Please note that this mail was generated by a script. The described changes are computed based on the x86_64 DVD. The full online repo contains too many changes to be listed here. Please check the known defects of this snapshot before upgrading: https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=1&version=Tumbleweed&build=20241113 Please do not reply to this email to report issues, rather file a bug on bugzilla.opensuse.org. For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports Packages changed: alsa (1.2.12 -> 1.2.13) alsa-ucm-conf (1.2.12 -> 1.2.13) alsa-utils (1.2.12 -> 1.2.13) grub2 libheif (1.19.2 -> 1.19.3) libopenmpt (0.7.10 -> 0.7.11) libsemanage libsoup libsoup2 llvm18 nghttp2 (1.62.1 -> 1.64.0) openSUSE-release (20241112 -> 20241113) openssl-3 qt6-declarative schily wget (1.24.5 -> 1.25.0) yast2-iscsi-client (5.0.3 -> 5.0.4) === Details === ==== alsa ==== Version update (1.2.12 -> 1.2.13) Subpackages: libasound2 libatopology2 - Update to alsa-lib 1.2.13: * static build fixes * documentation update for control remap API * PCM dmix fixes * pcm: implement snd_pcm_hw_params_get_sync() and obsolete snd_pcm_info_get_sync() * ump: Add a function to provide the packet word length of a UMP type * seq: Add snd_seq_{get|set}_ump_is_midi1() API functions * seq: Add API functions to set different tempo base values * seq: Add API helper functions for creating UMP Endpoint and Blocks * documentation fixes for UMP and sequencer API * test: Add an example programs for UMP For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-lib - Conditionally take libtool ==== alsa-ucm-conf ==== Version update (1.2.12 -> 1.2.13) - Update to version 1.2.13: * Updates for USB-audio, Mediatek, Qualcomm, ACP, SoundWire, wsa884x, wcd938x, Intel AVS, SOF HDA, etc For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-ucm-conf ==== alsa-utils ==== Version update (1.2.12 -> 1.2.13) - Update to alsa-utils 1.2.13: * alsactl: add support for AMD ACP digital microphone * aplay: Print '=== PAUSE ===' only if it is supported * aplaymidi/arecordmidi: Allow to pass 0 to -u option, too * new aplaymidi2/arecordmidi2 for MIDI v2.0 * aseqdump: improved UMP supports * various topology updates * aseqsend: improvement and UMP supports For details, see: https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-utils ==== grub2 ==== Subpackages: grub2-common grub2-i386-pc grub2-snapper-plugin grub2-systemd-sleep-plugin grub2-x86_64-efi grub2-x86_64-xen - Revert the patches related to BLS support in grub2-mkconfig, as they are not relevant to the current BLS integration and cause issues in older KIWI versions, which actively force it to be enabled by default (bsc#1233196) * 0002-Add-BLS-support-to-grub-mkconfig.patch * 0003-Add-grub2-switch-to-blscfg.patch * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch * 0008-blscfg-reading-bls-fragments-if-boot-present.patch * 0009-10_linux-Some-refinement-for-BLS.patch * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch ==== libheif ==== Version update (1.19.2 -> 1.19.3) Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openjpeg libheif-rav1e libheif-svtenc libheif1 - update to 1.19.2: * fixes a race condition that may lead to some image tiles not being included in the output image (#1379) * fix a potential crash when querying overlay image information ==== libopenmpt ==== Version update (0.7.10 -> 0.7.11) - Update to 0.7.11: * IT: Donât import SAx High Offset command for IT 1.xx modules. This feature was added in Impulse Tracker 2.00. * IT: Limit Vxx parameter to V80 for files made with old Schism Tracker versions. * IT / S3M: Impulse Tracker 2.14 patch version information was incorrect. * S3M: O00 effects are no longer ignored if the tracker version in the file