Please note that this mail was generated by a script. The described changes are computed based on the aarch64 DVD. The full online repo contains too many changes to be listed here. Please check the known defects of this snapshot before upgrading: https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=3&version=Tumbleweed&build=20241113 Please do not reply to this email to report issues, rather file a bug on bugzilla.opensuse.org. For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports Packages changed: alsa (1.2.12 -> 1.2.13) alsa-ucm-conf (1.2.12 -> 1.2.13) alsa-utils (1.2.12 -> 1.2.13) grub2 libheif (1.19.2 -> 1.19.3) libopenmpt (0.7.10 -> 0.7.11) libsemanage libsoup libsoup2 llvm18 nghttp2 (1.62.1 -> 1.64.0) openSUSE-release (20241112 -> 20241113) openssl-3 qt6-declarative schily wget (1.24.5 -> 1.25.0) yast2-iscsi-client (5.0.3 -> 5.0.4) === Details === ==== alsa ==== Version update (1.2.12 -> 1.2.13) Subpackages: libasound2 libatopology2 - Update to alsa-lib 1.2.13: * static build fixes * documentation update for control remap API * PCM dmix fixes * pcm: implement snd_pcm_hw_params_get_sync() and obsolete snd_pcm_info_get_sync() * ump: Add a function to provide the packet word length of a UMP type * seq: Add snd_seq_{get|set}_ump_is_midi1() API functions * seq: Add API functions to set different tempo base values * seq: Add API helper functions for creating UMP Endpoint and Blocks * documentation fixes for UMP and sequencer API * test: Add an example programs for UMP For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-lib - Conditionally take libtool ==== alsa-ucm-conf ==== Version update (1.2.12 -> 1.2.13) - Update to version 1.2.13: * Updates for USB-audio, Mediatek, Qualcomm, ACP, SoundWire, wsa884x, wcd938x, Intel AVS, SOF HDA, etc For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-ucm-conf ==== alsa-utils ==== Version update (1.2.12 -> 1.2.13) - Update to alsa-utils 1.2.13: * alsactl: add support for AMD ACP digital microphone * aplay: Print '=== PAUSE ===' only if it is supported * aplaymidi/arecordmidi: Allow to pass 0 to -u option, too * new aplaymidi2/arecordmidi2 for MIDI v2.0 * aseqdump: improved UMP supports * various topology updates * aseqsend: improvement and UMP supports For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-utils ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Revert the patches related to BLS support in grub2-mkconfig, as they are not relevant to the current BLS integration and cause issues in older KIWI versions, which actively force it to be enabled by default (bsc#1233196) * 0002-Add-BLS-support-to-grub-mkconfig.patch * 0003-Add-grub2-switch-to-blscfg.patch * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch * 0008-blscfg-reading-bls-fragments-if-boot-present.patch * 0009-10_linux-Some-refinement-for-BLS.patch * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch ==== libheif ==== Version update (1.19.2 -> 1.19.3) Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openjpeg libheif-rav1e libheif-svtenc libheif1 - update to 1.19.2: * fixes a race condition that may lead to some image tiles not being included in the output image (#1379) * fix a potential crash when querying overlay image information ==== libopenmpt ==== Version update (0.7.10 -> 0.7.11) - Update to 0.7.11: * IT: Donât import SAx High Offset command for IT 1.xx modules. This feature was added in Impulse Tracker 2.00. * IT: Limit Vxx parameter to V80 for files made with old Schism Tracker versions. * IT / S3M: Impulse Tracker 2.14 patch version information was incorrect. * S3M: O00 effects are no longer ignored if the tracker version in the file header indicates Scream Tracker 