openSUSE Kubic
Threads by month
- ----- 2025 -----
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
June 2019
- 2 participants
- 18 discussions
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
vim (8.1.1561 -> 8.1.1600)
=== Details ===
==== vim ====
Version update (8.1.1561 -> 8.1.1600)
Subpackages: vim-data-common
- Updated to version 8.1.1600, fixes the following problems
* Popup_setoptions() is not implemented yet.
* Popup window not always redrawn after popup_setoptions().
* Crash when using closures.
* Sign column takes up space. (Adam Stankiewicz)
* Error message when terminal closes while it is not in the current tab.
* Localtime_r() does not respond to $TZ changes.
* Cannot build with signs but without diff feature.
* Icon signs not displayed properly in the number column.
* textprop highlight starts too early if just after a tab.
* Compiler warnings with tiny build. (Tony Mechelynck)
* Textprop test fails if screenhots do not work.
* Tabpage option not yet implemented for popup window.
* Compiler warning for unused argument.
* Command line redrawn for +arabic without Arabic characters. (Dominique
Pelle)
* Dict and list could be GC'ed while displaying error in a timer. (Yasuhiro
Matsumoto)
* Cannot make part of a popup transparent.
* Shared functions for testing are disorganised.
* Cannot build with +textprop but without +timers.
* Set_ref_in_list() only sets ref in items.
* The evalfunc.c file is getting too big.
* :let-heredoc does not trim enough.
* Error number used in two places.
* Redraw problem when sign icons in the number column.
* In :let-heredoc line continuation is recognized.
* Popup window does not indicate scroll position.
* Popup window test fails.
* On error garbage collection may free memory in use.
* May start file dialog while exiting.
* Filetype not detected for C++ header files without extension.
* May still start file dialog while exiting.
* When resizing the screen may draw popup in wrong position. (Masato
Nishihata)
* Cannot scroll a popup window with the mouse.
* Update to test file missing.
* Compiler warning for uninitialized variable. (Tony Mechelynck)
* Cannot specify highlighting for popup window scrollbar.
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
kubic-control (0.6.1 -> 0.6.2)
vim (8.1.1561 -> 8.1.1600)
=== Details ===
==== kubic-control ====
Version update (0.6.1 -> 0.6.2)
Subpackages: kubicctl kubicd
- Update to version 0.6.2
- New function: destroy whole cluster
- Remove Nodes: allow to specify multiple nodes or '*' for all nodes
- Fix timeout option for draining nodes
==== vim ====
Version update (8.1.1561 -> 8.1.1600)
Subpackages: vim-data-common
- Updated to version 8.1.1600, fixes the following problems
* Popup_setoptions() is not implemented yet.
* Popup window not always redrawn after popup_setoptions().
* Crash when using closures.
* Sign column takes up space. (Adam Stankiewicz)
* Error message when terminal closes while it is not in the current tab.
* Localtime_r() does not respond to $TZ changes.
* Cannot build with signs but without diff feature.
* Icon signs not displayed properly in the number column.
* textprop highlight starts too early if just after a tab.
* Compiler warnings with tiny build. (Tony Mechelynck)
* Textprop test fails if screenhots do not work.
* Tabpage option not yet implemented for popup window.
* Compiler warning for unused argument.
* Command line redrawn for +arabic without Arabic characters. (Dominique
Pelle)
* Dict and list could be GC'ed while displaying error in a timer. (Yasuhiro
Matsumoto)
* Cannot make part of a popup transparent.
* Shared functions for testing are disorganised.
* Cannot build with +textprop but without +timers.
* Set_ref_in_list() only sets ref in items.
* The evalfunc.c file is getting too big.
* :let-heredoc does not trim enough.
* Error number used in two places.
* Redraw problem when sign icons in the number column.
* In :let-heredoc line continuation is recognized.
* Popup window does not indicate scroll position.
* Popup window test fails.
* On error garbage collection may free memory in use.
* May start file dialog while exiting.
* Filetype not detected for C++ header files without extension.
* May still start file dialog while exiting.
* When resizing the screen may draw popup in wrong position. (Masato
Nishihata)
* Cannot scroll a popup window with the mouse.
* Update to test file missing.
* Compiler warning for uninitialized variable. (Tony Mechelynck)
* Cannot specify highlighting for popup window scrollbar.
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
gpg2
kdump
mcstrans
multipath-tools (0.8.1+8+suse.8c11498 -> 0.8.1+28+suse.fea562a)
python-py
sssd (2.1.0 -> 2.2.0)
=== Details ===
==== gpg2 ====
- Fix secure memory being disabled before fips checks in libgcrypt [boo#1137307]
* Added gnupg-2.2.16-secmem.patch
==== kdump ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== mcstrans ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== multipath-tools ====
Version update (0.8.1+8+suse.8c11498 -> 0.8.1+28+suse.fea562a)
Subpackages: kpartx libmpath0
- Update to version 0.8.1+28+suse.fea562a:
* mpathpersist: optimize for setups with many LUNs (bsc#1134648)
* mpathpersist: add option -f/--batch-file (bsc#1134648)
* libmultipath: get_prio(): really don't reset prio for
inaccessible paths (bsc#1118495)
- Upstream bug fixes from dm-devel (bsc#1139369):
* multipath: call store_pathinfo with DI_BLACKLIST
* multipathd: fix REALLOC_REPLY with max length reply
* libmultipath: make vector_foreach_slot_backwards work as expected
* multipathd: fix client response for socket activation
* various minor fixes (coverity)
==== python-py ====
- Switch to multibuild to avoid cycle bsc#1138666
==== sssd ====
Version update (2.1.0 -> 2.2.0)
Subpackages: libsss_certmap0 libsss_idmap0 libsss_nss_idmap0 sssd-krb5-common sssd-ldap
- Update to new upstream release 2.2.0
* The Kerberos provider can now include more KDC addresses or
host names when writing data for the Kerberos locator plugin.
* The 2FA prompting can now be configured.
* The LDAP authentication provider now allows to use a
different method of changing LDAP passwords using a modify
operation in addition to the default extended operation.
* The "auto_private_groups" configuration option now takes a
new value hybrid.
* A new option "ad_gpo_ignore_unreadable" was added.
* The "cached_auth_timeout" parameter is now inherited by
trusted domains.
* The "ldap_sasl_mech" option now accepts another mechanism
"GSS-SPNEGO" in addition to "GSSAPI".
* The sssctl tool has two new commands, "cert-show" and
"cert-map".
- Create directory to download and cache GPOs (bsc#1132879)
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
autofs
flannel
gpg2
kdump
mcstrans
multipath-tools (0.8.1+8+suse.8c11498 -> 0.8.1+28+suse.fea562a)
python-py
sssd (2.1.0 -> 2.2.0)
=== Details ===
==== autofs ====
- BuildRequire pkgconfig(libsystemd) instead of systemd-devel:
allow OBS to shortcut by using systemd-devel-mini.
==== flannel ====
- Add missing words in descriptions.
==== gpg2 ====
- Fix secure memory being disabled before fips checks in libgcrypt [boo#1137307]
* Added gnupg-2.2.16-secmem.patch
==== kdump ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== mcstrans ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== multipath-tools ====
Version update (0.8.1+8+suse.8c11498 -> 0.8.1+28+suse.fea562a)
Subpackages: kpartx libmpath0
- Update to version 0.8.1+28+suse.fea562a:
* mpathpersist: optimize for setups with many LUNs (bsc#1134648)
* mpathpersist: add option -f/--batch-file (bsc#1134648)
* libmultipath: get_prio(): really don't reset prio for
inaccessible paths (bsc#1118495)
- Upstream bug fixes from dm-devel (bsc#1139369):
* multipath: call store_pathinfo with DI_BLACKLIST
* multipathd: fix REALLOC_REPLY with max length reply
* libmultipath: make vector_foreach_slot_backwards work as expected
* multipathd: fix client response for socket activation
* various minor fixes (coverity)
==== python-py ====
- Switch to multibuild to avoid cycle bsc#1138666
==== sssd ====
Version update (2.1.0 -> 2.2.0)
Subpackages: libsss_certmap0 libsss_idmap0 libsss_nss_idmap0 sssd-krb5-common sssd-ldap
- Update to new upstream release 2.2.0
* The Kerberos provider can now include more KDC addresses or
host names when writing data for the Kerberos locator plugin.
* The 2FA prompting can now be configured.
* The LDAP authentication provider now allows to use a
different method of changing LDAP passwords using a modify
operation in addition to the default extended operation.
* The "auto_private_groups" configuration option now takes a
new value hybrid.
* A new option "ad_gpo_ignore_unreadable" was added.
* The "cached_auth_timeout" parameter is now inherited by
trusted domains.
* The "ldap_sasl_mech" option now accepts another mechanism
"GSS-SPNEGO" in addition to "GSSAPI".
* The sssctl tool has two new commands, "cert-show" and
"cert-map".
- Create directory to download and cache GPOs (bsc#1132879)
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
audit
audit-secondary
btrfsmaintenance
cloud-init (18.5 -> 19.1)
ding-libs
filesystem
gcc9 (9.1.1+r271393 -> 9.1.1+r272147)
glib-networking (2.60.2 -> 2.60.3)
glib2 (2.60.3 -> 2.60.4)
growpart
hwdata (0.323 -> 0.324)
kernel-firmware (20190514 -> 20190618)
kernel-source (5.1.7 -> 5.1.10)
libcontainers-common
libseccomp (2.4.0 -> 2.4.1)
libsolv (0.7.4 -> 0.7.5)
libzypp (17.11.4 -> 17.12.0)
microos-tools (1.0+git20190218.9e72dd7 -> 1.0+git20190611.6211f74)
ncurses
permissions (1550_20190429 -> 1550_20190521)
python-base
systemd-presets-common-SUSE
sysvinit (2.90 -> 2.95)
zlib
zypper (1.14.27 -> 1.14.28)
=== Details ===
==== audit ====
Subpackages: libaudit1 libauparse0
- Make use of some %make_install.
==== audit-secondary ====
Subpackages: audit python3-audit
- Reduce scriptlets' hard dependency on systemd.
==== btrfsmaintenance ====
- spec: fix typo in macro name
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== cloud-init ====
Version update (18.5 -> 19.1)
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
- Update to version 19.1 (bsc#1136440)
+ Remove, included upstream
- fix-default-systemd-unit-dir.patch
- cloud-init-sysconf-ethsetup.patch
- cloud-init-handle-def-route-set.patch
- cloud-init-no-empty-resolv.patch
- cloud-init-proper-ipv6-varname.patch
+ Forward port
- cloud-init-trigger-udev.patch
+ Add cloud-init-detect-nova.diff (bsc#1136440)
+ Modify cloud-init-python2-sigpipe.patch, import signal and constants
+ Update spec to account for new location of bash completion
+ freebsd: add chpasswd pkg in the image [Gonéri Le Bouder]
+ tests: add Eoan release [Paride Legovini]
+ cc_mounts: check if mount -a on no-change fstab path
[Jason Zions (MSFT)] (LP: #1825596)
+ replace remaining occurrences of LOG.warn [Daniel Watkins]
+ DataSourceAzure: Adjust timeout for polling IMDS [Anh Vo]
+ Azure: Changes to the Hyper-V KVP Reporter [Anh Vo]
+ git tests: no longer show warning about safe yaml.
+ tools/read-version: handle errors [Chad Miller]
+ net/sysconfig: only indicate available on known sysconfig distros
(LP: #1819994)
+ packages: update rpm specs for new bash completion path
[Daniel Watkins] (LP: #1825444)
+ test_azure: mock util.SeLinuxGuard where needed
[Jason Zions (MSFT)] (LP: #1825253)
+ setup.py: install bash completion script in new location [Daniel Watkins]
+ mount_cb: do not pass sync and rw options to mount
[Gonéri Le Bouder] (LP: #1645824)
+ cc_apt_configure: fix typo in apt documentation [Dominic Schlegel]
+ Revert "DataSource: move update_events from a class to an instance..."
[Daniel Watkins]
+ Change DataSourceNoCloud to ignore file system label's case.
[Risto Oikarinen]
+ cmd:main.py: Fix missing 'modules-init' key in modes dict
[Antonio Romito] (LP: #1815109)
+ ubuntu_advantage: rewrite cloud-config module
+ Azure: Treat _unset network configuration as if it were absent
[Jason Zions (MSFT)] (LP: #1823084)
+ DatasourceAzure: add additional logging for azure datasource [Anh Vo]
+ cloud_tests: fix apt_pipelining test-cases
+ Azure: Ensure platform random_seed is always serializable as JSON.
[Jason Zions (MSFT)]
+ net/sysconfig: write out SUSE-compatible IPv6 config [Robert Schweikert]
+ tox: Update testenv for openSUSE Leap to 15.0 [Thomas Bechtold]
+ net: Fix ipv6 static routes when using eni renderer
[Raphael Glon] (LP: #1818669)
+ Add ubuntu_drivers config module [Daniel Watkins]
+ doc: Refresh Azure walinuxagent docs [Daniel Watkins]
+ tox: bump pylint version to latest (2.3.1) [Daniel Watkins]
+ DataSource: move update_events from a class to an instance attribute
[Daniel Watkins] (LP: #1819913)
+ net/sysconfig: Handle default route setup for dhcp configured NICs
[Robert Schweikert] (LP: #1812117)
+ DataSourceEc2: update RELEASE_BLOCKER to be more accurate
[Daniel Watkins]
+ cloud-init-per: POSIX sh does not support string subst, use sed
(LP: #1819222)
+ Support locking user with usermod if passwd is not available.
+ Example for Microsoft Azure data disk added. [Anton Olifir]
+ clean: correctly determine the path for excluding seed directory
[Daniel Watkins] (LP: #1818571)
+ helpers/openstack: Treat unknown link types as physical
[Daniel Watkins] (LP: #1639263)
+ drop Python 2.6 support and our NIH version detection [Daniel Watkins]
+ tip-pylint: Fix assignment-from-return-none errors
+ net: append type:dhcp[46] only if dhcp[46] is True in v2 netconfig
[Kurt Stieger] (LP: #1818032)
+ cc_apt_pipelining: stop disabling pipelining by default
[Daniel Watkins] (LP: #1794982)
+ tests: fix some slow tests and some leaking state [Daniel Watkins]
+ util: don't determine string_types ourselves [Daniel Watkins]
+ cc_rsyslog: Escape possible nested set [Daniel Watkins] (LP: #1816967)
+ Enable encrypted_data_bag_secret support for Chef
[Eric Williams] (LP: #1817082)
+ azure: Filter list of ssh keys pulled from fabric [Jason Zions (MSFT)]
+ doc: update merging doc with fixes and some additional details/examples
+ tests: integration test failure summary to use traceback if empty error
+ This is to fix https://bugs.launchpad.net/cloud-init/+bug/1812676
[Vitaly Kuznetsov]
+ EC2: Rewrite network config on AWS Classic instances every boot
[Guilherme G. Piccoli] (LP: #1802073)
+ netinfo: Adjust ifconfig output parsing for FreeBSD ipv6 entries
(LP: #1779672)
+ netplan: Don't render yaml aliases when dumping netplan (LP: #1815051)
+ add PyCharm IDE .idea/ path to .gitignore [Dominic Schlegel]
+ correct grammar issue in instance metadata documentation
[Dominic Schlegel] (LP: #1802188)
+ clean: cloud-init clean should not trace when run from within cloud_dir
(LP: #1795508)
+ Resolve flake8 comparison and pycodestyle over-ident issues
[Paride Legovini]
+ opennebula: also exclude epochseconds from changed environment vars
(LP: #1813641)
+ systemd: Render generator from template to account for system
differences. [Robert Schweikert]
+ sysconfig: On SUSE, use STARTMODE instead of ONBOOT
[Robert Schweikert] (LP: #1799540)
+ flake8: use ==/!= to compare str, bytes, and int literals
[Paride Legovini]
+ opennebula: exclude EPOCHREALTIME as known bash env variable with a
delta (LP: #1813383)
+ tox: fix disco httpretty dependencies for py37 (LP: #1813361)
+ run-container: uncomment baseurl in yum.repos.d/*.repo when using a
proxy [Paride Legovini]
+ lxd: install zfs-linux instead of zfs meta package
[Johnson Shi] (LP: #1799779)
+ net/sysconfig: do not write a resolv.conf file with only the header.
[Robert Schweikert]
+ net: Make sysconfig renderer compatible with Network Manager.
[Eduardo Otubo]
+ cc_set_passwords: Fix regex when parsing hashed passwords
[Marlin Cremers] (LP: #1811446)
+ net: Wait for dhclient to daemonize before reading lease file
[Jason Zions] (LP: #1794399)
+ [Azure] Increase retries when talking to Wireserver during metadata walk
[Jason Zions]
+ Add documentation on adding a datasource.
+ doc: clean up some datasource documentation.
+ ds-identify: fix wrong variable name in ovf_vmware_transport_guestinfo.
+ Scaleway: Support ssh keys provided inside an instance tag. [PORTE Loïc]
+ OVF: simplify expected return values of transport functions.
+ Vmware: Add support for the com.vmware.guestInfo OVF transport.
(LP: #1807466)
+ HACKING.rst: change contact info to Josh Powers
+ Update to pylint 2.2.2.
==== ding-libs ====
Subpackages: libbasicobjects0 libcollection4 libdhash1 libini_config5 libpath_utils1 libref_array1
- Add patch fixing errors writeout to stdout:
* INI-Remove-definiton-of-TRACE_LEVEL.patch
==== filesystem ====
- Re-add /var/cache and /var/log (revert [bsc#1078466] because of
[bsc#1078466])
- Fix permission of fs-var.conf
==== gcc9 ====
Version update (9.1.1+r271393 -> 9.1.1+r272147)
Subpackages: libgcc_s1 libstdc++6
- Update to gcc-9-branch head (r272147).
* Pulls fix for random debug info differences when compiling D code.
[gcc#90778]
- Update to gcc-9-branch head (r271995).
* installs workaround for broken lapack C interfaces
- Drop gcc9-spectrev1.patch, add gcc9-reproducible-builds.patch
and gcc9-reproducible-builds-buildid-for-checksum.patch moving
reproducible build improvements over from GCC 8 package.
- Split out libstdc++ pretty-printers into a separate package
supplementing gdb and the installed runtime. [bsc#1135254]
- Update to gcc-9-branch head (r271643).
==== glib-networking ====
Version update (2.60.2 -> 2.60.3)
- Update to version 2.60.3:
+ Fix clobbering of the thread-default main context after
certificate verification failure during async handshakes since
2.60.1.
+ Fix GTlsDatabase initialization failures in OpenSSL backend due
to uninitialized memory use.
+ Fix minor leak of ALPN protocols.
==== glib2 ====
Version update (2.60.3 -> 2.60.4)
Subpackages: glib2-tools libgio-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0
- Update to version 2.60.4:
+ Fixes to improved network status detection with NetworkManager.
+ Leak fixes to some `glib-genmarshal` generated code.
+ Further fixes to the Happy Eyeballs (RFC 8305) implementation.
+ File system permissions fix to clamp down permissions in a
small time window when copying files (CVE-2019-12450).