header indicates Scream Tracker 3.00 / 3.01, but the file was clearly saved with another tool (e.g. UNMO3). * S3M: As files made with Scream Tracker 3.20 and 3.21 cannot be told apart, both versions are now listed in the tracker metadata. * ULT: Try to preserve global commands if thereâs e.g. both a speed and tempo command in the same cell. * STM: Improved tracker identification metadata. * SymMOD: When running out of Zxx macros, try to find the closest macro to use instead. * SymMOD: Ignore unknown hunks instead of rejecting entire file, as thatâs what Symphonie does as well. * OKT: Disable loop on type âBâ samples if theyâre used on a mixed channel. * OKT: The last sample slot was never loaded. * PTM: Halve offset command strength for 16-bit samples. ==== libsemanage ==== Subpackages: libsemanage-conf libsemanage2 - Not conflict but obsolete libsemanage1 (bsc#1229757) ==== libsoup ==== Subpackages: libsoup-3_0-0 libsoup-lang typelib-1_0-Soup-3_0 - Add 6adc0e3e.patch: websocket: Process the frame as soon as we read data (boo#1233287 CVE-2024-52532 glgo#GNOME/libsoup#391). - Add 29b96fab.patch: websocket-test: disconnect error copy after the test ends (glgo#GNOME/libsoup#391). - Add a35222dd.patch: be more robust against invalid input when parsing params (boo#1233292 CVE-2024-52531 glgo#GNOME/libsoup!407). ==== libsoup2 ==== Subpackages: libsoup-2_4-1 libsoup2-lang - Add 04df03bc.patch: strictly don't allow NUL bytes in headers (boo#1233285 CVE-2024-52530 glgo#GNOME/libsoup#377). - Add libsoup-CVE-2024-52532.patch: websocket: Process the frame as soon as we read data (boo#1233287 CVE-2024-52532). - Add 29b96fab.patch: websocket-test: disconnect error copy after the test ends (glgo#GNOME/libsoup#391). - Add a35222dd.patch: be more robust against invalid input when parsing params (boo#1233292 CVE-2024-52531 glgo#GNOME/libsoup!407). ==== llvm18 ==== Subpackages: clang18 libLLVM18 libclang-cpp18 libclang_rt18 llvm18-gold - Require libffi when we build openmp for offloading. - Update llvm18.keyring from upstream. - Enable lldb on s390x and ppc64le (bsc#1232906). ==== nghttp2 ==== Version update (1.62.1 -> 1.64.0) - version update to 1.64.0 1.64.0 * Change clang-format options by @tatsuhiro-t in #2240 * build(deps): bump github.com/quic-go/quic-go from 0.46.0 to 0.47.0 by @dependabot in #2243 * build(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 by @dependabot in #2244 * nghttp2_map: Port ngtcp2 changes by @tatsuhiro-t in #2245 * h2load: Fix UDP datagram send/recv metric by @tatsuhiro-t in #2248 * build(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 by @dependabot in #2252 * fix race condition on h1 connection close by @TuxInvader in #2249 * Gha ubuntu 24.04 by @tatsuhiro-t in #2254 * GHA: Run tests for i686-w64-mingw32 host by @tatsuhiro-t in #2255 * cmake: Fix c-ares v1.34.0 version detection failure by @tatsuhiro-t in #2256 * fix: -Wextra-semi errors in nghttp2_helper.h by @codebytere in #2258 * clang-format macros that do not need semicolon at the end by @tatsuhiro-t in #2259 * Remove extra semicolons by @tatsuhiro-t in #2260 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2261 * Do not allow '@' in :authority or host field values by @tatsuhiro-t in #2262 * h2load: GRO buffer size should be 64KiB by @tatsuhiro-t in #2263 * Bump libbpf to v1.4.6 by @tatsuhiro-t in #2264 * Update nghttp2_check_authority doc by @tatsuhiro-t in #2265 1.63.0 * Bump libbpf to v1.4.2 by @tatsuhiro-t in #2191 * build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 by @dependabot in #2193 * nghttpx: Fix batch UDP QUIC packet dropped on GRO read by @tatsuhiro-t in #2196 * CMakeLists.txt: allow to compile the C only lib without CXX compiler by @ThomasDevoogdt in #2200 * build(deps): bump