version update (5.15.11+kde1 -> 5.15.12+kde1)
Subpackages: libQt5TextToSpeech5 libqt5-qtspeech-plugin-speechd
- Update to version 5.15.12+kde1, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtsvg ====
Version update (5.15.11+kde6 -> 5.15.12+kde6)
- Update to version 5.15.12+kde6, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qttools ====
Version update (5.15.11+kde3 -> 5.15.12+kde4)
Subpackages: libQt5Designer5 libQt5Help5 libqt5-qdbus libqt5-qtpaths
- Update to version 5.15.12+kde4, rebased upstream:
* qdoc: Ensure the generated temporary header file is closed properly
* Bump version to 5.15.12
==== libqt5-qttranslations ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtvirtualkeyboard ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
Subpackages: libQt5HunspellInputMethod5 libQt5VirtualKeyboard5 libqt5-qtvirtualkeyboard-hunspell
- Update to version 5.15.12+kde0, rebased upstream:
* Doc: Improve locale section of technical guide
* Fix visible area in the basic example
* Bump version to 5.15.12
==== libqt5-qtwayland ====
Version update (5.15.11+kde59 -> 5.15.12+kde60)
Subpackages: libQt5WaylandClient5 libQt5WaylandCompositor5
- Update to version 5.15.12+kde60, rebased upstream:
* Client: Always populate mimedata in drags
* Client: Honor QGuiApplication::overrideCursor()
* Always use blocking write for data_source.send
* client: Mark return values as unused to suppress compiler warnings
* tests: fix tst_seatv4 to use 24 as default cursor size
* Bump version to 5.15.12
==== libqt5-qtwebchannel ====
Version update (5.15.11+kde3 -> 5.15.12+kde3)
Subpackages: libQt5WebChannel5 libQt5WebChannel5-imports
- Update to version 5.15.12+kde3, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtwebsockets ====
Version update (5.15.11+kde2 -> 5.15.12+kde2)
Subpackages: libQt5WebSockets5 libQt5WebSockets5-imports
- Update to version 5.15.12+kde2, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtwebview ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
Subpackages: libQt5WebView5 libQt5WebView5-imports
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtx11extras ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libqt5-qtxmlpatterns ====
Version update (5.15.11+kde0 -> 5.15.12+kde0)
Subpackages: libQt5XmlPatterns5 libqt5-qtxmlpatterns-imports
- Update to version 5.15.12+kde0, rebased upstream:
* Bump version to 5.15.12
==== libraw ====
Version update (0.21.1 -> 0.21.2)
- update to 0.21.2:
* New compile-defined limit LIBRAW_MAX_PROFILE_SIZE_MB:
limits allocation/read size for embedded color profile
Embedded color profile allocation/read size: limited by input
file size.
* Multiple fixes (mostly inspired by oss-fuzz) to improve
library stability and/or input checks.
* raw-identify: use fallback if PATH_MAX not available
* Disabled color conversion for Canon 16-bit thumbnails
* docs/changelog: explained the case when no thumbnail is found
in specific file
* swapXX renamed to libraw_swapXX to avoid name conflict
* better striped thumbnails handling
- drop libraw-CVE-2023-1729.patch (upstream)
==== librsvg ====
Version update (2.57.0 -> 2.57.1)
Subpackages: gdk-pixbuf-loader-rsvg librsvg-2-2 rsvg-thumbnailer typelib-1_0-Rsvg-2_0
- Update to version 2.57.1:
+ Fix small-caps and bump the version of Pango required to 1.50.0.
+ Fix panic when using negative scaling transforms on the
toplevel.
+ Support "var(--foo, #aabbcc)" just for colors. This is the
minimum required to render color SVG emoji fonts that provide
color fallbacks, but it is not yet full support for CSS var().
+ Fix the VS2017 build.
+ Update cairo-rs.
+ Update the project metadata files.
==== libstorage-ng ====
Version update (4.5.163 -> 4.5.170)
Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1
- merge gh#openSUSE/libstorage-ng#976
- make more use of new SystemCmd interface
- use in-class member initialization
- inhibit colored output from udevadm
- fixed typos
- 4.5.170
- merge gh#openSUSE/libstorage-ng#975
- reduce number of udevadm settle calls during probing
- use in-class member initialization
- proved probe function taking SystemInfo as an additional argument
- fixed typos
- moved code
- 4.5.169
- Translated using Weblate (Slovak) (bsc#1149754)
- 4.5.168
- Translated using Weblate (Dutch) (bsc#1149754)
- Translated using Weblate (Japanese) (bsc#1149754)
- Translated using Weblate (Czech) (bsc#1149754)
- Translated using Weblate (Catalan) (bsc#1149754)
- merge gh#openSUSE/libstorage-ng#974
- updated pot and po files
- 4.5.167
- merge gh#openSUSE/libstorage-ng#973
- fixed typos
- 4.5.166
- merge gh#openSUSE/libstorage-ng#972
- added note about nvme json output
- 4.5.165
- merge gh#openSUSE/libstorage-ng#971
- adapted to changed nvme json output (bsc#1218306)
- 4.5.164
==== libxmlb ====
Version update (0.3.14 -> 0.3.15)
- update to 0.3.15:
* Sprinkle __attribute__((nonnull)) to give a little more
compile-time safety
* Accept text/xml as an alternative to application/xml
* Do not inline shared code
* Fix compiling with Visual Studio
* Fix the exported api test on Windows
* Generate and use .def file for clang-cl builds
Fan)
* Release source file handles early
==== libzypp ====
Version update (17.31.25 -> 17.31.27)
- CheckAccessDeleted: fix 'running in container' filter
(bsc#1218291)
- version 17.31.27 (22)
- Call zypp commit plugins during transactional update (fixes #506)
- Add support for loongarch64 (fixes #504)
- Teach MediaMultiCurl to download HTTP Multibyte ranges.