3.00 / 3.01, but the file was clearly saved with another tool (e.g. UNMO3). * S3M: As files made with Scream Tracker 3.20 and 3.21 cannot be told apart, both versions are now listed in the tracker metadata. * ULT: Try to preserve global commands if thereâs e.g. both a speed and tempo command in the same cell. * STM: Improved tracker identification metadata. * SymMOD: When running out of Zxx macros, try to find the closest macro to use instead. * SymMOD: Ignore unknown hunks instead of rejecting entire file, as thatâs what Symphonie does as well. * OKT: Disable loop on type âBâ samples if theyâre used on a mixed channel. * OKT: The last sample slot was never loaded. * PTM: Halve offset command strength for 16-bit samples. ==== libsemanage ==== Subpackages: libsemanage-conf libsemanage2 - Not conflict but obsolete libsemanage1 (bsc#1229757) ==== libsoup ==== Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0 - Add 6adc0e3e.patch: websocket: Process the frame as soon as we read data (boo#1233287 CVE-2024-52532 glgo#GNOME/libsoup#391). - Add 29b96fab.patch: websocket-test: disconnect error copy after the test ends (glgo#GNOME/libsoup#391). - Add a35222dd.patch: be more robust against invalid input when parsing params (boo#1233292 CVE-2024-52531 glgo#GNOME/libsoup!407). ==== libsoup2 ==== - Add 04df03bc.patch: strictly don't allow NUL bytes in headers (boo#1233285 CVE-2024-52530 glgo#GNOME/libsoup#377). - Add libsoup-CVE-2024-52532.patch: websocket: Process the frame as soon as we read data (boo#1233287 CVE-2024-52532). - Add 29b96fab.patch: websocket-test: disconnect error copy after the test ends (glgo#GNOME/libsoup#391). - Add a35222dd.patch: be more robust against invalid input when parsing params (boo#1233292 CVE-2024-52531 glgo#GNOME/libsoup!407). ==== llvm18 ==== Subpackages: clang18 libLLVM18 libclang-cpp18 libclang_rt18 llvm18-gold - Require libffi when we build openmp for offloading. - Update llvm18.keyring from upstream. - Enable lldb on s390x and ppc64le (bsc#1232906). ==== nghttp2 ==== Version update (1.62.1 -> 1.64.0) - version update to 1.64.0 1.64.0 * Change clang-format options by @tatsuhiro-t in #2240 * build(deps): bump github.com/quic-go/quic-go from 0.46.0 to 0.47.0 by @dependabot in #2243 * build(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 by @dependabot in #2244 * nghttp2_map: Port ngtcp2 changes by @tatsuhiro-t in #2245 * h2load: Fix UDP datagram send/recv metric by @tatsuhiro-t in #2248 * build(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 by @dependabot in #2252 * fix race condition on h1 connection close by @TuxInvader in #2249 * Gha ubuntu 24.04 by @tatsuhiro-t in #2254 * GHA: Run tests for i686-w64-mingw32 host by @tatsuhiro-t in #2255 * cmake: Fix c-ares v1.34.0 version detection failure by @tatsuhiro-t in #2256 * fix: -Wextra-semi errors in nghttp2_helper.h by @codebytere in #2258 * clang-format macros that do not need semicolon at the end by @tatsuhiro-t in #2259 * Remove extra semicolons by @tatsuhiro-t in #2260 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2261 * Do not allow '@' in :authority or host field values by @tatsuhiro-t in #2262 * h2load: GRO buffer size should be 64KiB by @tatsuhiro-t in #2263 * Bump libbpf to v1.4.6 by @tatsuhiro-t in #2264 * Update nghttp2_check_authority doc by @tatsuhiro-t in #2265 1.63.0 * Bump libbpf to v1.4.2 by @tatsuhiro-t in #2191 * build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 by @dependabot in #2193 * nghttpx: Fix batch UDP QUIC packet dropped on GRO read by @tatsuhiro-t in #2196 * CMakeLists.txt: allow to compile the C only lib without CXX compiler by @ThomasDevoogdt in #2200 * build(deps): bump github.com/quic-go/quic-go