+ Bugs fixed: glgo#GNOME/GLib#1755, glgo#GNOME/GLib#1788,
glgo#GNOME/GLib#1792, glgo#GNOME/GLib#1793,
glgo#GNOME/GLib#1795, glgo#GNOME/GLib!865, glgo#GNOME/GLib!878.
==== growpart ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== hwdata ====
Version update (0.323 -> 0.324)
- Update to version 0.324:
* Updated pci, usb and vendor ids.
==== kernel-firmware ====
Version update (20190514 -> 20190618)
Subpackages: ucode-amd
- Update to version 20190618:
* cavium: Add firmware for CNN55XX crypto driver.
* linux-firmware: Update firmware file for Intel Bluetooth 22161
* linux-firmware: Update firmware file for Intel Bluetooth 9560
* linux-firmware: Update firmware file for Intel Bluetooth 9260
* linux-firmware: Update AMD SEV firmware
* linux-firmware: update licence text for Marvell firmware
- Update to version 20190607:
* linux-firmware: update firmware for mhdp8546
* linux-firmware: rsi: update firmware images for Redpine 9113 chipset
* imx: sdma: update firmware to v3.5/v4.5
* nvidia: update GP10[2467] SEC2 RTOS with the one already used on GP108
==== kernel-source ====
Version update (5.1.7 -> 5.1.10)
Subpackages: kernel-debug kernel-default
- move patches from .fixes to .suse
There is no patches.fixes in stable.
- commit ad24342
- tcp: enforce tcp_min_snd_mss in tcp_mtu_probing() (bsc#1137586
CVE-2019-11479).
- tcp: add tcp_min_snd_mss sysctl (bsc#1137586 CVE-2019-11479).
- tcp: tcp_fragment() should apply sane memory limits (bsc#1137586
CVE-2019-11478).
- tcp: limit payload size of sacked skbs (bsc#1137586
CVE-2019-11477).
- commit a5ec6d9
- Linux 5.1.10 (bnc#1012628).
- media: rockchip/vpu: Fix/re-order probe-error/remove path
(bnc#1012628).
- media: rockchip/vpu: Add missing dont_use_autosuspend() calls
(bnc#1012628).
- rapidio: fix a NULL pointer dereference when create_workqueue()
fails (bnc#1012628).
- fs/fat/file.c: issue flush after the writeback of FAT
(bnc#1012628).
- sysctl: return -EINVAL if val violates minmax (bnc#1012628).
- ipc: prevent lockup on alloc_msg and free_msg (bnc#1012628).
- drm/msm: correct attempted NULL pointer dereference in debugfs
(bnc#1012628).
- drm/pl111: Initialize clock spinlock early (bnc#1012628).
- mm/mprotect.c: fix compilation warning because of unused 'mm'
variable (bnc#1012628).
- ARM: prevent tracing IPI_CPU_BACKTRACE (bnc#1012628).
- mm/hmm: select mmu notifier when selecting HMM (bnc#1012628).
- hugetlbfs: on restore reserve error path retain subpool
reservation (bnc#1012628).
- mm/memory_hotplug: release memory resource after
arch_remove_memory() (bnc#1012628).
- mem-hotplug: fix node spanned pages when we have a node with
only ZONE_MOVABLE (bnc#1012628).
- mm/cma.c: fix crash on CMA allocation if bitmap allocation fails
(bnc#1012628).
- initramfs: free initrd memory if opening /initrd.image fails
(bnc#1012628).
- mm/compaction.c: fix an undefined behaviour (bnc#1012628).
- mm/memory_hotplug.c: fix the wrong usage of N_HIGH_MEMORY
(bnc#1012628).
- mm/cma.c: fix the bitmap status to show failed allocation reason
(bnc#1012628).
- mm: page_mkclean vs MADV_DONTNEED race (bnc#1012628).
- mm/cma_debug.c: fix the break condition in cma_maxchunk_get()
(bnc#1012628).
- mm/slab.c: fix an infinite loop in leaks_show() (bnc#1012628).
- kernel/sys.c: prctl: fix false positive in validate_prctl_map()
(bnc#1012628).
- thermal: rcar_gen3_thermal: disable interrupt in .remove
(bnc#1012628).
- drivers: thermal: tsens: Don't print error message on
- EPROBE_DEFER (bnc#1012628).
- mfd: tps65912-spi: Add missing of table registration
(bnc#1012628).
- mfd: intel-lpss: Set the device in reset state when init
(bnc#1012628).
- drm/nouveau/disp/dp: respect sink limits when selecting failsafe
link configuration (bnc#1012628).
- mfd: twl6040: Fix device init errors for ACCCTL register
(bnc#1012628).
- perf/x86/intel: Allow PEBS multi-entry in watermark mode
(bnc#1012628).
- drm/nouveau/kms/gf119-gp10x: push HeadSetControlOutputResource()
mthd when encoders change (bnc#1012628).
- drm/nouveau: fix duplication of nv50_head_atom struct
(bnc#1012628).
- drm/bridge: adv7511: Fix low refresh rate selection
(bnc#1012628).
- objtool: Don't use ignore flag for fake jumps (bnc#1012628).
- drm/nouveau/kms/gv100-: fix spurious window immediate interlocks
(bnc#1012628).
- bpf: fix undefined behavior in narrow load handling
(bnc#1012628).
- EDAC/mpc85xx: Prevent building as a module (bnc#1012628).
- pwm: meson: Use the spin-lock only to protect register
modifications (bnc#1012628).
- mailbox: stm32-ipcc: check invalid irq (bnc#1012628).
- ntp: Allow TAI-UTC offset to be set to zero (bnc#1012628).
- f2fs: fix to avoid panic in do_recover_data() (bnc#1012628).
- f2fs: fix to avoid panic in f2fs_inplace_write_data()
(bnc#1012628).
- f2fs: fix error path of recovery (bnc#1012628).
- f2fs: fix to avoid panic in f2fs_remove_inode_page()
(bnc#1012628).
- f2fs: fix to do sanity check on free nid (bnc#1012628).
- f2fs: fix to clear dirty inode in error path of f2fs_iget()
(bnc#1012628).
- f2fs: fix to avoid panic in dec_valid_block_count()
(bnc#1012628).
- f2fs: fix to use inline space only if inline_xattr is enable
(bnc#1012628).
- f2fs: fix to avoid panic in dec_valid_node_count()
(bnc#1012628).
- f2fs: fix to do sanity check on valid block count of segment
(bnc#1012628).
- f2fs: fix to avoid deadloop in foreground GC (bnc#1012628).
- f2fs: fix to retrieve inline xattr space (bnc#1012628).
- f2fs: fix to do checksum even if inode page is uptodate
(bnc#1012628).
- media: atmel: atmel-isc: fix asd memory allocation
(bnc#1012628).
- percpu: remove spurious lock dependency between percpu and sched
(bnc#1012628).
- configfs: fix possible use-after-free in configfs_register_group
(bnc#1012628).
- uml: fix a boot splat wrt use of cpu_all_mask (bnc#1012628).
- PCI: dwc: Free MSI in dw_pcie_host_init() error path
(bnc#1012628).
- PCI: dwc: Free MSI IRQ page in dw_pcie_free_msi() (bnc#1012628).
- fbcon: Don't reset logo_shown when logo is currently shown
(bnc#1012628).
- ovl: do not generate duplicate fsnotify events for "fake" path
(bnc#1012628).
- mmc: mmci: Prevent polling for busy detection in IRQ context
(bnc#1012628).
- netfilter: nf_flow_table: fix missing error check for
rhashtable_insert_fast (bnc#1012628).
- netfilter: nf_conntrack_h323: restore boundary check correctness
(bnc#1012628).
- mips: Make sure dt memory regions are valid (bnc#1012628).
- netfilter: nf_tables: fix base chain stat rcu_dereference usage
(bnc#1012628).
- watchdog: imx2_wdt: Fix set_timeout for big timeout values
(bnc#1012628).
- watchdog: fix compile time error of pretimeout governors
(bnc#1012628).
- blk-mq: move cancel of requeue_work into blk_mq_release
(bnc#1012628).
- iommu/vt-d: Set intel_iommu_gfx_mapped correctly (bnc#1012628).
- vfio-pci/nvlink2: Fix potential VMA leak (bnc#1012628).
- misc: pci_endpoint_test: Fix test_reg_bar to be updated in
pci_endpoint_test (bnc#1012628).
- PCI: designware-ep: Use aligned ATU window for raising MSI
interrupts (bnc#1012628).
- nvme-pci: unquiesce admin queue on shutdown (bnc#1012628).
- nvme-pci: shutdown on timeout during deletion (bnc#1012628).
- netfilter: nf_flow_table: check ttl value in flow offload data
path (bnc#1012628).
- netfilter: nf_flow_table: fix netdev refcnt leak (bnc#1012628).
- ALSA: hda - Register irq handler after the chip initialization
(bnc#1012628).
- powerpc/pseries: Track LMB nid instead of using device tree
(bnc#1012628).
- arm64: defconfig: Update UFSHCD for Hi3660 soc (bnc#1012628).
- iommu/vt-d: Don't request page request irq under
dmar_global_lock (bnc#1012628).
- nvmem: core: fix read buffer in place (bnc#1012628).
- nvmem: sunxi_sid: Support SID on A83T and H5 (bnc#1012628).
- fuse: retrieve: cap requested size to negotiated max_write
(bnc#1012628).
- nfsd: allow fh_want_write to be called twice (bnc#1012628).
- nfsd: avoid uninitialized variable warning (bnc#1012628).
- vfio: Fix WARNING "do not call blocking ops when !TASK_RUNNING"
(bnc#1012628).
- iommu/arm-smmu-v3: Don't disable SMMU in kdump kernel
(bnc#1012628).
- switchtec: Fix unintended mask of MRPC event (bnc#1012628).
- net: thunderbolt: Unregister ThunderboltIP protocol handler
when suspending (bnc#1012628).
- x86/PCI: Fix PCI IRQ routing table memory leak (bnc#1012628).
- soc/tegra: pmc: Remove reset sysfs entries on error
(bnc#1012628).
- i40e: Queues are reserved despite "Invalid argument" error
(bnc#1012628).
- power: supply: cpcap-battery: Fix signed counter sample register
(bnc#1012628).
- platform/chrome: cros_ec_proto: check for NULL transfer function
(bnc#1012628).
- PCI: keystone: Invoke phy_reset() API before enabling PHY
(bnc#1012628).
- PCI: keystone: Prevent ARM32 specific code to be compiled for
ARM64 (bnc#1012628).
- soc: mediatek: pwrap: Zero initialize rdata in pwrap_init_cipher
(bnc#1012628).
- clk: rockchip: Turn on "aclk_dmac1" for suspend on rk3288
(bnc#1012628).
- usb: ohci-da8xx: disable the regulator if the overcurrent irq
fired (bnc#1012628).
- iommu/vt-d: Flush IOTLB for untrusted device in time
(bnc#1012628).
- soc: rockchip: Set the proper PWM for rk3288 (bnc#1012628).
- arm64: dts: imx8mq: Mark iomuxc_gpr as i.MX6Q compatible
(bnc#1012628).
- ARM: dts: imx51: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx50: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx53: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sx: Specify IMX6SX_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sll: Specify IMX6SLL_CLK_IPG as "ipg" clock to
SDMA (bnc#1012628).
- ARM: dts: imx7d: Specify IMX7D_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6ul: Specify IMX6UL_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sx: Specify IMX6SX_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6qdl: Specify IMX6QDL_CLK_IPG as "ipg" clock to
SDMA (bnc#1012628).
- PCI: rpadlpar: Fix leaked device_node references in add/remove
paths (bnc#1012628).
- drm/amd/display: disable link before changing link settings
(bnc#1012628).
- drm/amd/display: Use plane->color_space for dpp if specified
(bnc#1012628).
- ARM: OMAP2+: pm33xx-core: Do not Turn OFF CEFUSE as PPA may
be using it (bnc#1012628).
- pinctrl: pinctrl-intel: move gpio suspend/resume to noirq phase
(bnc#1012628).
- platform/x86: intel_pmc_ipc: adding error handling
(bnc#1012628).
- power: supply: max14656: fix potential use-before-alloc
(bnc#1012628).
- f2fs: fix potential recursive call when enabling data_flush
(bnc#1012628).
- net: hns3: return 0 and print warning when hit duplicate MAC
(bnc#1012628).
- PCI: dwc: Remove default MSI initialization for platform
specific MSI chips (bnc#1012628).
- PCI: rcar: Fix a potential NULL pointer dereference
(bnc#1012628).
- PCI: rcar: Fix 64bit MSI message address handling (bnc#1012628).
- scsi: qla2xxx: Reset the FCF_ASYNC_{SENT|ACTIVE} flags
(bnc#1012628).
- Input: goodix - add GT5663 CTP support (bnc#1012628).
- video: hgafb: fix potential NULL pointer dereference
(bnc#1012628).
- video: imsttfb: fix potential NULL pointer dereferences
(bnc#1012628).
- block, bfq: increase idling for weight-raised queues
(bnc#1012628).
- PCI: xilinx: Check for __get_free_pages() failure (bnc#1012628).
- arm64: dts: qcom: qcs404: Fix regulator supply names
(bnc#1012628).
- gpio: gpio-omap: add check for off wake capable gpios
(bnc#1012628).
- gpio: gpio-omap: limit errata 1.101 handling to wkup domain
gpios only (bnc#1012628).
- ice: Add missing case in print_link_msg for printing flow
control (bnc#1012628).
- media: v4l2-ctrl: v4l2_ctrl_request_setup returns with error
upon failure (bnc#1012628).
- batman-adv: Adjust name for batadv_dat_send_data (bnc#1012628).
- ice: Enable LAN_EN for the right recipes (bnc#1012628).
- ice: Do not set LB_EN for prune switch rules (bnc#1012628).
- dmaengine: idma64: Use actual device for DMA transfers
(bnc#1012628).
- pwm: tiehrpwm: Update shadow register for disabling PWMs
(bnc#1012628).
- media: v4l2-fwnode: Defaults may not override endpoint
configuration in firmware (bnc#1012628).
- ARM: dts: exynos: Always enable necessary APIO_1V8 and ABB_1V8
regulators on Arndale Octa (bnc#1012628).
- pwm: Fix deadlock warning when removing PWM device
(bnc#1012628).
- ARM: exynos: Fix undefined instruction during Exynos5422 resume
(bnc#1012628).
- usb: typec: fusb302: Check vconn is off when we start toggling
(bnc#1012628).
- soc: renesas: Identify R-Car M3-W ES1.3 (bnc#1012628).
- ARM: shmobile: porter: enable R-Car Gen2 regulator quirk
(bnc#1012628).
- gpio: vf610: Do not share irq_chip (bnc#1012628).
- percpu: do not search past bitmap when allocating an area
(bnc#1012628).
- Revert "Bluetooth: Align minimum encryption key size for LE
and BR/EDR connections" (bnc#1012628).
- Revert "drm/nouveau: add kconfig option to turn off nouveau
legacy contexts. (v3)" (bnc#1012628).
- ovl: check the capability before cred overridden (bnc#1012628).
- ovl: support stacked SEEK_HOLE/SEEK_DATA (bnc#1012628).
- ALSA: seq: Cover unsubscribe_port() in list_mutex (bnc#1012628).
- io_uring: fix failure to verify SQ_AFF cpu (bnc#1012628).
- Refresh
patches.suse/RFC-Bluetooth-Check-key-sizes-only-when-Secure-Simple-Pairing-is-enabled.patch.
- commit 0aa1dd8
- Update config files.
The previous commit did not play well. 5.1.9 is broken with =n of that
option, so leave it as =y as it was before 5.1.9.
- commit e68f829
- Update config files.
Set CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT=n, the same as master.
- commit cf58ab1
- Linux 5.1.9 (bnc#1012628).
- ethtool: fix potential userspace buffer overflow (bnc#1012628).
- Fix memory leak in sctp_process_init (bnc#1012628).
- ipv4: not do cache for local delivery if bc_forwarding is
enabled (bnc#1012628).
- ipv6: fix the check before getting the cookie in rt6_get_cookie
(bnc#1012628).
- net: ethernet: ti: cpsw_ethtool: fix ethtool ring param set
(bnc#1012628).
- net: mvpp2: Use strscpy to handle stat strings (bnc#1012628).
- net: rds: fix memory leak in rds_ib_flush_mr_pool (bnc#1012628).
- net: sfp: read eeprom in maximum 16 byte increments
(bnc#1012628).
- packet: unconditionally free po->rollover (bnc#1012628).
- pktgen: do not sleep with the thread lock held (bnc#1012628).
- Revert "fib_rules: return 0 directly if an exactly same rule
exists when NLM_F_EXCL not supplied" (bnc#1012628).
- udp: only choose unbound UDP socket for multicast when not in
a VRF (bnc#1012628).
- ipv6: use READ_ONCE() for inet->hdrincl as in ipv4
(bnc#1012628).
- ipv6: fix EFAULT on sendto with icmpv6 and hdrincl
(bnc#1012628).
- net: aquantia: fix wol configuration not applied sometimes
(bnc#1012628).
- neighbor: Reset gc_entries counter if new entry is released
before insert (bnc#1012628).
- neighbor: Call __ipv4_neigh_lookup_noref in neigh_xmit
(bnc#1012628).
- cls_matchall: avoid panic when receiving a packet before filter
set (bnc#1012628).
- ipmr_base: Do not reset index in mr_table_dump (bnc#1012628).
- net/mlx4_en: ethtool, Remove unsupported SFP EEPROM high pages
query (bnc#1012628).
- net/tls: replace the sleeping lock around RX resync with a
bit lock (bnc#1012628).
- rcu: locking and unlocking need to always be at least barriers
(bnc#1012628).
- habanalabs: fix debugfs code (bnc#1012628).
- ARC: mm: SIGSEGV userspace trying to access kernel virtual
memory (bnc#1012628).
- parisc: Use implicit space register selection for loading the
coherence index of I/O pdirs (bnc#1012628).
- parisc: Fix crash due alternative coding for NP iopdir_fdc bit
(bnc#1012628).
- SUNRPC fix regression in umount of a secure mount (bnc#1012628).
- SUNRPC: Fix a use after free when a server rejects the
RPCSEC_GSS credential (bnc#1012628).
- NFSv4.1: Again fix a race where CB_NOTIFY_LOCK fails to wake
a waiter (bnc#1012628).
- NFSv4.1: Fix bug only first CB_NOTIFY_LOCK is handled
(bnc#1012628).
- fuse: fallocate: fix return with locked inode (bnc#1012628).
- fuse: fix copy_file_range() in the writeback case (bnc#1012628).
- pstore: Set tfm to NULL on free_buf_for_compression
(bnc#1012628).
- pstore/ram: Run without kernel crash dump region (bnc#1012628).
- kbuild: use more portable 'command -v' for cc-cross-prefix
(bnc#1012628).
- memstick: mspro_block: Fix an error code in
mspro_block_issue_req() (bnc#1012628).
- mmc: tmio: fix SCC error handling to avoid false positive CRC
error (bnc#1012628).
- mmc: sdhci_am654: Fix SLOTTYPE write (bnc#1012628).
- x86/power: Fix 'nosmt' vs hibernation triple fault during resume
(bnc#1012628).
- x86/insn-eval: Fix use-after-free access to LDT entry
(bnc#1012628).