- Teach zsync downloads to MultiCurl.
- Expand RepoVars in URLs downloading a .repo file (bsc#1212160)
Convenient and helps documentation as it may refer to a single
command for a bunch of distributions. Like e.g. "zypper ar
'https://server.my/$releasever/my.repo'".
- version 17.31.26 (22)
==== lsof ====
Version update (4.99.0 -> 4.99.3)
- lsof 4.99.3:
* Fix compilation error when HASIPv6 is not defined
* Add configure option --disable-liblsof to disable installation
of liblsof
- add lsof-4.99.3-fix-version-in-configure-ac.patch
==== lttng-ust ====
Version update (2.13.5 -> 2.13.6)
- update to 2.13.6:
* Fix: segmentation fault on filter interpretation in "switch"
mode
* Fix: `ip` context is expressed as a base-10 field
* Fix: c99: use __asm__ __volatile__
* Fix: c99: static assert: clang build fails due to multiple
typedef
* Fix: Reevaluate LTTNG_UST_TRACEPOINT_DEFINE each time
tracepoint.h is included
* Fix: trace events in C++ constructors/destructors
* Fix: trace events in C constructors/destructors
* Fix: use unaligned pointer accesses for lttng_inline_memcpy
==== mozilla-nss ====
Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools
- add nss-allow-slow-tests-s390x.patch: "certutil dump keys with
explicit default trust flags" test needs longer than the allowed
6 seconds on s390x
==== multipath-tools ====
Version update (0.9.7+76+suse.5f857af -> 0.9.7+93+suse.e2f2272)
Subpackages: kpartx libmpath0
- Update to version 0.9.7+93+suse.e2f2272:
* fix ANA prioritizer enablement logic (bsc#1218326)
* avoid setting queue_if_no_path on multipath maps for which the
no_path_retry timeout has expired
* the interactive commands "restorequeueing map X" and
"restorequeing maps" now only affect maps that had queueing
manually disabled using "disablequeuing maps" or
"disablequeuing map X" beforehand
* Spelling fixes
==== newt ====
Version update (0.52.23 -> 0.52.24)
- update to 0.52.24:
* add support for python3.13
* fix compiler warnings
==== nftables ====
Subpackages: libnftables1 python311-nftables
- buildrequire setuptools explicitly as pip drops the dependency
- Fix the python bindings subpackages
* The PEP517 python build requires setuptools
* Actually use the rpm subpackage definition
* The version is actually python3dist(nftables) = 0.1
* is noarch and requires libnftables1 through dlopen, tell
rpmlint
* remove unused shebang
==== nodejs21 ====
Subpackages: npm21
- c-ares-fixes.patch: fixes unit tests for new c-ares
==== open-iscsi ====
Subpackages: libopeniscsiusr0
- Updated to latest upstream: two small changes, with no known
functional changes:
* Incorrect documentation for `iscsiadm -m session` print level
(upstream issue #432)
* Stop using deprecated inet_aton and inet_ntoa (upstream issue
[#435])
- Also, stopped using pre-prepared tarballs for the build, instead
now using a service file to get latest SUSE srouces directly.
This removed these two files:
* open-iscsi-2.1.9-suse.tar.bz2, and
* open-iscsi-SUSE-latest.diff.bz2
whcih were both created by a shell script, and added a service-
file-generated file of the form:
* open-iscsi-2.1.9.suse+TAG_OFFSET.tar.xz
where TAG_OFFSET is of the form "COMMIT_COUNT.HASH", where
COMMIT_COUNT is the count of commits since 2.1.9-suse (in this
case), and HASH is the git commit hash being used.
==== openblas_openmp ====
- add Requires(pre/post): coreutils to the sub-packages that use
commands like: ln, dirname, mktemp, etc in the pre/post scriptlets
==== openblas_pthreads ====
- add Requires(pre/post): coreutils to the sub-packages that use
commands like: ln, dirname, mktemp, etc in the pre/post scriptlets
==== osinfo-db ====
Version update (20231027 -> 20231215)
- Update to database version 20231215 (jsc#PED-6305)
osinfo-db-20231215.tar.xz
==== perl-HTTP-Cookies ====
Version update (6.10 -> 6.110.0)
- updated to 6.11
see /usr/share/doc/packages/perl-HTTP-Cookies/Changes
6.11 2023-12-07 16:36:52Z
- Replace "Test" with "Test::More" (GH#70) (James Raspass)
==== perl-IO-Socket-SSL ====
- Fix the test t/core.t to build with OpenSSL 3.2.0. [bsc#1218342]
* https://github.com/noxxi/p5-io-socket-ssl/issues/147
* Add perl-IO-Socket-SSL-Openssl32.patch
==== perl-IO-Tty ====
Version update (1.180.0 -> 1.200.0)
- updated to 1.20
see /usr/share/doc/packages/perl-IO-Tty/ChangeLog
1.20 2023-12-28 Todd Rinaldo
participants (1)
-
Guillaume Gardet