github.com/quic-go/quic-go from 0.43.1 to 0.44.0 by @dependabot in #2197 * Fix compiler versions in readme by @ryandesign in #2203 * build(deps): bump golang.org/x/net from 0.25.0 to 0.26.0 by @dependabot in #2205 * build(deps): bump github.com/quic-go/quic-go from 0.44.0 to 0.45.0 by @dependabot in #2206 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2207 * build(deps): bump docker/build-push-action from 5 to 6 by @dependabot in #2208 * Add wolfSSL support by @tatsuhiro-t in #2209 * Append --shallow-submodules to git clone --recursive by @tatsuhiro-t in #2210 * Always append options to extra options by @tatsuhiro-t in #2211 * build(deps): bump github.com/quic-go/quic-go from 0.45.0 to 0.45.1 by @dependabot in #2213 * Disable dependency tracking by @tatsuhiro-t in #2214 * Fix Dockerfile.android build failure by @tatsuhiro-t in #2215 * Fix UDP_GRO struct cmsghdr data type by @tatsuhiro-t in #2216 * GHA: Suppress warnings by @tatsuhiro-t in #2217 * Fix levenshtein initialization by @tatsuhiro-t in #2218 * build(deps): bump golang.org/x/net from 0.26.0 to 0.27.0 by @dependabot in #2220 * Undefine NGHTTP2_NO_SSIZE_T if BUILDING_NGHTTP2 is defined by @tatsuhiro-t in #2224 * Bump clang format by @tatsuhiro-t in #2226 * Suppress old compiler error by @tatsuhiro-t in #2228 * build(deps): bump github.com/quic-go/quic-go from 0.45.1 to 0.45.2 by @dependabot in #2229 * build(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 by @dependabot in #2231 * build(deps): bump github.com/quic-go/quic-go from 0.45.2 to 0.46.0 by @dependabot in #2232 * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2236 * Bump libbpf to v1.4.5 by @tatsuhiro-t in #2237 * Update go by @tatsuhiro-t in #2238 * levenshtein: Use size_t by @tatsuhiro-t in #2239 ==== openSUSE-release ==== Version update (20241112 -> 20241113) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssl-3 ==== Subpackages: libopenssl3 libopenssl3-32bit libopenssl3-x86-64-v3 - Do not use HASHBANGPERL to avoid introducing a dependency on the perl-base package. [bsc#1233235] - Add missing fixes for SHA3_squeeze and quic_multistream_test on pcc64 arch. [jsc#PED-10280] * Added openssl-3-fix-sha3-squeeze-ppc64.patch * Added openssl-3-fix-quic_multistream_test.patch ==== qt6-declarative ==== Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 libQt6LabsSharedImage6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 libQt6QuickWidgets6 qt6-declarative-imports - Replace 0001-WIP-speculative-gc-fix.patch with newer ones, should unbreak spectacle and some others (kde#496139): * 0001-Log-state-transitions-for-the-GC.patch * 0001-Engine-Mark-created-wrapped-objects-after-GCState-Ma.patch ==== schily ==== Subpackages: libcdrdeflt1_0 libdeflt1_0 libfile1_0 libfind4_0 librmt1_0 librscg1_0 libscg1_0 libscgcmd1_0 libschily2_0 mkisofs spax star - Modernize specfile ==== wget ==== Version update (1.24.5 -> 1.25.0) Subpackages: wget-lang - GNU wget 1.25.0: * New testcase for pathconf truncation * Fix libproxy build with --disable-debug * [BREAKING CHANGE] Support continious reading from stdin pipes * Properly re-implement userinfo parsing (rfc2396) * init: fix -Warray-bounds in setval_internal_tilde * Fix build error on MingW with `G_GETFL` and `F_SETFL` flags * Fix returning uninitialized variable * Fix a static analysis false positive * [BREAKING CHANGE] Fix CVE-2024-10524 (drop support for shorthand URLs) (bsc#1233256) - Remove committed patches * properly-re-implement-userinfo-parsing.patch - Renumber patches ==== yast2-iscsi-client ==== Version update (5.0.3 -> 5.0.4) - Fixes for bsc#1231385 - Do not call iscsi_offload.sh script anymore using the iscsi ifaces created by autoLogOn directly and exposing them in the UI instead of the offload card selection. - 5.0.4