- i2c: xiic: Add max_read_len quirk (bnc#1012628).
- s390/mm: fix address space detection in exception handling
(bnc#1012628).
- nvme-rdma: fix queue mapping when queue count is limited
(bnc#1012628).
- xen-blkfront: switch kcalloc to kvcalloc for large array
allocation (bnc#1012628).
- MIPS: Bounds check virt_addr_valid (bnc#1012628).
- MIPS: pistachio: Build uImage.gz by default (bnc#1012628).
- genwqe: Prevent an integer overflow in the ioctl (bnc#1012628).
- test_firmware: Use correct snprintf() limit (bnc#1012628).
- drm/rockchip: fix fb references in async update (bnc#1012628).
- drm/vc4: fix fb references in async update (bnc#1012628).
- drm/gma500/cdv: Check vbt config bits when detecting lvds panels
(bnc#1012628).
- drm/msm: fix fb references in async update (bnc#1012628).
- drm: add non-desktop quirk for Valve HMDs (bnc#1012628).
- drm/nouveau: add kconfig option to turn off nouveau legacy
contexts. (v3) (bnc#1012628).
- drm: add non-desktop quirks to Sensics and OSVR headsets
(bnc#1012628).
- drm: Fix timestamp docs for variable refresh properties
(bnc#1012628).
- drm/amdgpu/psp: move psp version specific function pointers
to early_init (bnc#1012628).
- drm/radeon: prefer lower reference dividers (bnc#1012628).
- drm/amdgpu: remove ATPX_DGPU_REQ_POWER_FOR_DISPLAYS check when
hotplug-in (bnc#1012628).
- drm/i915: Fix I915_EXEC_RING_MASK (bnc#1012628).
- drm/amdgpu/soc15: skip reset on init (bnc#1012628).
- drm/amd/display: Add ASICREV_IS_PICASSO (bnc#1012628).
- drm/amdgpu: fix ring test failure issue during s3 in vce 3.0
(V2) (bnc#1012628).
- drm/i915/fbc: disable framebuffer compression on GeminiLake
(bnc#1012628).
- drm/i915/gvt: emit init breadcrumb for gvt request
(bnc#1012628).
- drm: don't block fb changes for async plane updates
(bnc#1012628).
- drm/i915/gvt: Initialize intel_gvt_gtt_entry in stack
(bnc#1012628).
- drm/amd: fix fb references in async update (bnc#1012628).
- ipv4: Define __ipv4_neigh_lookup_noref when CONFIG_INET is
disabled (bnc#1012628).
- commit 8904439
- Revert "drm: allow render capable master with DRM_AUTH ioctls"
(fix radv check).
- commit 3ca4077
- drm/i915: Maintain consistent documentation subsection ordering
(fix kernel-doc).
- Delete
patches.rpmify/Revert-doc-Cope-with-the-deprecation-of-AutoReporter.patch.
Use usptream fix instead of revert.
- commit 4e8aae9
- scsi: mpt3sas_ctl: fix double-fetch bug in _ctl_ioctl_main()
(bsc#1136922 cve-2019-12456).
- commit 0c3fc9f
- Revert "doc: Cope with the deprecation of AutoReporter"
(fix kernel-doc).
- commit 1c5c2b4
- Linux 5.1.8 (bnc#1012628).
- sparc64: Fix regression in non-hypervisor TLB flush xcall
(bnc#1012628).
- include/linux/bitops.h: sanitize rotate primitives
(bnc#1012628).
- xhci: update bounce buffer with correct sg num (bnc#1012628).
- xhci: Use %zu for printing size_t type (bnc#1012628).
- xhci: Convert xhci_handshake() to use
readl_poll_timeout_atomic() (bnc#1012628).
- usb: xhci: avoid null pointer deref when bos field is NULL
(bnc#1012628).
- usbip: usbip_host: fix BUG: sleeping function called from
invalid context (bnc#1012628).
- usbip: usbip_host: fix stub_dev lock context imbalance
regression (bnc#1012628).
- USB: Fix slab-out-of-bounds write in usb_get_bos_descriptor
(bnc#1012628).
- USB: sisusbvga: fix oops in error path of sisusb_probe
(bnc#1012628).
- USB: Add LPM quirk for Surface Dock GigE adapter (bnc#1012628).
- USB: rio500: refuse more than one device at a time
(bnc#1012628).
- USB: rio500: fix memory leak in close after disconnect
(bnc#1012628).
- media: usb: siano: Fix general protection fault in smsusb
(bnc#1012628).
- media: usb: siano: Fix false-positive "uninitialized variable"
warning (bnc#1012628).
- media: smsusb: better handle optional alignment (bnc#1012628).
- brcmfmac: fix NULL pointer derefence during USB disconnect
(bnc#1012628).
- scsi: zfcp: fix missing zfcp_port reference put on -EBUSY from
port_remove (bnc#1012628).
- scsi: zfcp: fix to prevent port_remove with pure auto scan LUNs
(only sdevs) (bnc#1012628).
- tracing: Avoid memory leak in predicate_parse() (bnc#1012628).
- Btrfs: fix wrong ctime and mtime of a directory after log replay
(bnc#1012628).
- Btrfs: fix race updating log root item during fsync
(bnc#1012628).
- Btrfs: fix fsync not persisting changed attributes of a
directory (bnc#1012628).
- btrfs: correct zstd workspace manager lock to use spin_lock_bh()
(bnc#1012628).
- btrfs: qgroup: Check bg while resuming relocation to avoid
NULL pointer dereference (bnc#1012628).
- Btrfs: incremental send, fix file corruption when no-holes
feature is enabled (bnc#1012628).
- btrfs: reloc: Also queue orphan reloc tree for cleanup to
avoid BUG_ON() (bnc#1012628).
- iio: dac: ds4422/ds4424 fix chip verification (bnc#1012628).
- iio: adc: ads124: avoid buffer overflow (bnc#1012628).
- iio: adc: modify NPCM ADC read reference voltage (bnc#1012628).
- iio: adc: ti-ads8688: fix timestamp is not updated in buffer
(bnc#1012628).
- s390/crypto: fix gcm-aes-s390 selftest failures (bnc#1012628).
- s390/crypto: fix possible sleep during spinlock aquired
(bnc#1012628).
- KVM: PPC: Book3S HV: XIVE: Do not clear IRQ data of passthrough
interrupts (bnc#1012628).
- KVM: PPC: Book3S HV: Fix lockdep warning when entering guest
on POWER9 (bnc#1012628).
- KVM: PPC: Book3S HV: Restore SPRG3 in kvmhv_p9_guest_entry()
(bnc#1012628).
- powerpc/perf: Fix MMCRA corruption by bhrb_filter (bnc#1012628).
- powerpc/kexec: Fix loading of kernel + initramfs with
kexec_file_load() (bnc#1012628).
- ALSA: line6: Assure canceling delayed work at disconnection
(bnc#1012628).
- ALSA: hda/realtek - Set default power save node to 0
(bnc#1012628).
- ALSA: hda/realtek - Improve the headset mic for Acer Aspire
laptops (bnc#1012628).
- KVM: s390: Do not report unusabled IDs via KVM_CAP_MAX_VCPU_ID
(bnc#1012628).
- drm/nouveau/i2c: Disable i2c bus access after ->fini()
(bnc#1012628).
- i2c: mlxcpld: Fix wrong initialization order in probe
(bnc#1012628).
- i2c: synquacer: fix synquacer_i2c_doxfer() return value
(bnc#1012628).
- tty: serial: msm_serial: Fix XON/XOFF (bnc#1012628).
- tty: max310x: Fix external crystal register setup (bnc#1012628).
- mm, memcg: consider subtrees in memory.events (bnc#1012628).
- kasan: initialize tag to 0xff in __kasan_kmalloc (bnc#1012628).
- kernel/signal.c: trace_signal_deliver when signal_group_exit
(bnc#1012628).
- signal/arm64: Use force_sig not force_sig_fault for SIGKILL
(bnc#1012628).
- mm, compaction: make sure we isolate a valid PFN (bnc#1012628).
- arm64: Fix the arm64_personality() syscall wrapper redirection
(bnc#1012628).
- docs: Fix conf.py for Sphinx 2.0 (bnc#1012628).
- doc: Cope with the deprecation of AutoReporter (bnc#1012628).
- doc: Cope with Sphinx logging deprecations (bnc#1012628).
- x86/ima: Check EFI_RUNTIME_SERVICES before using (bnc#1012628).
- ima: fix wrong signed policy requirement when not appraising
(bnc#1012628).
- ima: show rules with IMA_INMASK correctly (bnc#1012628).
- evm: check hash algorithm passed to init_desc() (bnc#1012628).
- clk: imx: imx8mm: fix int pll clk gate (bnc#1012628).
- vt/fbcon: deinitialize resources in visual_init() after failed
memory allocation (bnc#1012628).
- serial: sh-sci: disable DMA for uart_console (bnc#1012628).
- staging: vc04_services: prevent integer overflow in
create_pagelist() (bnc#1012628).
- staging: wlan-ng: fix adapter initialization failure
(bnc#1012628).
- cifs: fix memory leak of pneg_inbuf on -EOPNOTSUPP ioctl case
(bnc#1012628).
- CIFS: cifs_read_allocate_pages: don't iterate through whole
page array on ENOMEM (bnc#1012628).
- Revert "lockd: Show pid of lockd for remote locks"
(bnc#1012628).
- gcc-plugins: Fix build failures under Darwin host (bnc#1012628).
- drm/tegra: gem: Fix CPU-cache maintenance for BO's allocated
using get_pages() (bnc#1012628).
- drm/vmwgfx: Fix user space handle equal to zero (bnc#1012628).
- drm/vmwgfx: Fix compat mode shader operation (bnc#1012628).
- drm/vmwgfx: Don't send drm sysfs hotplug events on initial
master set (bnc#1012628).
- drm/sun4i: Fix sun8i HDMI PHY clock initialization
(bnc#1012628).
- drm/sun4i: Fix sun8i HDMI PHY configuration for > 148.5 MHz
(bnc#1012628).
- drm/imx: ipuv3-plane: fix atomic update status query for
non-plus i.MX6Q (bnc#1012628).
- drm/fb-helper: generic: Call drm_client_add() after setup is
done (bnc#1012628).
- drm/atomic: Wire file_priv through for property changes
(bnc#1012628).
- drm: Expose "FB_DAMAGE_CLIPS" property to atomic aware
user-space only (bnc#1012628).
- drm/rockchip: shutdown drm subsystem on shutdown (bnc#1012628).
- drm/lease: Make sure implicit planes are leased (bnc#1012628).
- drm/cma-helper: Fix drm_gem_cma_free_object() (bnc#1012628).
- Revert "x86/build: Move _etext to actual end of .text"
(bnc#1012628).
- x86/kprobes: Set instruction page as executable (bnc#1012628).
- commit ed4965b
- s390: drop meaningless 'targets' from tools Makefile (s390
kmp build fix).
- commit c8cc0ca
==== libcontainers-common ====
- Update to libpod v1.4.0
- The podman checkpoint and podman restore commands can now be
used to migrate containers between Podman installations on
different systems
- The podman cp command now supports a pause flag to pause
containers while copying into them
- The remote client now supports a configuration file for
pre-configuring connections to remote Podman installations
- Fixed CVE-2019-10152 - The podman cp command improperly
dereferenced symlinks in host context
- Fixed a bug where podman commit could improperly set
environment variables that contained = characters
- Fixed a bug where rootless Podman would sometimes fail to start
containers with forwarded ports
- Fixed a bug where podman version on the remote client could
segfault
- Fixed a bug where podman container runlabel would use
/proc/self/exe instead of the path of the Podman command when
printing the command being executed
- Fixed a bug where filtering images by label did not work
- Fixed a bug where specifying a bing mount or tmpfs mount over
an image volume would cause a container to be unable to start
- Fixed a bug where podman generate kube did not work with
containers with named volumes
- Fixed a bug where rootless Podman would receive permission
denied errors accessing conmon.pid
- Fixed a bug where podman cp with a folder specified as target
would replace the folder, as opposed to copying into it
- Fixed a bug where rootless Podman commands could double-unlock
a lock, causing a crash
- Fixed a bug where Podman incorrectly set tmpcopyup on /dev/
mounts, causing errors when using the Kata containers runtime
- Fixed a bug where podman exec would fail on older kernels
- The podman commit command is now usable with the Podman remote
client
- The --signature-policy flag (used with several image-related
commands) has been deprecated
- The podman unshare command now defines two environment
variables in the spawned shell: CONTAINERS_RUNROOT and
CONTAINERS_GRAPHROOT, pointing to temporary and permanent
storage for rootless containers
- Updated vendored containers/storage and containers/image
libraries with numerous bugfixes
- Updated vendored Buildah to v1.8.3
- Podman now requires Conmon v0.2.0
- The podman cp command is now aliased as podman container cp
- Rootless Podman will now default init_path using root Podman's
configuration files (/etc/containers/libpod.conf and
/usr/share/containers/libpod.conf) if not overridden in the
rootless configuration
- Update to image v1.5.1
- Vendor in latest containers/storage
- docker/docker_client: Drop redundant Domain(ref.ref) call
- pkg/blobinfocache: Split implementations into subpackages
- copy: progress bar: show messages on completion
- docs: rename manpages to *.5.command
- add container-certs.d.md manpage
- pkg/docker/config: Bring auth tests from
docker/docker_client_test
- Don't allocate a sync.Mutex separately
- Update to storage v1.12.10
- Add function to parse out mount options from graphdriver
- Merge the disparate parts of all of the Unix-like lockfiles
- Fix unix-but-not-Linux compilation
- Return XDG_RUNTIME_DIR as RootlessRuntimeDir if set
- Cherry-pick moby/moby #39292 for CVE-2018-15664 fixes
- lockfile: add RecursiveLock() API
- Update generated files
- Fix crash on tesing of aufs code
- Let consumers know when Layers and Images came from read-only stores
- chown: do not change owner for the mountpoint
- locks: correctly mark updates to the layers list
- CreateContainer: don't worry about mapping layers unless necessary
- docs: fix manpage for containers-storage.conf
- docs: sort configuration options alphabetically
- docs: document OSTree file deduplication
- Add missing options to man page for containers-storage
- overlay: use the layer idmapping if present
- vfs: prefer layer custom idmappings
- layers: propagate down the idmapping settings
- Recreate symlink when not found
- docs: fix manpage for configuration file
- docs: add special handling for manpages in sect 5
- overlay: fix single-lower test
- Recreate symlink when not found
- overlay: propagate errors from mountProgram
- utils: root in a userns uses global conf file
- Fix handling of additional stores
- Correctly check permissions on rootless directory
- Fix possible integer overflow on 32bit builds
- Evaluate device path for lvm
- lockfile test: make concurrent RW test determinisitc
- lockfile test: make concurrent read tests deterministic
- drivers.DirCopy: fix filemode detection
- storage: move the logic to detect rootless into utils.go
- Don't set (struct flock).l_pid
- Improve documentation of getLockfile
- Rename getLockFile to createLockerForPath, and document it
- Add FILES section to containers-storage.5 man page
- add digest locks
- drivers/copy: add a non-cgo fallback
- Add default SLES mounts for container-suseconnect usage
==== libseccomp ====
Version update (2.4.0 -> 2.4.1)
- Update to new upstream release 2.4.1
* Fix a BPF generation bug where the optimizer mistakenly
identified duplicate BPF code blocks.
==== libsolv ====
Version update (0.7.4 -> 0.7.5)
- make cleandeps jobs on patterns work [bnc#1137977]
- fix favorq leaking between solver runs if the solver is reused
- fix SOLVER_FLAG_FOCUS_BEST updateing packages without reason
- be more correct with multiversion packages that obsolete their
own name [bnc#1127155]
- allow building with swig-4.0.0 [bnc#1135749]
- bump version to 0.7.5
- always prefer to stay with the same package name if there are
multiple alternatives [bnc#1131823]
==== libzypp ====
Version update (17.11.4 -> 17.12.0)
- Drop unused InterProcessMutex class and test
- Drop unused WebpinResult class and test
- Give posttrans script a parameter of 0 (issue #168)
- Use CURL_HTTP_VERSION_2TLS if available (fixes #141)
- version 17.12.0 (12)
==== microos-tools ====
Version update (1.0+git20190218.9e72dd7 -> 1.0+git20190611.6211f74)
- Update to version 1.0+git20190611.6211f74:
* Rename 51-corefiles.conf to 30-corefiles.conf, so that an user
can override it by installing telemectrics-client or
systemd-coredump.
==== ncurses ====
Subpackages: libncurses6 ncurses-utils terminfo terminfo-base
- Add ncurses patch 20190609
+ add mintty, mintty-direct (adapted from patch by Thomas Wolff).
Some of the suggested user-defined capabilities are commented-out,
to allow builds with ncurses 5.9 and 6.0
+ add Smol/Rmol for tmux, vte-2018 (patch by Nicholas Marriott).
+ add rs1 to konsole, mlterm -TD
+ modify _nc_merge_entry() to make a copy of the data which it merges,
to avoid modifying the source-data when aligning extended names.
- Add ncurses patch 20190601
+ modify an internal call to vid_puts to pass extended color pairs
e.g., from tty_update.c and lib_mvcur.c (report by Niegodziwy Beru).
+ improve manual page description of init_tabs capability and TABSIZE
variable.
- Add ncurses patch 20190525
+ modify reset_cmd.c to allow for tabstops at intervals other than 8
(report by Vincent Huisman).
- Add ncurses patch 20190518
+ update xterm-new to xterm patch #345 -TD
+ add/use xterm+keypad in xterm-new (report by Alain D D Williams) -TD
+ update terminator entry -TD
+ remove hard-tabs from ti703 (report by Robert Clausecker)
+ mention meml/memu/box1 in user_caps manual page.
+ mention user_caps.5 in tic and infocmp manual pages.
- Adopt the patches ncurses-5.9-ibm327x.dif and ncurses-6.1.dif
==== permissions ====
Version update (1550_20190429 -> 1550_20190521)
Subpackages: chkstat permissions-config
- Update to version 20190521:
* singluarity: Add starter-suid for version 3.2.0
* adjust settings for amanda to current binary layout
- Move BuildRequires: back to main package
- Moved requires to subpackages (bsc#1137257)
==== python-base ====
Subpackages: libpython2_7-1_0
- Set _lto_cflags to nil as it will prevent to propage LTO
for Python modules that are built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
==== systemd-presets-common-SUSE ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== sysvinit ====
Version update (2.90 -> 2.95)
- Remove logsave as well as the manual page as those as part of
package e2fsprogs already
- Update to sysvinit 2.95
* new logsave helper
- Update to startpar-0.63
* move startpar from /sbin to /bin
- Port our patches
* startpar-0.58.dif
* sysvinit-2.88dsf-suse.patch
* sysvinit-2.90-no-kill.patch
* sysvinit-2.90.dif
==== zlib ====
- Do not enable the previous patchset on s390 but just s390x
bsc#1137624
- Add patchset for s390 improvements jsc#SLE-5807 bsc#1136717:
* 410.patch
==== zypper ====
Version update (1.14.27 -> 1.14.28)
- man: split '--with[out]' like options to ease searching.