from 0.43.1 to 0.44.0 by @dependabot in #2197 * Fix compiler versions in readme by @ryandesign in #2203 * build(deps): bump golang.org/x/net from 0.25.0 to 0.26.0 by @dependabot in #2205 * build(deps): bump github.com/quic-go/quic-go from 0.44.0 to 0.45.0 by @dependabot in #2206 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2207 * build(deps): bump docker/build-push-action from 5 to 6 by @dependabot in #2208 * Add wolfSSL support by @tatsuhiro-t in #2209 * Append --shallow-submodules to git clone --recursive by @tatsuhiro-t in #2210 * Always append options to extra options by @tatsuhiro-t in #2211 * build(deps): bump github.com/quic-go/quic-go from 0.45.0 to 0.45.1 by @dependabot in #2213 * Disable dependency tracking by @tatsuhiro-t in #2214 * Fix Dockerfile.android build failure by @tatsuhiro-t in #2215 * Fix UDP_GRO struct cmsghdr data type by @tatsuhiro-t in #2216 * GHA: Suppress warnings by @tatsuhiro-t in #2217 * Fix levenshtein initialization by @tatsuhiro-t in #2218 * build(deps): bump golang.org/x/net from 0.26.0 to 0.27.0 by @dependabot in #2220 * Undefine NGHTTP2_NO_SSIZE_T if BUILDING_NGHTTP2 is defined by @tatsuhiro-t in #2224 * Bump clang format by @tatsuhiro-t in #2226 * Suppress old compiler error by @tatsuhiro-t in #2228 * build(deps): bump github.com/quic-go/quic-go from 0.45.1 to 0.45.2 by @dependabot in #2229 * build(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 by @dependabot in #2231 * build(deps): bump github.com/quic-go/quic-go from 0.45.2 to 0.46.0 by @dependabot in #2232 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2236 * Bump libbpf to v1.4.5 by @tatsuhiro-t in #2237 * Update go by @tatsuhiro-t in #2238 * levenshtein: Use size_t by @tatsuhiro-t in #2239 ==== openSUSE-release ==== Version update (20241112 -> 20241113) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssl-3 ==== Subpackages: libopenssl3 - Do not use HASHBANGPERL to avoid introducing a dependency on the perl-base package. [bsc#1233235] - Add missing fixes for SHA3_squeeze and quic_multistream_test on pcc64 arch. [jsc#PED-10280] * Added openssl-3-fix-sha3-squeeze-ppc64.patch * Added openssl-3-fix-quic_multistream_test.patch ==== qt6-declarative ==== Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 libQt6LabsSharedImage6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 libQt6QuickWidgets6 qt6-declarative-imports - Replace 0001-WIP-speculative-gc-fix.patch with newer ones, should unbreak spectacle and some others (kde#496139): * 0001-Log-state-transitions-for-the-GC.patch * 0001-Engine-Mark-created-wrapped-objects-after-GCState-Ma.patch ==== schily ==== Subpackages: libcdrdeflt1_0 libdeflt1_0 libfile1_0 libfind4_0 librmt1_0 librscg1_0 libscg1_0 libscgcmd1_0 libschily2_0 mkisofs spax star - Modernize specfile ==== wget ==== Version update (1.24.5 -> 1.25.0) - GNU wget 1.25.0: * New testcase for pathconf truncation * Fix libproxy build with --disable-debug * [BREAKING CHANGE] Support continious reading from stdin pipes * Properly re-implement userinfo parsing (rfc2396) * init: fix -Warray-bounds in setval_internal_tilde * Fix build error on MingW with `G_GETFL` and `F_SETFL` flags * Fix returning uninitialized variable * Fix a static analysis false positive * [BREAKING CHANGE] Fix CVE-2024-10524 (drop support for shorthand URLs) (bsc#1233256) - Remove committed patches * properly-re-implement-userinfo-parsing.patch - Renumber patches ==== yast2-iscsi-client ==== Version update (5.0.3 -> 5.0.4) - Fixes for bsc#1231385 - Do not call iscsi_offload.sh script anymore using the iscsi ifaces created by autoLogOn directly and exposing them in the UI instead of the offload card selection. - 5.0.4