- Unhide 'ps' command in help
- Add option to show more conflict information
- Rephrased `zypper ps` hint (bsc#859480)
- Fix repo refresh not returning 106-ZYPPER_EXIT_INF_REPOS_SKIPPED
if --root is used (bsc#1134226)
- Fix unknown package handling in zypper install (fixes bsc#1127608)
- Fix the package build failure with CMake 3.14.
- Re-show progress bar after pressing retry upon install error
(bsc#1131113)
- version 1.14.28
- Fix build with CMake >= 3.14
Starting with CMake 3.14, EXCLUDE_FROM_ALL now spreads from
directories to targets. 'make -C someSubdir' when 'someSubdir'
uses the 'EXCLUDE_FROM_ALL' keyword does nothing.
- Remove unneeded CMake commands.
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
audit
audit-secondary
btrfsmaintenance
cloud-init (18.5 -> 19.1)
ding-libs
filesystem
gcc9 (9.1.1+r271393 -> 9.1.1+r272147)
glib-networking (2.60.2 -> 2.60.3)
glib2 (2.60.3 -> 2.60.4)
growpart
hwdata (0.323 -> 0.324)
kernel-firmware (20190514 -> 20190618)
kernel-source (5.1.7 -> 5.1.10)
kubic-control (0.5.1 -> 0.6.1)
libcontainers-common
libseccomp (2.4.0 -> 2.4.1)
libsolv (0.7.4 -> 0.7.5)
libzypp (17.11.4 -> 17.12.0)
microos-tools (1.0+git20190218.9e72dd7 -> 1.0+git20190611.6211f74)
ncurses
permissions (1550_20190429 -> 1550_20190521)
python-base
salt
systemd-presets-common-SUSE
sysvinit (2.90 -> 2.95)
zlib
zypper (1.14.27 -> 1.14.28)
=== Details ===
==== audit ====
Subpackages: libaudit1 libauparse0
- Make use of some %make_install.
==== audit-secondary ====
Subpackages: audit python3-audit
- Reduce scriptlets' hard dependency on systemd.
==== btrfsmaintenance ====
- spec: fix typo in macro name
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== cloud-init ====
Version update (18.5 -> 19.1)
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
- Update to version 19.1 (bsc#1136440)
+ Remove, included upstream
- fix-default-systemd-unit-dir.patch
- cloud-init-sysconf-ethsetup.patch
- cloud-init-handle-def-route-set.patch
- cloud-init-no-empty-resolv.patch
- cloud-init-proper-ipv6-varname.patch
+ Forward port
- cloud-init-trigger-udev.patch
+ Add cloud-init-detect-nova.diff (bsc#1136440)
+ Modify cloud-init-python2-sigpipe.patch, import signal and constants
+ Update spec to account for new location of bash completion
+ freebsd: add chpasswd pkg in the image [Gonéri Le Bouder]
+ tests: add Eoan release [Paride Legovini]
+ cc_mounts: check if mount -a on no-change fstab path
[Jason Zions (MSFT)] (LP: #1825596)
+ replace remaining occurrences of LOG.warn [Daniel Watkins]
+ DataSourceAzure: Adjust timeout for polling IMDS [Anh Vo]
+ Azure: Changes to the Hyper-V KVP Reporter [Anh Vo]
+ git tests: no longer show warning about safe yaml.
+ tools/read-version: handle errors [Chad Miller]
+ net/sysconfig: only indicate available on known sysconfig distros
(LP: #1819994)
+ packages: update rpm specs for new bash completion path
[Daniel Watkins] (LP: #1825444)
+ test_azure: mock util.SeLinuxGuard where needed
[Jason Zions (MSFT)] (LP: #1825253)
+ setup.py: install bash completion script in new location [Daniel Watkins]
+ mount_cb: do not pass sync and rw options to mount
[Gonéri Le Bouder] (LP: #1645824)
+ cc_apt_configure: fix typo in apt documentation [Dominic Schlegel]
+ Revert "DataSource: move update_events from a class to an instance..."
[Daniel Watkins]
+ Change DataSourceNoCloud to ignore file system label's case.
[Risto Oikarinen]
+ cmd:main.py: Fix missing 'modules-init' key in modes dict
[Antonio Romito] (LP: #1815109)
+ ubuntu_advantage: rewrite cloud-config module
+ Azure: Treat _unset network configuration as if it were absent
[Jason Zions (MSFT)] (LP: #1823084)
+ DatasourceAzure: add additional logging for azure datasource [Anh Vo]
+ cloud_tests: fix apt_pipelining test-cases
+ Azure: Ensure platform random_seed is always serializable as JSON.
[Jason Zions (MSFT)]
+ net/sysconfig: write out SUSE-compatible IPv6 config [Robert Schweikert]
+ tox: Update testenv for openSUSE Leap to 15.0 [Thomas Bechtold]
+ net: Fix ipv6 static routes when using eni renderer
[Raphael Glon] (LP: #1818669)
+ Add ubuntu_drivers config module [Daniel Watkins]
+ doc: Refresh Azure walinuxagent docs [Daniel Watkins]
+ tox: bump pylint version to latest (2.3.1) [Daniel Watkins]
+ DataSource: move update_events from a class to an instance attribute
[Daniel Watkins] (LP: #1819913)
+ net/sysconfig: Handle default route setup for dhcp configured NICs
[Robert Schweikert] (LP: #1812117)
+ DataSourceEc2: update RELEASE_BLOCKER to be more accurate
[Daniel Watkins]
+ cloud-init-per: POSIX sh does not support string subst, use sed
(LP: #1819222)
+ Support locking user with usermod if passwd is not available.
+ Example for Microsoft Azure data disk added. [Anton Olifir]
+ clean: correctly determine the path for excluding seed directory
[Daniel Watkins] (LP: #1818571)
+ helpers/openstack: Treat unknown link types as physical
[Daniel Watkins] (LP: #1639263)
+ drop Python 2.6 support and our NIH version detection [Daniel Watkins]
+ tip-pylint: Fix assignment-from-return-none errors
+ net: append type:dhcp[46] only if dhcp[46] is True in v2 netconfig
[Kurt Stieger] (LP: #1818032)
+ cc_apt_pipelining: stop disabling pipelining by default
[Daniel Watkins] (LP: #1794982)
+ tests: fix some slow tests and some leaking state [Daniel Watkins]
+ util: don't determine string_types ourselves [Daniel Watkins]
+ cc_rsyslog: Escape possible nested set [Daniel Watkins] (LP: #1816967)
+ Enable encrypted_data_bag_secret support for Chef
[Eric Williams] (LP: #1817082)
+ azure: Filter list of ssh keys pulled from fabric [Jason Zions (MSFT)]
+ doc: update merging doc with fixes and some additional details/examples
+ tests: integration test failure summary to use traceback if empty error
+ This is to fix https://bugs.launchpad.net/cloud-init/+bug/1812676
[Vitaly Kuznetsov]
+ EC2: Rewrite network config on AWS Classic instances every boot
[Guilherme G. Piccoli] (LP: #1802073)
+ netinfo: Adjust ifconfig output parsing for FreeBSD ipv6 entries
(LP: #1779672)
+ netplan: Don't render yaml aliases when dumping netplan (LP: #1815051)
+ add PyCharm IDE .idea/ path to .gitignore [Dominic Schlegel]
+ correct grammar issue in instance metadata documentation
[Dominic Schlegel] (LP: #1802188)
+ clean: cloud-init clean should not trace when run from within cloud_dir
(LP: #1795508)
+ Resolve flake8 comparison and pycodestyle over-ident issues
[Paride Legovini]
+ opennebula: also exclude epochseconds from changed environment vars
(LP: #1813641)
+ systemd: Render generator from template to account for system
differences. [Robert Schweikert]
+ sysconfig: On SUSE, use STARTMODE instead of ONBOOT
[Robert Schweikert] (LP: #1799540)
+ flake8: use ==/!= to compare str, bytes, and int literals
[Paride Legovini]
+ opennebula: exclude EPOCHREALTIME as known bash env variable with a
delta (LP: #1813383)
+ tox: fix disco httpretty dependencies for py37 (LP: #1813361)
+ run-container: uncomment baseurl in yum.repos.d/*.repo when using a
proxy [Paride Legovini]
+ lxd: install zfs-linux instead of zfs meta package
[Johnson Shi] (LP: #1799779)
+ net/sysconfig: do not write a resolv.conf file with only the header.
[Robert Schweikert]
+ net: Make sysconfig renderer compatible with Network Manager.
[Eduardo Otubo]
+ cc_set_passwords: Fix regex when parsing hashed passwords
[Marlin Cremers] (LP: #1811446)
+ net: Wait for dhclient to daemonize before reading lease file
[Jason Zions] (LP: #1794399)
+ [Azure] Increase retries when talking to Wireserver during metadata walk
[Jason Zions]
+ Add documentation on adding a datasource.
+ doc: clean up some datasource documentation.
+ ds-identify: fix wrong variable name in ovf_vmware_transport_guestinfo.
+ Scaleway: Support ssh keys provided inside an instance tag. [PORTE Loïc]
+ OVF: simplify expected return values of transport functions.
+ Vmware: Add support for the com.vmware.guestInfo OVF transport.
(LP: #1807466)
+ HACKING.rst: change contact info to Josh Powers
+ Update to pylint 2.2.2.
==== ding-libs ====
Subpackages: libbasicobjects0 libcollection4 libdhash1 libini_config5 libpath_utils1 libref_array1
- Add patch fixing errors writeout to stdout:
* INI-Remove-definiton-of-TRACE_LEVEL.patch
==== filesystem ====
- Re-add /var/cache and /var/log (revert [bsc#1078466] because of
[bsc#1078466])
- Fix permission of fs-var.conf
==== gcc9 ====
Version update (9.1.1+r271393 -> 9.1.1+r272147)
Subpackages: libgcc_s1 libstdc++6
- Update to gcc-9-branch head (r272147).
* Pulls fix for random debug info differences when compiling D code.
[gcc#90778]
- Update to gcc-9-branch head (r271995).
* installs workaround for broken lapack C interfaces
- Drop gcc9-spectrev1.patch, add gcc9-reproducible-builds.patch
and gcc9-reproducible-builds-buildid-for-checksum.patch moving
reproducible build improvements over from GCC 8 package.
- Split out libstdc++ pretty-printers into a separate package
supplementing gdb and the installed runtime. [bsc#1135254]
- Update to gcc-9-branch head (r271643).
==== glib-networking ====
Version update (2.60.2 -> 2.60.3)
- Update to version 2.60.3:
+ Fix clobbering of the thread-default main context after
certificate verification failure during async handshakes since
2.60.1.
+ Fix GTlsDatabase initialization failures in OpenSSL backend due
to uninitialized memory use.
+ Fix minor leak of ALPN protocols.
==== glib2 ====
Version update (2.60.3 -> 2.60.4)
Subpackages: glib2-tools libgio-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0
- Update to version 2.60.4:
+ Fixes to improved network status detection with NetworkManager.
+ Leak fixes to some `glib-genmarshal` generated code.
+ Further fixes to the Happy Eyeballs (RFC 8305) implementation.
+ File system permissions fix to clamp down permissions in a
small time window when copying files (CVE-2019-12450).
+ Bugs fixed: glgo#GNOME/GLib#1755, glgo#GNOME/GLib#1788,
glgo#GNOME/GLib#1792, glgo#GNOME/GLib#1793,
glgo#GNOME/GLib#1795, glgo#GNOME/GLib!865, glgo#GNOME/GLib!878.
==== growpart ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== hwdata ====
Version update (0.323 -> 0.324)
- Update to version 0.324:
* Updated pci, usb and vendor ids.
==== kernel-firmware ====
Version update (20190514 -> 20190618)
Subpackages: ucode-amd
- Update to version 20190618:
* cavium: Add firmware for CNN55XX crypto driver.
* linux-firmware: Update firmware file for Intel Bluetooth 22161
* linux-firmware: Update firmware file for Intel Bluetooth 9560
* linux-firmware: Update firmware file for Intel Bluetooth 9260
* linux-firmware: Update AMD SEV firmware
* linux-firmware: update licence text for Marvell firmware
- Update to version 20190607:
* linux-firmware: update firmware for mhdp8546
* linux-firmware: rsi: update firmware images for Redpine 9113 chipset
* imx: sdma: update firmware to v3.5/v4.5
* nvidia: update GP10[2467] SEC2 RTOS with the one already used on GP108
==== kernel-source ====
Version update (5.1.7 -> 5.1.10)
Subpackages: kernel-debug kernel-default
- move patches from .fixes to .suse
There is no patches.fixes in stable.
- commit ad24342
- tcp: enforce tcp_min_snd_mss in tcp_mtu_probing() (bsc#1137586
CVE-2019-11479).
- tcp: add tcp_min_snd_mss sysctl (bsc#1137586 CVE-2019-11479).
- tcp: tcp_fragment() should apply sane memory limits (bsc#1137586
CVE-2019-11478).
- tcp: limit payload size of sacked skbs (bsc#1137586
CVE-2019-11477).
- commit a5ec6d9
- Linux 5.1.10 (bnc#1012628).
- media: rockchip/vpu: Fix/re-order probe-error/remove path
(bnc#1012628).
- media: rockchip/vpu: Add missing dont_use_autosuspend() calls
(bnc#1012628).
- rapidio: fix a NULL pointer dereference when create_workqueue()
fails (bnc#1012628).
- fs/fat/file.c: issue flush after the writeback of FAT
(bnc#1012628).
- sysctl: return -EINVAL if val violates minmax (bnc#1012628).
- ipc: prevent lockup on alloc_msg and free_msg (bnc#1012628).
- drm/msm: correct attempted NULL pointer dereference in debugfs
(bnc#1012628).
- drm/pl111: Initialize clock spinlock early (bnc#1012628).
- mm/mprotect.c: fix compilation warning because of unused 'mm'
variable (bnc#1012628).
- ARM: prevent tracing IPI_CPU_BACKTRACE (bnc#1012628).
- mm/hmm: select mmu notifier when selecting HMM (bnc#1012628).
- hugetlbfs: on restore reserve error path retain subpool
reservation (bnc#1012628).
- mm/memory_hotplug: release memory resource after
arch_remove_memory() (bnc#1012628).
- mem-hotplug: fix node spanned pages when we have a node with
only ZONE_MOVABLE (bnc#1012628).
- mm/cma.c: fix crash on CMA allocation if bitmap allocation fails
(bnc#1012628).
- initramfs: free initrd memory if opening /initrd.image fails
(bnc#1012628).
- mm/compaction.c: fix an undefined behaviour (bnc#1012628).
- mm/memory_hotplug.c: fix the wrong usage of N_HIGH_MEMORY
(bnc#1012628).
- mm/cma.c: fix the bitmap status to show failed allocation reason
(bnc#1012628).
- mm: page_mkclean vs MADV_DONTNEED race (bnc#1012628).
- mm/cma_debug.c: fix the break condition in cma_maxchunk_get()
(bnc#1012628).
- mm/slab.c: fix an infinite loop in leaks_show() (bnc#1012628).
- kernel/sys.c: prctl: fix false positive in validate_prctl_map()
(bnc#1012628).
- thermal: rcar_gen3_thermal: disable interrupt in .remove
(bnc#1012628).
- drivers: thermal: tsens: Don't print error message on
- EPROBE_DEFER (bnc#1012628).
- mfd: tps65912-spi: Add missing of table registration
(bnc#1012628).
- mfd: intel-lpss: Set the device in reset state when init
(bnc#1012628).
- drm/nouveau/disp/dp: respect sink limits when selecting failsafe
link configuration (bnc#1012628).
- mfd: twl6040: Fix device init errors for ACCCTL register
(bnc#1012628).
- perf/x86/intel: Allow PEBS multi-entry in watermark mode
(bnc#1012628).
- drm/nouveau/kms/gf119-gp10x: push HeadSetControlOutputResource()
mthd when encoders change (bnc#1012628).
- drm/nouveau: fix duplication of nv50_head_atom struct
(bnc#1012628).
- drm/bridge: adv7511: Fix low refresh rate selection
(bnc#1012628).
- objtool: Don't use ignore flag for fake jumps (bnc#1012628).
- drm/nouveau/kms/gv100-: fix spurious window immediate interlocks
(bnc#1012628).
- bpf: fix undefined behavior in narrow load handling
(bnc#1012628).
- EDAC/mpc85xx: Prevent building as a module (bnc#1012628).
- pwm: meson: Use the spin-lock only to protect register
modifications (bnc#1012628).
- mailbox: stm32-ipcc: check invalid irq (bnc#1012628).
- ntp: Allow TAI-UTC offset to be set to zero (bnc#1012628).
- f2fs: fix to avoid panic in do_recover_data() (bnc#1012628).
- f2fs: fix to avoid panic in f2fs_inplace_write_data()
(bnc#1012628).
- f2fs: fix error path of recovery (bnc#1012628).
- f2fs: fix to avoid panic in f2fs_remove_inode_page()
(bnc#1012628).
- f2fs: fix to do sanity check on free nid (bnc#1012628).
- f2fs: fix to clear dirty inode in error path of f2fs_iget()
(bnc#1012628).
- f2fs: fix to avoid panic in dec_valid_block_count()
(bnc#1012628).
- f2fs: fix to use inline space only if inline_xattr is enable
(bnc#1012628).
- f2fs: fix to avoid panic in dec_valid_node_count()
(bnc#1012628).
- f2fs: fix to do sanity check on valid block count of segment
(bnc#1012628).
- f2fs: fix to avoid deadloop in foreground GC (bnc#1012628).
- f2fs: fix to retrieve inline xattr space (bnc#1012628).
- f2fs: fix to do checksum even if inode page is uptodate
(bnc#1012628).
- media: atmel: atmel-isc: fix asd memory allocation
(bnc#1012628).
- percpu: remove spurious lock dependency between percpu and sched
(bnc#1012628).
- configfs: fix possible use-after-free in configfs_register_group
(bnc#1012628).
- uml: fix a boot splat wrt use of cpu_all_mask (bnc#1012628).
- PCI: dwc: Free MSI in dw_pcie_host_init() error path
(bnc#1012628).
- PCI: dwc: Free MSI IRQ page in dw_pcie_free_msi() (bnc#1012628).
- fbcon: Don't reset logo_shown when logo is currently shown
(bnc#1012628).
- ovl: do not generate duplicate fsnotify events for "fake" path
(bnc#1012628).
- mmc: mmci: Prevent polling for busy detection in IRQ context
(bnc#1012628).
- netfilter: nf_flow_table: fix missing error check for
rhashtable_insert_fast (bnc#1012628).
- netfilter: nf_conntrack_h323: restore boundary check correctness
(bnc#1012628).
- mips: Make sure dt memory regions are valid (bnc#1012628).
- netfilter: nf_tables: fix base chain stat rcu_dereference usage
(bnc#1012628).
- watchdog: imx2_wdt: Fix set_timeout for big timeout values
(bnc#1012628).
- watchdog: fix compile time error of pretimeout governors
(bnc#1012628).
- blk-mq: move cancel of requeue_work into blk_mq_release
(bnc#1012628).
- iommu/vt-d: Set intel_iommu_gfx_mapped correctly (bnc#1012628).
- vfio-pci/nvlink2: Fix potential VMA leak (bnc#1012628).
- misc: pci_endpoint_test: Fix test_reg_bar to be updated in
pci_endpoint_test (bnc#1012628).
- PCI: designware-ep: Use aligned ATU window for raising MSI
interrupts (bnc#1012628).
- nvme-pci: unquiesce admin queue on shutdown (bnc#1012628).
- nvme-pci: shutdown on timeout during deletion (bnc#1012628).
- netfilter: nf_flow_table: check ttl value in flow offload data
path (bnc#1012628).
- netfilter: nf_flow_table: fix netdev refcnt leak (bnc#1012628).
- ALSA: hda - Register irq handler after the chip initialization
(bnc#1012628).
- powerpc/pseries: Track LMB nid instead of using device tree
(bnc#1012628).
- arm64: defconfig: Update UFSHCD for Hi3660 soc (bnc#1012628).
- iommu/vt-d: Don't request page request irq under
dmar_global_lock (bnc#1012628).
- nvmem: core: fix read buffer in place (bnc#1012628).
- nvmem: sunxi_sid: Support SID on A83T and H5 (bnc#1012628).
- fuse: retrieve: cap requested size to negotiated max_write
(bnc#1012628).
- nfsd: allow fh_want_write to be called twice (bnc#1012628).
- nfsd: avoid uninitialized variable warning (bnc#1012628).
- vfio: Fix WARNING "do not call blocking ops when !TASK_RUNNING"
(bnc#1012628).
- iommu/arm-smmu-v3: Don't disable SMMU in kdump kernel
(bnc#1012628).
- switchtec: Fix unintended mask of MRPC event (bnc#1012628).
- net: thunderbolt: Unregister ThunderboltIP protocol handler
when suspending (bnc#1012628).
- x86/PCI: Fix PCI IRQ routing table memory leak (bnc#1012628).
- soc/tegra: pmc: Remove reset sysfs entries on error
(bnc#1012628).
- i40e: Queues are reserved despite "Invalid argument" error
(bnc#1012628).
- power: supply: cpcap-battery: Fix signed counter sample register
(bnc#1012628).
- platform/chrome: cros_ec_proto: check for NULL transfer function
(bnc#1012628).
- PCI: keystone: Invoke phy_reset() API before enabling PHY
(bnc#1012628).
- PCI: keystone: Prevent ARM32 specific code to be compiled for
ARM64 (bnc#1012628).
- soc: mediatek: pwrap: Zero initialize rdata in pwrap_init_cipher
(bnc#1012628).
- clk: rockchip: Turn on "aclk_dmac1" for suspend on rk3288
(bnc#1012628).
- usb: ohci-da8xx: disable the regulator if the overcurrent irq
fired (bnc#1012628).
- iommu/vt-d: Flush IOTLB for untrusted device in time
(bnc#1012628).
- soc: rockchip: Set the proper PWM for rk3288 (bnc#1012628).
- arm64: dts: imx8mq: Mark iomuxc_gpr as i.MX6Q compatible
(bnc#1012628).
- ARM: dts: imx51: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx50: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx53: Specify IMX5_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sx: Specify IMX6SX_CLK_IPG as "ahb" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sll: Specify IMX6SLL_CLK_IPG as "ipg" clock to
SDMA (bnc#1012628).
- ARM: dts: imx7d: Specify IMX7D_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6ul: Specify IMX6UL_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6sx: Specify IMX6SX_CLK_IPG as "ipg" clock to SDMA
(bnc#1012628).
- ARM: dts: imx6qdl: Specify IMX6QDL_CLK_IPG as "ipg" clock to
SDMA (bnc#1012628).
- PCI: rpadlpar: Fix leaked device_node references in add/remove
paths (bnc#1012628).
- drm/amd/display: disable link before changing link settings
(bnc#1012628).
- drm/amd/display: Use plane->color_space for dpp if specified
(bnc#1012628).
- ARM: OMAP2+: pm33xx-core: Do not Turn OFF CEFUSE as PPA may
be using it (bnc#1012628).
- pinctrl: pinctrl-intel: move gpio suspend/resume to noirq phase
(bnc#1012628).
- platform/x86: intel_pmc_ipc: adding error handling
(bnc#1012628).
- power: supply: max14656: fix potential use-before-alloc
(bnc#1012628).
- f2fs: fix potential recursive call when enabling data_flush
(bnc#1012628).
- net: hns3: return 0 and print warning when hit duplicate MAC
(bnc#1012628).
- PCI: dwc: Remove default MSI initialization for platform
specific MSI chips (bnc#1012628).
- PCI: rcar: Fix a potential NULL pointer dereference
(bnc#1012628).
- PCI: rcar: Fix 64bit MSI message address handling (bnc#1012628).
- scsi: qla2xxx: Reset the FCF_ASYNC_{SENT|ACTIVE} flags
(bnc#1012628).
- Input: goodix - add GT5663 CTP support (bnc#1012628).
- video: hgafb: fix potential NULL pointer dereference
(bnc#1012628).
- video: imsttfb: fix potential NULL pointer dereferences
(bnc#1012628).
- block, bfq: increase idling for weight-raised queues
(bnc#1012628).
- PCI: xilinx: Check for __get_free_pages() failure (bnc#1012628).
- arm64: dts: qcom: qcs404: Fix regulator supply names
(bnc#1012628).
- gpio: gpio-omap: add check for off wake capable gpios
(bnc#1012628).
- gpio: gpio-omap: limit errata 1.101 handling to wkup domain
gpios only (bnc#1012628).
- ice: Add missing case in print_link_msg for printing flow
control (bnc#1012628).
- media: v4l2-ctrl: v4l2_ctrl_request_setup returns with error
upon failure (bnc#1012628).
- batman-adv: Adjust name for batadv_dat_send_data (bnc#1012628).
- ice: Enable LAN_EN for the right recipes (bnc#1012628).
- ice: Do not set LB_EN for prune switch rules (bnc#1012628).
- dmaengine: idma64: Use actual device for DMA transfers
(bnc#1012628).
- pwm: tiehrpwm: Update shadow register for disabling PWMs
(bnc#1012628).
- media: v4l2-fwnode: Defaults may not override endpoint
configuration in firmware (bnc#1012628).
- ARM: dts: exynos: Always enable necessary APIO_1V8 and ABB_1V8
regulators on Arndale Octa (bnc#1012628).
- pwm: Fix deadlock warning when removing PWM device
(bnc#1012628).
- ARM: exynos: Fix undefined instruction during Exynos5422 resume
(bnc#1012628).
- usb: typec: fusb302: Check vconn is off when we start toggling
(bnc#1012628).
- soc: renesas: Identify R-Car M3-W ES1.3 (bnc#1012628).
- ARM: shmobile: porter: enable R-Car Gen2 regulator quirk
(bnc#1012628).
- gpio: vf610: Do not share irq_chip (bnc#1012628).
- percpu: do not search past bitmap when allocating an area
(bnc#1012628).
- Revert "Bluetooth: Align minimum encryption key size for LE
and BR/EDR connections" (bnc#1012628).
- Revert "drm/nouveau: add kconfig option to turn off nouveau
legacy contexts. (v3)" (bnc#1012628).
- ovl: check the capability before cred overridden (bnc#1012628).
- ovl: support stacked SEEK_HOLE/SEEK_DATA (bnc#1012628).
- ALSA: seq: Cover unsubscribe_port() in list_mutex (bnc#1012628).
- io_uring: fix failure to verify SQ_AFF cpu (bnc#1012628).
- Refresh
patches.suse/RFC-Bluetooth-Check-key-sizes-only-when-Secure-Simple-Pairing-is-enabled.patch.
- commit 0aa1dd8
- Update config files.
The previous commit did not play well. 5.1.9 is broken with =n of that
option, so leave it as =y as it was before 5.1.9.
- commit e68f829
- Update config files.
Set CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT=n, the same as master.
- commit cf58ab1
- Linux 5.1.9 (bnc#1012628).
- ethtool: fix potential userspace buffer overflow (bnc#1012628).
- Fix memory leak in sctp_process_init (bnc#1012628).
- ipv4: not do cache for local delivery if bc_forwarding is
enabled (bnc#1012628).
- ipv6: fix the check before getting the cookie in rt6_get_cookie
(bnc#1012628).
- net: ethernet: ti: cpsw_ethtool: fix ethtool ring param set
(bnc#1012628).
- net: mvpp2: Use strscpy to handle stat strings (bnc#1012628).
- net: rds: fix memory leak in rds_ib_flush_mr_pool (bnc#1012628).
- net: sfp: read eeprom in maximum 16 byte increments
(bnc#1012628).
- packet: unconditionally free po->rollover (bnc#1012628).
- pktgen: do not sleep with the thread lock held (bnc#1012628).
- Revert "fib_rules: return 0 directly if an exactly same rule
exists when NLM_F_EXCL not supplied" (bnc#1012628).
- udp: only choose unbound UDP socket for multicast when not in
a VRF (bnc#1012628).
- ipv6: use READ_ONCE() for inet->hdrincl as in ipv4
(bnc#1012628).
- ipv6: fix EFAULT on sendto with icmpv6 and hdrincl
(bnc#1012628).
- net: aquantia: fix wol configuration not applied sometimes
(bnc#1012628).
- neighbor: Reset gc_entries counter if new entry is released
before insert (bnc#1012628).
- neighbor: Call __ipv4_neigh_lookup_noref in neigh_xmit
(bnc#1012628).
- cls_matchall: avoid panic when receiving a packet before filter
set (bnc#1012628).
- ipmr_base: Do not reset index in mr_table_dump (bnc#1012628).
- net/mlx4_en: ethtool, Remove unsupported SFP EEPROM high pages
query (bnc#1012628).
- net/tls: replace the sleeping lock around RX resync with a
bit lock (bnc#1012628).
- rcu: locking and unlocking need to always be at least barriers
(bnc#1012628).
- habanalabs: fix debugfs code (bnc#1012628).
- ARC: mm: SIGSEGV userspace trying to access kernel virtual
memory (bnc#1012628).
- parisc: Use implicit space register selection for loading the
coherence index of I/O pdirs (bnc#1012628).
- parisc: Fix crash due alternative coding for NP iopdir_fdc bit
(bnc#1012628).
- SUNRPC fix regression in umount of a secure mount (bnc#1012628).
- SUNRPC: Fix a use after free when a server rejects the
RPCSEC_GSS credential (bnc#1012628).
- NFSv4.1: Again fix a race where CB_NOTIFY_LOCK fails to wake
a waiter (bnc#1012628).
- NFSv4.1: Fix bug only first CB_NOTIFY_LOCK is handled
(bnc#1012628).
- fuse: fallocate: fix return with locked inode (bnc#1012628).
- fuse: fix copy_file_range() in the writeback case (bnc#1012628).
- pstore: Set tfm to NULL on free_buf_for_compression
(bnc#1012628).
- pstore/ram: Run without kernel crash dump region (bnc#1012628).
- kbuild: use more portable 'command -v' for cc-cross-prefix
(bnc#1012628).
- memstick: mspro_block: Fix an error code in
mspro_block_issue_req() (bnc#1012628).
- mmc: tmio: fix SCC error handling to avoid false positive CRC
error (bnc#1012628).
- mmc: sdhci_am654: Fix SLOTTYPE write (bnc#1012628).
- x86/power: Fix 'nosmt' vs hibernation triple fault during resume
(bnc#1012628).
- x86/insn-eval: Fix use-after-free access to LDT entry
(bnc#1012628).
- i2c: xiic: Add max_read_len quirk (bnc#1012628).
- s390/mm: fix address space detection in exception handling
(bnc#1012628).
- nvme-rdma: fix queue mapping when queue count is limited
(bnc#1012628).
- xen-blkfront: switch kcalloc to kvcalloc for large array
allocation (bnc#1012628).
- MIPS: Bounds check virt_addr_valid (bnc#1012628).
- MIPS: pistachio: Build uImage.gz by default (bnc#1012628).
- genwqe: Prevent an integer overflow in the ioctl (bnc#1012628).
- test_firmware: Use correct snprintf() limit (bnc#1012628).
- drm/rockchip: fix fb references in async update (bnc#1012628).
- drm/vc4: fix fb references in async update (bnc#1012628).
- drm/gma500/cdv: Check vbt config bits when detecting lvds panels
(bnc#1012628).
- drm/msm: fix fb references in async update (bnc#1012628).
- drm: add non-desktop quirk for Valve HMDs (bnc#1012628).
- drm/nouveau: add kconfig option to turn off nouveau legacy
contexts. (v3) (bnc#1012628).
- drm: add non-desktop quirks to Sensics and OSVR headsets
(bnc#1012628).
- drm: Fix timestamp docs for variable refresh properties
(bnc#1012628).
- drm/amdgpu/psp: move psp version specific function pointers
to early_init (bnc#1012628).
- drm/radeon: prefer lower reference dividers (bnc#1012628).
- drm/amdgpu: remove ATPX_DGPU_REQ_POWER_FOR_DISPLAYS check when
hotplug-in (bnc#1012628).
- drm/i915: Fix I915_EXEC_RING_MASK (bnc#1012628).
- drm/amdgpu/soc15: skip reset on init (bnc#1012628).
- drm/amd/display: Add ASICREV_IS_PICASSO (bnc#1012628).
- drm/amdgpu: fix ring test failure issue during s3 in vce 3.0
(V2) (bnc#1012628).
- drm/i915/fbc: disable framebuffer compression on GeminiLake
(bnc#1012628).
- drm/i915/gvt: emit init breadcrumb for gvt request
(bnc#1012628).
- drm: don't block fb changes for async plane updates
(bnc#1012628).
- drm/i915/gvt: Initialize intel_gvt_gtt_entry in stack
(bnc#1012628).
- drm/amd: fix fb references in async update (bnc#1012628).
- ipv4: Define __ipv4_neigh_lookup_noref when CONFIG_INET is
disabled (bnc#1012628).
- commit 8904439
- Revert "drm: allow render capable master with DRM_AUTH ioctls"
(fix radv check).
- commit 3ca4077
- drm/i915: Maintain consistent documentation subsection ordering
(fix kernel-doc).
- Delete
patches.rpmify/Revert-doc-Cope-with-the-deprecation-of-AutoReporter.patch.
Use usptream fix instead of revert.
- commit 4e8aae9
- scsi: mpt3sas_ctl: fix double-fetch bug in _ctl_ioctl_main()
(bsc#1136922 cve-2019-12456).
- commit 0c3fc9f
- Revert "doc: Cope with the deprecation of AutoReporter"
(fix kernel-doc).
- commit 1c5c2b4
- Linux 5.1.8 (bnc#1012628).
- sparc64: Fix regression in non-hypervisor TLB flush xcall
(bnc#1012628).
- include/linux/bitops.h: sanitize rotate primitives
(bnc#1012628).
- xhci: update bounce buffer with correct sg num (bnc#1012628).
- xhci: Use %zu for printing size_t type (bnc#1012628).
- xhci: Convert xhci_handshake() to use
readl_poll_timeout_atomic() (bnc#1012628).
- usb: xhci: avoid null pointer deref when bos field is NULL
(bnc#1012628).
- usbip: usbip_host: fix BUG: sleeping function called from
invalid context (bnc#1012628).
- usbip: usbip_host: fix stub_dev lock context imbalance
regression (bnc#1012628).
- USB: Fix slab-out-of-bounds write in usb_get_bos_descriptor
(bnc#1012628).
- USB: sisusbvga: fix oops in error path of sisusb_probe
(bnc#1012628).
- USB: Add LPM quirk for Surface Dock GigE adapter (bnc#1012628).
- USB: rio500: refuse more than one device at a time
(bnc#1012628).
- USB: rio500: fix memory leak in close after disconnect
(bnc#1012628).
- media: usb: siano: Fix general protection fault in smsusb
(bnc#1012628).
- media: usb: siano: Fix false-positive "uninitialized variable"
warning (bnc#1012628).
- media: smsusb: better handle optional alignment (bnc#1012628).
- brcmfmac: fix NULL pointer derefence during USB disconnect
(bnc#1012628).
- scsi: zfcp: fix missing zfcp_port reference put on -EBUSY from
port_remove (bnc#1012628).
- scsi: zfcp: fix to prevent port_remove with pure auto scan LUNs
(only sdevs) (bnc#1012628).
- tracing: Avoid memory leak in predicate_parse() (bnc#1012628).
- Btrfs: fix wrong ctime and mtime of a directory after log replay
(bnc#1012628).
- Btrfs: fix race updating log root item during fsync
(bnc#1012628).
- Btrfs: fix fsync not persisting changed attributes of a
directory (bnc#1012628).
- btrfs: correct zstd workspace manager lock to use spin_lock_bh()
(bnc#1012628).
- btrfs: qgroup: Check bg while resuming relocation to avoid
NULL pointer dereference (bnc#1012628).
- Btrfs: incremental send, fix file corruption when no-holes
feature is enabled (bnc#1012628).
- btrfs: reloc: Also queue orphan reloc tree for cleanup to
avoid BUG_ON() (bnc#1012628).
- iio: dac: ds4422/ds4424 fix chip verification (bnc#1012628).
- iio: adc: ads124: avoid buffer overflow (bnc#1012628).
- iio: adc: modify NPCM ADC read reference voltage (bnc#1012628).
- iio: adc: ti-ads8688: fix timestamp is not updated in buffer
(bnc#1012628).
- s390/crypto: fix gcm-aes-s390 selftest failures (bnc#1012628).
- s390/crypto: fix possible sleep during spinlock aquired
(bnc#1012628).
- KVM: PPC: Book3S HV: XIVE: Do not clear IRQ data of passthrough
interrupts (bnc#1012628).
- KVM: PPC: Book3S HV: Fix lockdep warning when entering guest
on POWER9 (bnc#1012628).
- KVM: PPC: Book3S HV: Restore SPRG3 in kvmhv_p9_guest_entry()
(bnc#1012628).
- powerpc/perf: Fix MMCRA corruption by bhrb_filter (bnc#1012628).
- powerpc/kexec: Fix loading of kernel + initramfs with
kexec_file_load() (bnc#1012628).
- ALSA: line6: Assure canceling delayed work at disconnection
(bnc#1012628).
- ALSA: hda/realtek - Set default power save node to 0
(bnc#1012628).
- ALSA: hda/realtek - Improve the headset mic for Acer Aspire
laptops (bnc#1012628).
- KVM: s390: Do not report unusabled IDs via KVM_CAP_MAX_VCPU_ID
(bnc#1012628).
- drm/nouveau/i2c: Disable i2c bus access after ->fini()
(bnc#1012628).
- i2c: mlxcpld: Fix wrong initialization order in probe
(bnc#1012628).
- i2c: synquacer: fix synquacer_i2c_doxfer() return value
(bnc#1012628).
- tty: serial: msm_serial: Fix XON/XOFF (bnc#1012628).
- tty: max310x: Fix external crystal register setup (bnc#1012628).
- mm, memcg: consider subtrees in memory.events (bnc#1012628).
- kasan: initialize tag to 0xff in __kasan_kmalloc (bnc#1012628).
- kernel/signal.c: trace_signal_deliver when signal_group_exit
(bnc#1012628).
- signal/arm64: Use force_sig not force_sig_fault for SIGKILL
(bnc#1012628).
- mm, compaction: make sure we isolate a valid PFN (bnc#1012628).
- arm64: Fix the arm64_personality() syscall wrapper redirection
(bnc#1012628).
- docs: Fix conf.py for Sphinx 2.0 (bnc#1012628).
- doc: Cope with the deprecation of AutoReporter (bnc#1012628).
- doc: Cope with Sphinx logging deprecations (bnc#1012628).
- x86/ima: Check EFI_RUNTIME_SERVICES before using (bnc#1012628).
- ima: fix wrong signed policy requirement when not appraising
(bnc#1012628).
- ima: show rules with IMA_INMASK correctly (bnc#1012628).
- evm: check hash algorithm passed to init_desc() (bnc#1012628).
- clk: imx: imx8mm: fix int pll clk gate (bnc#1012628).
- vt/fbcon: deinitialize resources in visual_init() after failed
memory allocation (bnc#1012628).
- serial: sh-sci: disable DMA for uart_console (bnc#1012628).
- staging: vc04_services: prevent integer overflow in
create_pagelist() (bnc#1012628).
- staging: wlan-ng: fix adapter initialization failure
(bnc#1012628).
- cifs: fix memory leak of pneg_inbuf on -EOPNOTSUPP ioctl case
(bnc#1012628).
- CIFS: cifs_read_allocate_pages: don't iterate through whole
page array on ENOMEM (bnc#1012628).
- Revert "lockd: Show pid of lockd for remote locks"
(bnc#1012628).
- gcc-plugins: Fix build failures under Darwin host (bnc#1012628).
- drm/tegra: gem: Fix CPU-cache maintenance for BO's allocated
using get_pages() (bnc#1012628).
- drm/vmwgfx: Fix user space handle equal to zero (bnc#1012628).
- drm/vmwgfx: Fix compat mode shader operation (bnc#1012628).
- drm/vmwgfx: Don't send drm sysfs hotplug events on initial
master set (bnc#1012628).
- drm/sun4i: Fix sun8i HDMI PHY clock initialization
(bnc#1012628).
- drm/sun4i: Fix sun8i HDMI PHY configuration for > 148.5 MHz
(bnc#1012628).
- drm/imx: ipuv3-plane: fix atomic update status query for
non-plus i.MX6Q (bnc#1012628).
- drm/fb-helper: generic: Call drm_client_add() after setup is
done (bnc#1012628).
- drm/atomic: Wire file_priv through for property changes
(bnc#1012628).
- drm: Expose "FB_DAMAGE_CLIPS" property to atomic aware
user-space only (bnc#1012628).
- drm/rockchip: shutdown drm subsystem on shutdown (bnc#1012628).
- drm/lease: Make sure implicit planes are leased (bnc#1012628).
- drm/cma-helper: Fix drm_gem_cma_free_object() (bnc#1012628).
- Revert "x86/build: Move _etext to actual end of .text"
(bnc#1012628).
- x86/kprobes: Set instruction page as executable (bnc#1012628).
- commit ed4965b
- s390: drop meaningless 'targets' from tools Makefile (s390
kmp build fix).
- commit c8cc0ca
==== kubic-control ====
Version update (0.5.1 -> 0.6.1)
Subpackages: kubicctl kubicd
- Update to version 0.6.1
- Store kubeadm join token for 23 hours to not create too many for every single node
- Fix kubernetes version argument for kubeadm
- Open rbac.conf with every call, else we don't see our own changes
- Don't build on i586 to make some scripts happy...
- Update to version 0.6.0
- Add --adv-addr option to kubicctl init
- Refactor code
- Many, many bug fixes
- Add requires to the k8s-yaml files we really always need
==== libcontainers-common ====
- Update to libpod v1.4.0
- The podman checkpoint and podman restore commands can now be
used to migrate containers between Podman installations on
different systems
- The podman cp command now supports a pause flag to pause
containers while copying into them
- The remote client now supports a configuration file for
pre-configuring connections to remote Podman installations
- Fixed CVE-2019-10152 - The podman cp command improperly
dereferenced symlinks in host context
- Fixed a bug where podman commit could improperly set
environment variables that contained = characters
- Fixed a bug where rootless Podman would sometimes fail to start
containers with forwarded ports
- Fixed a bug where podman version on the remote client could
segfault
- Fixed a bug where podman container runlabel would use
/proc/self/exe instead of the path of the Podman command when
printing the command being executed
- Fixed a bug where filtering images by label did not work
- Fixed a bug where specifying a bing mount or tmpfs mount over
an image volume would cause a container to be unable to start
- Fixed a bug where podman generate kube did not work with
containers with named volumes
- Fixed a bug where rootless Podman would receive permission
denied errors accessing conmon.pid
- Fixed a bug where podman cp with a folder specified as target
would replace the folder, as opposed to copying into it
- Fixed a bug where rootless Podman commands could double-unlock
a lock, causing a crash
- Fixed a bug where Podman incorrectly set tmpcopyup on /dev/
mounts, causing errors when using the Kata containers runtime
- Fixed a bug where podman exec would fail on older kernels
- The podman commit command is now usable with the Podman remote
client
- The --signature-policy flag (used with several image-related
commands) has been deprecated
- The podman unshare command now defines two environment
variables in the spawned shell: CONTAINERS_RUNROOT and
CONTAINERS_GRAPHROOT, pointing to temporary and permanent
storage for rootless containers
- Updated vendored containers/storage and containers/image
libraries with numerous bugfixes
- Updated vendored Buildah to v1.8.3
- Podman now requires Conmon v0.2.0
- The podman cp command is now aliased as podman container cp
- Rootless Podman will now default init_path using root Podman's
configuration files (/etc/containers/libpod.conf and
/usr/share/containers/libpod.conf) if not overridden in the
rootless configuration
- Update to image v1.5.1
- Vendor in latest containers/storage
- docker/docker_client: Drop redundant Domain(ref.ref) call
- pkg/blobinfocache: Split implementations into subpackages
- copy: progress bar: show messages on completion
- docs: rename manpages to *.5.command
- add container-certs.d.md manpage
- pkg/docker/config: Bring auth tests from
docker/docker_client_test
- Don't allocate a sync.Mutex separately
- Update to storage v1.12.10
- Add function to parse out mount options from graphdriver
- Merge the disparate parts of all of the Unix-like lockfiles
- Fix unix-but-not-Linux compilation
- Return XDG_RUNTIME_DIR as RootlessRuntimeDir if set
- Cherry-pick moby/moby #39292 for CVE-2018-15664 fixes
- lockfile: add RecursiveLock() API
- Update generated files
- Fix crash on tesing of aufs code
- Let consumers know when Layers and Images came from read-only stores
- chown: do not change owner for the mountpoint
- locks: correctly mark updates to the layers list
- CreateContainer: don't worry about mapping layers unless necessary
- docs: fix manpage for containers-storage.conf
- docs: sort configuration options alphabetically
- docs: document OSTree file deduplication
- Add missing options to man page for containers-storage
- overlay: use the layer idmapping if present
- vfs: prefer layer custom idmappings
- layers: propagate down the idmapping settings
- Recreate symlink when not found
- docs: fix manpage for configuration file
- docs: add special handling for manpages in sect 5
- overlay: fix single-lower test
- Recreate symlink when not found
- overlay: propagate errors from mountProgram
- utils: root in a userns uses global conf file
- Fix handling of additional stores
- Correctly check permissions on rootless directory
- Fix possible integer overflow on 32bit builds
- Evaluate device path for lvm
- lockfile test: make concurrent RW test determinisitc
- lockfile test: make concurrent read tests deterministic
- drivers.DirCopy: fix filemode detection
- storage: move the logic to detect rootless into utils.go
- Don't set (struct flock).l_pid
- Improve documentation of getLockfile
- Rename getLockFile to createLockerForPath, and document it
- Add FILES section to containers-storage.5 man page
- add digest locks
- drivers/copy: add a non-cgo fallback
- Add default SLES mounts for container-suseconnect usage
==== libseccomp ====
Version update (2.4.0 -> 2.4.1)
- Update to new upstream release 2.4.1
* Fix a BPF generation bug where the optimizer mistakenly
identified duplicate BPF code blocks.
==== libsolv ====
Version update (0.7.4 -> 0.7.5)
- make cleandeps jobs on patterns work [bnc#1137977]
- fix favorq leaking between solver runs if the solver is reused
- fix SOLVER_FLAG_FOCUS_BEST updateing packages without reason
- be more correct with multiversion packages that obsolete their
own name [bnc#1127155]
- allow building with swig-4.0.0 [bnc#1135749]
- bump version to 0.7.5
- always prefer to stay with the same package name if there are
multiple alternatives [bnc#1131823]
==== libzypp ====
Version update (17.11.4 -> 17.12.0)
- Drop unused InterProcessMutex class and test
- Drop unused WebpinResult class and test
- Give posttrans script a parameter of 0 (issue #168)
- Use CURL_HTTP_VERSION_2TLS if available (fixes #141)
- version 17.12.0 (12)
==== microos-tools ====
Version update (1.0+git20190218.9e72dd7 -> 1.0+git20190611.6211f74)
- Update to version 1.0+git20190611.6211f74:
* Rename 51-corefiles.conf to 30-corefiles.conf, so that an user
can override it by installing telemectrics-client or
systemd-coredump.
==== ncurses ====
Subpackages: libncurses6 ncurses-utils terminfo terminfo-base
- Add ncurses patch 20190609
+ add mintty, mintty-direct (adapted from patch by Thomas Wolff).
Some of the suggested user-defined capabilities are commented-out,
to allow builds with ncurses 5.9 and 6.0
+ add Smol/Rmol for tmux, vte-2018 (patch by Nicholas Marriott).
+ add rs1 to konsole, mlterm -TD
+ modify _nc_merge_entry() to make a copy of the data which it merges,
to avoid modifying the source-data when aligning extended names.
- Add ncurses patch 20190601
+ modify an internal call to vid_puts to pass extended color pairs
e.g., from tty_update.c and lib_mvcur.c (report by Niegodziwy Beru).
+ improve manual page description of init_tabs capability and TABSIZE
variable.
- Add ncurses patch 20190525
+ modify reset_cmd.c to allow for tabstops at intervals other than 8
(report by Vincent Huisman).
- Add ncurses patch 20190518
+ update xterm-new to xterm patch #345 -TD
+ add/use xterm+keypad in xterm-new (report by Alain D D Williams) -TD
+ update terminator entry -TD
+ remove hard-tabs from ti703 (report by Robert Clausecker)
+ mention meml/memu/box1 in user_caps manual page.
+ mention user_caps.5 in tic and infocmp manual pages.
- Adopt the patches ncurses-5.9-ibm327x.dif and ncurses-6.1.dif
==== permissions ====
Version update (1550_20190429 -> 1550_20190521)
Subpackages: chkstat permissions-config
- Update to version 20190521:
* singluarity: Add starter-suid for version 3.2.0
* adjust settings for amanda to current binary layout
- Move BuildRequires: back to main package
- Moved requires to subpackages (bsc#1137257)
==== python-base ====
Subpackages: libpython2_7-1_0
- Set _lto_cflags to nil as it will prevent to propage LTO
for Python modules that are built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
==== salt ====
Subpackages: python3-salt salt-master salt-minion
- Provide the missing features required for Yomi (Yet one more installer)
- Added:
* provide-the-missing-features-required-for-yomi-yet-o.patch
==== systemd-presets-common-SUSE ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== sysvinit ====
Version update (2.90 -> 2.95)
- Remove logsave as well as the manual page as those as part of
package e2fsprogs already
- Update to sysvinit 2.95
* new logsave helper
- Update to startpar-0.63
* move startpar from /sbin to /bin
- Port our patches
* startpar-0.58.dif
* sysvinit-2.88dsf-suse.patch
* sysvinit-2.90-no-kill.patch
* sysvinit-2.90.dif
==== zlib ====
- Do not enable the previous patchset on s390 but just s390x
bsc#1137624
- Add patchset for s390 improvements jsc#SLE-5807 bsc#1136717:
* 410.patch
==== zypper ====
Version update (1.14.27 -> 1.14.28)
- man: split '--with[out]' like options to ease searching.
- Unhide 'ps' command in help
- Add option to show more conflict information
- Rephrased `zypper ps` hint (bsc#859480)
- Fix repo refresh not returning 106-ZYPPER_EXIT_INF_REPOS_SKIPPED
if --root is used (bsc#1134226)
- Fix unknown package handling in zypper install (fixes bsc#1127608)
- Fix the package build failure with CMake 3.14.
- Re-show progress bar after pressing retry upon install error
(bsc#1131113)
- version 1.14.28
- Fix build with CMake >= 3.14
Starting with CMake 3.14, EXCLUDE_FROM_ALL now spreads from
directories to targets. 'make -C someSubdir' when 'someSubdir'
uses the 'EXCLUDE_FROM_ALL' keyword does nothing.
- Remove unneeded CMake commands.
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
apparmor (2.13.2 -> 2.13.3)
fuse3 (3.5.0 -> 3.6.1)
ipset (7.1 -> 7.2)
libapparmor (2.13.2 -> 2.13.3)
lz4 (1.8.3 -> 1.9.1)
vim (8.1.1467 -> 8.1.1561)
xen
=== Details ===
==== apparmor ====
Version update (2.13.2 -> 2.13.3)
Subpackages: apparmor-abstractions apparmor-parser apparmor-profiles apparmor-utils perl-apparmor python3-apparmor
- update to 2.13.3
- profile updates for dnsmasq, dovecot, identd, syslog-ng
- new "lsb_release" profile (only used when using "Px -> lsb_release")
- fix buggy syntax in tunables/share
- several abstraction updates
- parser: fix "Px -> foo-bar" (the "-" was rejected before)
- several bugfixes in aa-genprof and aa-logprof
- see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3
for the detailed upstream changelog
- drop upstream(ed) patches:
- apparmor-nameservice-resolv-conf-link.patch
- profile_filename_cornercase.diff
- dnsmasq-libvirtd.diff
- dnsmasq-revert-alternation.diff
- usrmerge-fixes.diff
- libapparmor-swig-4.diff
- re-number remaining patches
==== fuse3 ====
Version update (3.5.0 -> 3.6.1)
- Disable LTO due to symbol versioning (boo#1138803).
- Update to version 3.6.1
* Fixed version number (release 3.6.0 was shipped with a declared
version of 3.0.0).
- Update to version 3.6.0
* Added a new example (passthrough_hp). The functionality is
similar to passthrough_ll, but the implementation focuses
on performance and correctness rather than simplicity.
* Added support for fuse kernel feature max_pages which allows
to increase the maximum number of pages that can be used per
request. This feature was introduced in kernel 4.20.
max_pages is set based on the value in max_write.
By default max_write will be 1MiB now for kernels that
support max_pages. If you want smaller buffers or writes
you have to set max_write manually.
==== ipset ====
Version update (7.1 -> 7.2)
Subpackages: libipset13
- Update to new upstream release 7.2
* ipset: Fix memory accounting for hash types on resize
==== libapparmor ====
Version update (2.13.2 -> 2.13.3)
- update to AppArmor 2.13.1
- some fixes in cache handling
- see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3
for the detailed upstream changelog
==== lz4 ====
Version update (1.8.3 -> 1.9.1)
- Update to new upstream release 1.9.1
* Decompression speed was improved by about 12% (x86/x64).
* New option `lz4 --list` to inspect the block type, checksum
information, compressed and decompressed sizes (if present). The
command is limited to single-frame files for the time being.
==== vim ====
Version update (8.1.1467 -> 8.1.1561)
Subpackages: vim-data-common
- Updated to version 8.1.1561, fixes the following problems
- refreshed patches:
disable-unreliable-tests.patch
vim-7.4-highlight_fstab.patch
* Cscope test fails.
* The generated desktop files may be invalid.
* No test for checking the cursor style response.
* New Unicode character U32FF missing from double-width table.
* 'background' not correctly set for 2-digit rgb termresponse.
* Add_termcap_entry() is not tested.
* New resolve() implementation causes problem for plugins.
* 'ttybuiltin' is not tested.
* Search string not displayed when 'rightleft' is set.
* No statistics displayed after running tests.
* Test summary fails in the tiny version.
* Still an error when running tests with the tiny version.
* Change included for debugging only.
* Length for two-digit rgb termresponse is off by one.
* No test for wincol() depending on the 'number' option.
* Skipped tests are not properly listed.
* Some tests are slow.
* Double free when garbage_collect() is used in autocommand.
* A listener change is merged even when it adds a line. (Paul Jolly)
* Older msgfmt cannot generate proper .desktop file.
* Summary of tests has incorrect failed count.
* Sign order wrong when priority was changed.
* When a single test fails the exit code is not set. (Daniel Hahler)
* When skipping over code after an exception was thrown expression evaluation
is aborted after a function call. (Ingo Karkat)
* Redrawing with popups is slow and causes flicker.
* Build failure.
* Memory access error.
* Popup window height is not recomputed.
* Accessing memory beyond allocated space.
* ":write" increments b:changedtick even though nothing changed. (Daniel
Hahler)
* Ruler not updated after popup window was removed.
* Wrong shell command when building with VIMDLL and "!" in 'guioptions'.
* New behavior of b:changedtick not tested.
* Cannot play any sound.
* Sound test fails on Travis.
* Sound test still fails on Travis.
* Running "make clean" twice gives errors.
* Syntax error in Travis config.
* Sound test still fails on Travis.
* Sound keeps failing on Travis.
* Cmdline_row can become negative, causing a crash.
* A plugin cannot easily expand a command like done internally.
* Matches in a popup window are not displayed properly.
* ch_evalexpr() hangs when used recursively. (Paul Jolly)
* All popup functionality is in functions, except :popupclear.
* Memory leak reported for sound when build with EXITFREE.
* Time reported for a test measured wrong.
* When a popup changes all windows are redrawn.
* Crash when setting 'columns' while a popup is visible.
* 'backupskip' may contain duplicates.
* Popup windows are ignored when dealing with mouse position.
* When a popup window is closed the buffer remains.
* Popup_notification() not implemented yet.
* Cannot show range of buffer lines in popup window.
* Tests are silently skipped.
* Cannot move a popup window with the mouse.
* No numerical value for the patchlevel.
* When moving a popup window over the command line it is not redrawn.
* Popup_any_visible() is unused.
* Libcanberra is linked with even when not used.
* Travis config is not optimal.
* Clipboard type name is inconsistent.
* Build fails.
* Modeless selection in popup window selects too much.
* Popup select test fails on Mac.
* Popup select test still fails on Mac.
* Using "tab" for popup window can be confusing.
* Cannot specify highlighting for notifications.
* Not easy to define a variable and lock it.
* Cannot build without the +eval feature.
* Check for ASAN is not reliable.
* An OptionSet autocommand does not get enough info.
* Const test fails with small features.
* Some balloon tests don't run when they can.
* When the screen is to small there is no message about that. (Daniel Hahler)
* In some tests 'tags' is set but not restored. (Daniel Hahler)
* Functionality of bt_nofile() is confusing.
* Popup_dialog() is not implemented.
* Quickfix test fails.
* When a popup has left padding text may be cut off.
* Warning for shadowing popup_dragwin. (Dominique Pelle)
* Cursor position is wrong after sign column appears or disappears. (Yegappan
Lakshmanan)
* Not easy to change the text in a popup window.
* Docs and tests for :const can be improved.
* NOT_IN_POPUP_WINDOW is confusing. (Andy Massimino)
* The command displayed to show a failing screenshot does not include the
"testdir" directory.
* Compiler warning for unused variables in tiny version. (Tony Mechelynck)
* Popup_menu() and popup_filter_menu() are not implemented yet.
* Popup window title property not implemented yet.
* Popup window hidden option not implemented yet.
* Popup_setoptions() is not implemented yet.
==== xen ====
- spec: xen-tools: require matching version of xen package
bsc#1137471
- Remove two stale patches
xen.build-compare.man.patch
xenpaging.doc.patch
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
apparmor (2.13.2 -> 2.13.3)
fuse3 (3.5.0 -> 3.6.1)
ipset (7.1 -> 7.2)
libapparmor (2.13.2 -> 2.13.3)
lz4 (1.8.3 -> 1.9.1)
vim (8.1.1467 -> 8.1.1561)
xen
=== Details ===
==== apparmor ====
Version update (2.13.2 -> 2.13.3)
Subpackages: apparmor-abstractions apparmor-parser apparmor-profiles apparmor-utils perl-apparmor python3-apparmor
- update to 2.13.3
- profile updates for dnsmasq, dovecot, identd, syslog-ng
- new "lsb_release" profile (only used when using "Px -> lsb_release")
- fix buggy syntax in tunables/share
- several abstraction updates
- parser: fix "Px -> foo-bar" (the "-" was rejected before)
- several bugfixes in aa-genprof and aa-logprof
- see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3
for the detailed upstream changelog
- drop upstream(ed) patches:
- apparmor-nameservice-resolv-conf-link.patch
- profile_filename_cornercase.diff
- dnsmasq-libvirtd.diff
- dnsmasq-revert-alternation.diff
- usrmerge-fixes.diff
- libapparmor-swig-4.diff
- re-number remaining patches
==== fuse3 ====
Version update (3.5.0 -> 3.6.1)
- Disable LTO due to symbol versioning (boo#1138803).
- Update to version 3.6.1
* Fixed version number (release 3.6.0 was shipped with a declared
version of 3.0.0).
- Update to version 3.6.0
* Added a new example (passthrough_hp). The functionality is
similar to passthrough_ll, but the implementation focuses
on performance and correctness rather than simplicity.
* Added support for fuse kernel feature max_pages which allows
to increase the maximum number of pages that can be used per
request. This feature was introduced in kernel 4.20.
max_pages is set based on the value in max_write.
By default max_write will be 1MiB now for kernels that
support max_pages. If you want smaller buffers or writes
you have to set max_write manually.
==== ipset ====
Version update (7.1 -> 7.2)
Subpackages: libipset13
- Update to new upstream release 7.2
* ipset: Fix memory accounting for hash types on resize
==== libapparmor ====
Version update (2.13.2 -> 2.13.3)
- update to AppArmor 2.13.1
- some fixes in cache handling
- see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3
for the detailed upstream changelog
==== lz4 ====
Version update (1.8.3 -> 1.9.1)
- Update to new upstream release 1.9.1
* Decompression speed was improved by about 12% (x86/x64).
* New option `lz4 --list` to inspect the block type, checksum
information, compressed and decompressed sizes (if present). The
command is limited to single-frame files for the time being.
==== vim ====
Version update (8.1.1467 -> 8.1.1561)
Subpackages: vim-data-common
- Updated to version 8.1.1561, fixes the following problems
- refreshed patches:
disable-unreliable-tests.patch
vim-7.4-highlight_fstab.patch
* Cscope test fails.
* The generated desktop files may be invalid.
* No test for checking the cursor style response.
* New Unicode character U32FF missing from double-width table.
* 'background' not correctly set for 2-digit rgb termresponse.
* Add_termcap_entry() is not tested.
* New resolve() implementation causes problem for plugins.
* 'ttybuiltin' is not tested.
* Search string not displayed when 'rightleft' is set.
* No statistics displayed after running tests.
* Test summary fails in the tiny version.
* Still an error when running tests with the tiny version.
* Change included for debugging only.
* Length for two-digit rgb termresponse is off by one.
* No test for wincol() depending on the 'number' option.
* Skipped tests are not properly listed.
* Some tests are slow.
* Double free when garbage_collect() is used in autocommand.
* A listener change is merged even when it adds a line. (Paul Jolly)
* Older msgfmt cannot generate proper .desktop file.
* Summary of tests has incorrect failed count.
* Sign order wrong when priority was changed.
* When a single test fails the exit code is not set. (Daniel Hahler)
* When skipping over code after an exception was thrown expression evaluation
is aborted after a function call. (Ingo Karkat)
* Redrawing with popups is slow and causes flicker.
* Build failure.
* Memory access error.
* Popup window height is not recomputed.
* Accessing memory beyond allocated space.
* ":write" increments b:changedtick even though nothing changed. (Daniel
Hahler)
* Ruler not updated after popup window was removed.
* Wrong shell command when building with VIMDLL and "!" in 'guioptions'.
* New behavior of b:changedtick not tested.
* Cannot play any sound.
* Sound test fails on Travis.
* Sound test still fails on Travis.
* Running "make clean" twice gives errors.
* Syntax error in Travis config.
* Sound test still fails on Travis.
* Sound keeps failing on Travis.
* Cmdline_row can become negative, causing a crash.
* A plugin cannot easily expand a command like done internally.
* Matches in a popup window are not displayed properly.
* ch_evalexpr() hangs when used recursively. (Paul Jolly)
* All popup functionality is in functions, except :popupclear.
* Memory leak reported for sound when build with EXITFREE.
* Time reported for a test measured wrong.
* When a popup changes all windows are redrawn.
* Crash when setting 'columns' while a popup is visible.
* 'backupskip' may contain duplicates.
* Popup windows are ignored when dealing with mouse position.
* When a popup window is closed the buffer remains.
* Popup_notification() not implemented yet.
* Cannot show range of buffer lines in popup window.
* Tests are silently skipped.
* Cannot move a popup window with the mouse.
* No numerical value for the patchlevel.
* When moving a popup window over the command line it is not redrawn.
* Popup_any_visible() is unused.
* Libcanberra is linked with even when not used.
* Travis config is not optimal.
* Clipboard type name is inconsistent.
* Build fails.
* Modeless selection in popup window selects too much.
* Popup select test fails on Mac.
* Popup select test still fails on Mac.
* Using "tab" for popup window can be confusing.
* Cannot specify highlighting for notifications.
* Not easy to define a variable and lock it.
* Cannot build without the +eval feature.
* Check for ASAN is not reliable.
* An OptionSet autocommand does not get enough info.
* Const test fails with small features.
* Some balloon tests don't run when they can.
* When the screen is to small there is no message about that. (Daniel Hahler)
* In some tests 'tags' is set but not restored. (Daniel Hahler)
* Functionality of bt_nofile() is confusing.
* Popup_dialog() is not implemented.
* Quickfix test fails.
* When a popup has left padding text may be cut off.
* Warning for shadowing popup_dragwin. (Dominique Pelle)
* Cursor position is wrong after sign column appears or disappears. (Yegappan
Lakshmanan)
* Not easy to change the text in a popup window.
* Docs and tests for :const can be improved.
* NOT_IN_POPUP_WINDOW is confusing. (Andy Massimino)
* The command displayed to show a failing screenshot does not include the
"testdir" directory.
* Compiler warning for unused variables in tiny version. (Tony Mechelynck)
* Popup_menu() and popup_filter_menu() are not implemented yet.
* Popup window title property not implemented yet.
* Popup window hidden option not implemented yet.
* Popup_setoptions() is not implemented yet.
==== xen ====
- spec: xen-tools: require matching version of xen package
bsc#1137471
- Remove two stale patches
xen.build-compare.man.patch
xenpaging.doc.patch
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
grub2
iputils
kexec-tools (2.0.18 -> 2.0.19)
openssl (1.1.1b -> 1.1.1c)
openssl-1_1 (1.1.1b -> 1.1.1c)
python-Babel (2.6.0 -> 2.7.0)
python-cryptography (2.6.1 -> 2.7)
python-rpm-macros (20190430.5260267 -> 20190610.2ee3233)
python-six
python-urllib3 (1.24.2 -> 1.25.3)
python3 (3.7.2 -> 3.7.3)
python3-base (3.7.2 -> 3.7.3)
systemd-presets-branding-MicroOS
zstd
=== Details ===
==== grub2 ====
Subpackages: grub2-i386-pc grub2-snapper-plugin grub2-x86_64-efi
- Avoid high resolution when trying to keep current mode (bsc#1133842)
* grub2-video-limit-the-resolution-for-fixed-bimap-font.patch
- Make GRUB_SAVEDEFAULT working with btrfs (bsc#1128592)
* grub2-grubenv-in-btrfs-header.patch
==== iputils ====
- Add patch ping-Fix-unwanted-bell-on-unreachable-address.patch (boo#1135118)
==== kexec-tools ====
Version update (2.0.18 -> 2.0.19)
- Bump to version 2.0.19
Changelog: http://git.kernel.org/cgit/utils/kernel/kexec/kexec-tools.git/log/?id=refs/…
==== openssl ====
Version update (1.1.1b -> 1.1.1c)
- Update to 1.1.1c release
==== openssl-1_1 ====
Version update (1.1.1b -> 1.1.1c)
Subpackages: libopenssl1_1
- Use upstream patch for the locale crash (bsc#1135550)
* https://github.com/openssl/openssl/pull/8966
- delete openssl-fix_underflow_in_errstr_handling.patch
- add 0001-build_SYS_str_reasons-Fix-a-crash-caused-by-overlong.patch
- Add s390x vectorized support for ChaCha20 and Poly1305
(jsc#SLE-6126, jsc#SLE-6129)
* 0001-s390x-assembly-pack-perlasm-support.patch
* 0002-crypto-chacha-asm-chacha-s390x.pl-add-vx-code-path.patch
* 0003-crypto-poly1305-asm-poly1305-s390x.pl-add-vx-code-pa.patch
* 0004-s390x-assembly-pack-fix-formal-interface-bug-in-chac.patch
* 0005-s390x-assembly-pack-import-chacha-from-cryptogams-re.patch
* 0006-s390x-assembly-pack-import-poly-from-cryptogams-repo.patch
- delete 0001-crypto-poly1305-asm-poly1305-s390x.pl-add-vx-code-pa.patch
- Update to 1.1.1c (bsc#1133925, jsc#SLE-6430)
* Prevent over long nonces in ChaCha20-Poly1305 (CVE-2019-1543)
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input
for every encryption operation. RFC 7539 specifies that the nonce value
(IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length
and front pads the nonce with 0 bytes if it is less than 12
bytes. However it also incorrectly allows a nonce to be set of up to 16
bytes. In this case only the last 12 bytes are significant and any
additional leading bytes are ignored.
* Add build tests for C++. These are generated files that only do one
thing, to include one public OpenSSL head file each. This tests that
the public header files can be usefully included in a C++ application.
* Enable SHA3 pre-hashing for ECDSA and DSA.
* Change the default RSA, DSA and DH size to 2048 bit instead of 1024.
This changes the size when using the genpkey app when no size is given. It
fixes an omission in earlier changes that changed all RSA, DSA and DH
generation apps to use 2048 bits by default.
* Reorganize the manual pages to consistently have RETURN VALUES,
EXAMPLES, SEE ALSO and HISTORY come in that order, and adjust
util/fix-doc-nits accordingly.
* Add the missing accessor EVP_PKEY_get0_engine()
* Have apps like 's_client' and 's_server' output the signature scheme
along with other cipher suite parameters when debugging.
* Make OPENSSL_config() error agnostic again.
* Do the error handling in RSA decryption constant time.
* Ensure that SM2 only uses SM3 as digest algorithm
- drop upstreamed patches:
* openssl-fix-handling-of-GNU-strerror_r.patch
* 0001-Fix-for-BIO_get_mem_ptr-and-related-regressions.patch
- update keyring by including Richard Levitte's key
==== python-Babel ====
Version update (2.6.0 -> 2.7.0)
- version update to 2.7.0
Possibly incompatible changes
* General: Internal uses of ``babel.util.odict`` have been replaced with
``collections.OrderedDict`` from The Python standard library.
Improvements
* CLDR: Upgrade to CLDR 35.1 - Alberto Mardegan, Aarni Koskela (#626, #643)
* General: allow anchoring path patterns to the start of a string -
Brian Cappello (#600)
* General: Bumped version requirement on pytz - @chrisbrake (#592)
* Messages: `pybabel compile`: exit with code 1 if errors were encountered
- Aarni Koskela (#647)
* Messages: Add omit-header to update_catalog - Cédric Krier (#633)
* Messages: Catalog update: keep user comments from destination by default
- Aarni Koskela (#648)
* Messages: Skip empty message when writing mo file - Cédric Krier (#564)
* Messages: Small fixes to avoid crashes on badly formatted .po files
- Bryn Truscott (#597)
* Numbers: `parse_decimal()` `strict` argument and `suggestions`
- Charly C (#590)
* Numbers: don't repeat suggestions in parse_decimal strict - Serban
Constantin (#599)
* Numbers: implement currency formatting with long display names
- Luke Plant (#585)
* Numbers: parse_decimal(): assume spaces are equivalent to non-breaking
spaces when not in strict mode - Aarni Koskela (#649)
* Performance: Cache locale_identifiers() - Aarni Koskela (#644)
Bugfixes
* CLDR: Skip alt=... for week data (minDays, firstDay, weekendStart,
weekendEnd) - Aarni Koskela (#634)
* Dates: Fix wrong weeknumber for 31.12.2018 - BT-sschmid (#621)
* Locale: Avoid KeyError trying to get data on WindowsXP - mondeja (#604)
* Locale: get_display_name(): Don't attempt to concatenate variant
information to None - Aarni Koskela (#645)
* Messages: pofile: Add comparison operators to _NormalizedString - Aarni
Koskela (#646)
* Messages: pofile: don't crash when message.locations can't be sorted
- Aarni Koskela (#646)
==== python-cryptography ====
Version update (2.6.1 -> 2.7)
- update to 2.7
* BACKWARDS INCOMPATIBLE: Removed the cryptography.hazmat.primitives.mac.MACContext interface.
The CMAC and HMAC APIs have not changed, but they are no longer registered
as MACContext instances.
* Removed support for running our tests with setup.py test.
* Add support for :class:`~cryptography.hazmat.primitives.poly1305.Poly1305`
when using OpenSSL 1.1.1 or newer.
* Support serialization with Encoding.OpenSSH and PublicFormat.OpenSSH
in :meth:`Ed25519PublicKey.public_bytes <cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PublicKey.public_bytes>` .
* Correctly allow passing a SubjectKeyIdentifier to :meth:`~cryptography.x509.AuthorityKeyIdentifier.from_issuer_subject_key_identifier`
and deprecate passing an Extension object.
- Simplify the test execution to be more understandable
==== python-rpm-macros ====
Version update (20190430.5260267 -> 20190610.2ee3233)
- Update to version 20190610.2ee3233:
* Fix typo, missing opening brace.
* Add the first draft of pyproject_wheel and pyproject_install macros.
* Yet another attempt to preserve $PYTHONPATH set in the environment.
* Document also %pytest_arch
* Document %pytest in README.md
* Multiline macros don't work correctly on older RPMs.
* Add missing $ expansion on the pytest call
* Rewrite pytest and pytest_arch into Lua macros with multiple arguments.
* We should preserve existing PYTHONPATH.
* Add --ignore to pytest calls to ignore build directories.
- Update to version 20190610.2ee3233:
* Fix typo, missing opening brace.
- Update to version 20190511.2ed22b6:
* Add the first draft of pyproject_wheel and pyproject_install macros.
==== python-six ====
- Fix pytest call
- Fixdocumentation package generating
==== python-urllib3 ====
Version update (1.24.2 -> 1.25.3)
- Fixup pre script: the migration issue happens when changing from
python-urllib3 to python2-urllib3: the number of installed
instances of python2-urlliib3 is at this moment 1, unlike in
regular updates. This is due to a name change, which consists not
of a pure package update.
- Provides/Obsoletes does not fix the issue: we have a
directory-to-symlink switch, which cannot be handled by RPM
internally. Assist using pre script (boo#1138715).
- Fix Upgrade from Leap 42.1/42.2 by adding Obsoletes/Provides:
python-urllib3, fixes boo#1138746
- Skip test_source_address_error as we raise different error with
fixes that we provide in new python2/3
- Add more test to skip as with new openssl some behaviour changed
and we can't rely on them anymore
- Unbundle the six, rfc3986, and backports.ssl_match_hostname
- Update to 1.25.3:
* Change HTTPSConnection to load system CA certificates when ca_certs, ca_cert_dir, and ssl_context are unspecified. (Pull #1608, Issue #1603)
* Upgrade bundled rfc3986 to v1.3.2. (Pull #1609, Issue #1605)
- Update to 1.25.2:
* Change is_ipaddress to not detect IPvFuture addresses. (Pull #1583)
* Change parse_url to percent-encode invalid characters within the path, query, and target components. (Pull #1586)
* Add support for Google's Brotli package. (Pull #1572, Pull #1579)
* Upgrade bundled rfc3986 to v1.3.1 (Pull #1578)
- Require all the deps from the secure list rather than Recommend.
This makes the check to be run always and ensure the urls are
"secure".
- Remove ndg-httpsclient as it is not needed since 2015
- Add missing dependency on brotlipy
- Fix the tests to pass again
- update to 1.25 (bsc#1132663, CVE-2019-11236):
* Require and validate certificates by default when using HTTPS
* Upgraded ``urllib3.utils.parse_url()`` to be RFC 3986 compliant.
* Added support for ``key_password`` for ``HTTPSConnectionPool`` to use
encrypted ``key_file`` without creating your own ``SSLContext`` object.
* Add TLSv1.3 support to CPython, pyOpenSSL, and SecureTransport ``SSLContext``
implementations. (Pull #1496)
* Switched the default multipart header encoder from RFC 2231 to HTML 5 working draft.
* Fixed issue where OpenSSL would block if an encrypted client private key was
given and no password was given. Instead an ``SSLError`` is raised.
* Added support for Brotli content encoding. It is enabled automatically if
``brotlipy`` package is installed which can be requested with
``urllib3[brotli]`` extra.
* Drop ciphers using DSS key exchange from default TLS cipher suites.
Improve default ciphers when using SecureTransport.
* Implemented a more efficient ``HTTPResponse.__iter__()`` method.
- Drop urllib3-test-ssl-drop-sslv3.patch . No longer needed
- Update to 1.24.2:
- Implemented a more efficient HTTPResponse.__iter__() method.
(Issue #1483)
- Upgraded urllib3.utils.parse_url() to be RFC 3986 compliant.
(Pull #1487)
- Remove Authorization header regardless of case when
redirecting to cross-site. (Issue #1510)
- Added support for key_password for HTTPSConnectionPool to use
encrypted key_file without creating your own SSLContext
object. (Pull #1489)
- Fixed issue where OpenSSL would block if an encrypted client
private key was given and no password was given. Instead an
SSLError is raised. (Pull #1489)
- Require and validate certificates by default when using HTTPS
(Pull #1507)
- Added support for Brotli content encoding. It is enabled
automatically if brotlipy package is installed which can be
requested with urllib3[brotli] extra. (Pull #1532)
- Add TLSv1.3 support to CPython, pyOpenSSL, and
SecureTransport SSLContext implementations. (Pull #1496)
- Drop ciphers using DSS key exchange from default TLS cipher
suites. Improve default ciphers when using SecureTransport.
(Pull #1496)
- Add support for IPv6 addresses in subjectAltName section of
certificates. (Issue #1269)
- Switched the default multipart header encoder from RFC 2231
to HTML 5 working draft. (Issue #303, PR #1492)
- Update to 1.24.1:
* Remove quadratic behavior within GzipDecoder.decompress()
(Issue #1467)
* Restored functionality of ciphers parameter for
create_urllib3_context(). (Issue #1462)
- Update to 1.24:
* Allow key_server_hostname to be specified when initializing a PoolManager to allow custom SNI to be overridden. (Pull #1449)
* Test against Python 3.7 on AppVeyor. (Pull #1453)
* Early-out ipv6 checks when running on App Engine. (Pull #1450)
* Change ambiguous description of backoff_factor (Pull #1436)
* Add ability to handle multiple Content-Encodings (Issue #1441 and Pull #1442)
* Skip DNS names that can't be idna-decoded when using pyOpenSSL (Issue #1405).
* Add a server_hostname parameter to HTTPSConnection which allows for overriding the SNI hostname sent in the handshake. (Pull #1397)
* Drop support for EOL Python 2.6 (Pull #1429 and Pull #1430)
* Fixed bug where responses with header Content-Type: message/* erroneously raised HeaderParsingError, resulting in a warning being logged. (Pull #1439)
* Move urllib3 to src/urllib3 (Pull #1409)
- Drop patch 1414.patch merged upstream
- Refresh patches:
* python-urllib3-recent-date.patch
* urllib3-ssl-default-context.patch
- Switch to multibuild to minize requirements for providing
urllib3 module.
- fix dependency again for passing tests for python 2.x
- Do not use ifpython2 for BRs where it does not work
- add python-ipaddress dependency for python 2.x
- Drop not needed devel and nose deps
- update to 1.23
- add 1414.patch - fix tests with new tornado
- refresh python-urllib3-recent-date.patch
- drop urllib3-test-no-coverage.patch
* Allow providing a list of headers to strip from requests when redirecting
to a different host. Defaults to the Authorization header. Different
headers can be set via Retry.remove_headers_on_redirect.
* Fix util.selectors._fileobj_to_fd to accept long
* Dropped Python 3.3 support.
* Put the connection back in the pool when calling stream()
or read_chunked() on a chunked HEAD response.
* Fixed pyOpenSSL-specific ssl client authentication issue when clients
attempted to auth via certificate + chain
* Add the port to the connectionpool connect print
* Don't use the uuid module to create multipart data boundaries.
* read_chunked() on a closed response returns no chunks.
* Add Python 2.6 support to contrib.securetransport
* Added support for auth info in url for SOCKS proxy
- Allows Recommends and Suggest in Fedora
- Recommends only for SUSE
- disable more flaky tests specifically for PowerPC
- Add python-urllib3-recent-date.patch: Fix test suite, use correct
date (gh#shazow/urllib3#1303, boo#1074247).
- use python3 for detection, in anticipation of python2 removal
- Disable tests that timeout
- update to 1.22:
* Fixed missing brackets in ``HTTP CONNECT`` when connecting to IPv6 address via
IPv6 proxy. (Issue #1222)
* Made the connection pool retry on ``SSLError``. The original ``SSLError``
is available on ``MaxRetryError.reason``. (Issue #1112)
* Drain and release connection before recursing on retry/redirect. Fixes
deadlocks with a blocking connectionpool. (Issue #1167)
* Fixed compatibility for cookiejar. (Issue #1229)
* pyopenssl: Use vendored version of ``six``. (Issue #1231)
- use pytest for running the tests. That is what upstream is doing
- update to 1.21.1:
* Fixed SecureTransport issue that would cause long delays in response body
delivery. (Pull #1154)
* Fixed regression in 1.21 that threw exceptions when users passed the
``socket_options`` flag to the ``PoolManager``. (Issue #1165)
* Fixed regression in 1.21 that threw exceptions when users passed the
``assert_hostname`` or ``assert_fingerprint`` flag to the ``PoolManager``.
* Improved performance of certain selector system calls on Python 3.5 and
later. (Pull #1095)
* Resolved issue where the PyOpenSSL backend would not wrap SysCallError
exceptions appropriately when sending data. (Pull #1125)
* Selectors now detects a monkey-patched select module after import for modules
that patch the select module like eventlet, greenlet. (Pull #1128)
* Reduced memory consumption when streaming zlib-compressed responses
(as opposed to raw deflate streams). (Pull #1129)
* Connection pools now use the entire request context when constructing the
pool key. (Pull #1016)
* ``PoolManager.connection_from_*`` methods now accept a new keyword argument,
``pool_kwargs``, which are merged with the existing ``connection_pool_kw``.
* Add retry counter for ``status_forcelist``. (Issue #1147)
* Added ``contrib`` module for using SecureTransport on macOS:
``urllib3.contrib.securetransport``. (Pull #1122)
* urllib3 now only normalizes the case of ``http://`` and ``https://`` schemes:
for schemes it does not recognise, it assumes they are case-sensitive and
leaves them unchanged.
- Relax python-nose version requirement on SLE 12 (fate#321630)
- merge python3 modifications
- update for multipython build
- update to 1.20:
* Added support for waiting for I/O using selectors other than select, improving urllib3?s behaviour with large numbers of concurrent connections. (Pull #1001)
* Updated the date for the system clock check. (Issue #1005)
* ConnectionPools now correctly consider hostnames to be case-insensitive. (Issue #1032)
* Outdated versions of PyOpenSSL now cause the PyOpenSSL contrib module to fail when it is injected, rather than at first use. (Pull #1063)
* Outdated versions of cryptography now cause the PyOpenSSL contrib module to fail when it is injected, rather than at first use. (Issue #1044)
* Automatically attempt to rewind a file-like body object when a request is retried or redirected. (Pull #1039)
* Fix some bugs that occur when modules incautiously patch the queue module. (Pull #1061)
* Prevent retries from occuring on read timeouts for which the request method was not in the method whitelist. (Issue #1059)
* Changed the PyOpenSSL contrib module to lazily load idna to avoid unnecessarily bloating the memory of programs that don?t need it. (Pull #1076)
* Add support for IPv6 literals with zone identifiers. (Pull #1013)
* Added support for socks5h:// and socks4a:// schemes when working with SOCKS proxies, and controlled remote DNS appropriately. (Issue #1035)
update to version 1.19.1
* Forgot to mention #955.
* Starting o the user guide.
* Add ipaddress marker to setup.cfg.
* CHANGES for #897
* Version added 1.17
* Change debug level to 'debug' to match ConnectionPool
* Moving some stuff to advanced usage.
* Ignore only the unused import error
* Uniform checks.
* Add test for past date in Retry-After header
* Adding all reference docs
* Ok, I just gotta see what's going on here.
* Adding app engine docs
* Keep using the good OpenSSL
* Adding timeout section
* Removing absolute import in NTLMPool
* Use the good OpenSSL.
* Small pass at contributing
* parse_url: Disallow non-integer digits explicitly in port numbers
* Fixup some whitespace.
* Updating copy on landing page.
* Fix flake8 E305 errors
* Use OS default certs when possible
* Fleshing out user guide.
* Fallback to the vendored ipaddress module.
* Updating intersphinx to python 3.4
* Seems like version mismatch is the issue.
* Improve the cipher suite comment
* Retry backoff time is calculated only from the last consecutive errors sequence
* Fix a typo in the user guide documentation
* Update docs guide with new dependencies
* Tests for #979
* Remove HIGH cipher suites as well.
* Adding SSL verification section to user guide.
* More CHANGES
* Changes for #1017
* Changelog for #1009.
* Vendor a backport of the ipaddress module.
* CHANGES for 1.19
* Fixed typos
* Revert "Fallback to the vendored ipaddress module."
* Use "with" to close more files eagerly and also on error
* Addressing review comments
* First stab at the new index page
* Removing unneeded scratch file.
* Fixing some references
* Moving some stuff around.
* CR fixes
* Remove 100% requirement from nosetests.
* Try using codecov
* Remove absolute import.
* Split ciphers up to individual lines.
* add warning when timeout without total is used on App Engine
* We don't want a sad @haikuginger
* RequestHistory is a namedtuple instance.
* I wonder if we're missing this.
* Switching to alabaster theme
* Prefer user-supplied host headers.
* Try shoving it in tox.ini
* Add include=urllib3/* to prevent core module coverage through six.moves
* Pointing flake8 specifically at the urllib3 package
* CHANGES for #955
* Sorry PyPy.
* Add support for ChaCha20.
* Make Travis CI fail if docs have warnings or errors
* Added CHANGES entry
* Test with OpenSSL 1.1 on Mac.
* Backport Python 3.5 match_hostname function.
* Wrap lines to under 99 chars
* Moving docs creation into tox
* Gotta use the pyenv everywhere.
* Explicitly check if a value in a multipart header is None instead of just a falsy value
* Move to a more complex bit of idna handling.
* Make codecov enforce 100% coverage.
* Error if GAE_PYTHONPATH is not set when running make test-gae
* Changes for #258.
* adding length_remaining functionality to HTTPResponse
* test TLSv1 instead of SSLv3
* fixing infinite loop when stream(None) called
* Adding proxy section
* Don't forget setup.cfg
* Removing TODO
* add changelog for #978
* Stop testing our parsing via TLS failure.
* CHANGES for #928
* Add support for OS X.
* While I'm shotgun debugging.
* Merging new release version: 1.19.1
* Clean up some bugs.
* Support date in Retry-After header
* Defer to URLFetch's default timeout instead of hard coding 5s.
* Update Travis PyPy testing to 5.4
* Remove 3DES support.
* Seems like Python 2.6 doesn't like -m pip
* Adding logging and exceptions.
* changing conditional order to prefer isclosed over closed
* Have the 'secure' flag install ipaddress.
* Respect Retry-After header for redirection
* Respect Retry-After header
* Correct the import of urljoin for Python 3
* use dunder slots for Url class slots variable
* Update README.rst to better reflect new documentation.
* Allow PyPy 5.3 to fail
* updating CHANGES and CONTRIBUTORS
* Clarifying a few things.
* Revert "Remove ipaddress marker."
* Fix GAE_PYTHONPATH error in Makefile
* Removing symlinks from dummyserver certs to fix test suite on Windows
* adding in exception for booleans and zero values in timeouts
* CHANGES for #930
* add domain and method aware logging to connectionpool (#897)
* Add release note about #941 (#943)
* Make HTTPResponse.stream() work with file-like body of non-HTTPResponse type (eg StringIO)
* Use HTTPException, LifoQueue, Empty, and Full from six
* CHANGES for #858 and #887
* Updating links to SSL warning help page. Fixes #918
* More alabaster customizations, starting on TOC
* CHANGES for #835
* It's possible but unlikely that we need combine
* We actually require cryptography-based PyOpenSSL now.
* PySocks 1.5.7 causes problems with IPv6.
* fixing socks and ssl docstrings.
* Fix doc syntax in user-guide.rst
* Urllib3 -> urllib3
* Removing uneeded files.
* Dear tox: plz propagate env vars. Thanks.
* Favour our own match_hostname over old versions.
* Bow before our fruit overlords.
* enforce_content_length for incrementally read responses
* fixing incorrect message for IncompleteRead
* Update setup.cfg
* Changelog for #986.
* Spelling fixes
* Line breaks.
* Adding docs/requirements.txt for readthedocs.
* CHANGES for #989.
* Normalize the scheme and host in the URL parser
* Update changes for 1.17
* Changes for #979
* Changelog update for #947.
* Update connectionpool.py
* Make BodyNotHttplibCompatible inherit from HttpError, urllib3's base exception class, only
* Update changes for 1.18
* Update PyOpenSSL to not use ndg-httpsclient or pyasn1
* Retry history changed from list to tuple
* Add a cert with IP SAN and test for it.
* parse_retry_after: Disallow non-integer digits, allow whitespace
* Add failing test for #1009.
* Remove markers from setup.py.
* Use Travis supplied PyPy 5.3
* Support retry for 413, 429 and 503 status code
* Remove ipaddress marker.
* Revert "Vendor a backport of the ipaddress module."
* Adding retry section
* CVE-2016-9015: Correct set verify flags.
* Update CHANGES.rst for #911
* Tests for case-insensitivity in the scheme and host
* Add changelog for #967.
* Try updating setuptools.
* Updating flake8 locations
* Forward-port 1.18.1 changelog.
* Update [secure] extra.
* Add more advanced usage docs
* CHANGES for #990
* [contrib/pyopenssl] remove unused ssl_wrap_socket
* Import more from six
- update to 1.16:
* Disable IPv6 DNS when IPv6 connections are not possible. (Issue #840)
* Provide ``key_fn_by_scheme`` pool keying mechanism that can be
overridden. (Issue #830)
* Normalize scheme and host to lowercase for pool keys, and include
``source_address``. (Issue #830)
* Cleaner exception chain in Python 3 for ``_make_request``.
(Issue #861)
* Fixed installing ``urllib3[socks]`` extra. (Issue #864)
* Fixed signature of ``ConnectionPool.close`` so it can actually safely be
called by subclasses. (Issue #873)
* Retain ``release_conn`` state across retries. (Issues #651, #866)
* Add customizable ``HTTPConnectionPool.ResponseCls``, which defaults to
``HTTPResponse`` but can be replaced with a subclass. (Issue #879)
- Use pypi.io as Source url
- update to 1.15.1:
* Fix packaging to include backports module. (Issue #841)
* Added Retry(raise_on_status=False). (Issue #720)
* Always use setuptools, no more distutils fallback. (Issue #785)
* Dropped support for Python 3.2. (Issue #786)
* Chunked transfer encoding when requesting with ``chunked=True``.
* Fixed regression with IPv6 port parsing. (Issue #801)
* Append SNIMissingWarning messages to allow users to specify it in
the PYTHONWARNINGS environment variable. (Issue #816)
* Handle unicode headers in Py2. (Issue #818)
* Log certificate when there is a hostname mismatch. (Issue #820)
* Preserve order of request/response headers. (Issue #821)
- change Requires on pyopenssl, pyasn1 into Recommends,
add ndg-httpsclient as well
(these are dependencies of urrlib3's pyopenssl module, which can be
used if native python's ssl capabilities are not good enough)
- Update 1.14 source tar.gz from the source
* Rebase urllib3-test-no-coverage.patch
- Update to Version 1.14 (2015-12-29)
* contrib: SOCKS proxy support! (Issue #762)
* Fixed AppEngine handling of transfer-encoding header and bug in
Timeout defaults checking. (Issue #763)
- Update to Version 1.13.1 (2015-12-18)
* Fixed regression in IPv6 + SSL for match_hostname. (Issue #761)
- Update to Version 1.13 (2015-12-14)
* Fixed pip install urllib3[secure] on modern pip. (Issue #706)
* pyopenssl: Fixed SSL3_WRITE_PENDING error. (Issue #717)
* pyopenssl: Support for TLSv1.1 and TLSv1.2. (Issue #696)
* Close connections more defensively on exception. (Issue #734)
* Adjusted read_chunked to handle gzipped, chunk-encoded bodies
without repeatedly flushing the decoder, to function better on
Jython. (Issue #743)
* Accept ca_cert_dir for SSL-related PoolManager configuration.
(Issue #758)
- removed ready-event.patch: applied upstream
- disabled more dysfunctional tests
- restored ability to build with openSUSE <= 13.2
- removed python-certifi dependency, we don't want to use it
- drop 0001-Don-t-pin-dependency-to-exact-version.patch because it's
not needed anymore
- re-enable tests, re-add relevant dependencies
* don't exclude test_util.py
* exclude proxy timeout tests that fail for spurious reasons
- urllib3-ssl-default-context.patch - use set_default_verify_paths()
if no certificate path specified and verification not explicitly
disabled
- urllib3-test-ssl-drop-sslv3.patch - don't use "SSLv3" constants
in python 2.7.9 and up
- ready-event.patch - fix race conditions in timeout tests
- drop %pre section because apparently "egg-info as file" is no longer
true and this breaks builds
- Delete the system egg-info during pre phase: older versions of
the package installed it as a directory, the latest update
creates a file, and rpm has known issues with replacing this.
- add python-pyOpenSSL, python-certifi and python-pyasn1 requirements
- Comment out test requirements, as tests are disabled anyway, and
one of these packages depend on python-requests, which depends on
this package resulting in a circular dependency for openSUSE <= 13.1
- Update to version 1.12
* Rely on six for importing httplib to work around conflicts with
other Python 3 shims. (Issue #688)
* Add support for directories of certificate authorities, as
supported by OpenSSL. (Issue #701)
* New exception: NewConnectionError, raised when we fail to
establish a new connection, usually ECONNREFUSED socket error.
- Fix version dependencies
- Add new build requirements following upstream changes
* python-nose-exclude
* python-tox
* python-twine
* python-wheel
- Update 0001-Don-t-pin-dependency-to-exact-version.patch
- Disable tests for now, as there require network
==== python3 ====
Version update (3.7.2 -> 3.7.3)
- Set _lto_cflags to nil as the package is using LTO via --enable-lto.
That will prevent to propage LTO for Python modules that are
built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
- Fix metadata of patches.
- Rename boo1071941-make-install-in-sep-loc.patch to
00251-change-user-install-location.patch which is the original
name, so it can be looked up in the Fedora VCS.
- Mark distutils bdist_wininst command unsupported
with 00316-mark-bdist_wininst-unsupported.patch
- Remove Windows bdist_wininst executables from runtime package
- Update to 3.7.3, which is the maintenance release without any
significant changes in API.
- Updated patches:
- CVE-2019-5010-null-defer-x509-cert-DOS.patch
- distutils-reproducible-compile.patch
- python-3.3.0b1-fix_date_time_compiler.patch
- python-3.6.0-multilib.patch
- raise_SIGING_not_handled.patch
- Remove building of Qt Develop help files.
==== python3-base ====
Version update (3.7.2 -> 3.7.3)
Subpackages: libpython3_7m1_0
- Set _lto_cflags to nil as the package is using LTO via --enable-lto.
That will prevent to propage LTO for Python modules that are
built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
- Fix metadata of patches.
- Rename boo1071941-make-install-in-sep-loc.patch to
00251-change-user-install-location.patch which is the original
name, so it can be looked up in the Fedora VCS.
- Mark distutils bdist_wininst command unsupported
with 00316-mark-bdist_wininst-unsupported.patch
- Remove Windows bdist_wininst executables from runtime package
- Update to 3.7.3, which is the maintenance release without any
significant changes in API.
- Updated patches:
- CVE-2019-5010-null-defer-x509-cert-DOS.patch
- distutils-reproducible-compile.patch
- python-3.3.0b1-fix_date_time_compiler.patch
- python-3.6.0-multilib.patch
- raise_SIGING_not_handled.patch
==== systemd-presets-branding-MicroOS ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== zstd ====
- Remove googletest-devel BuildRequires and pzstd-global-gtest.patch
because we want zstd in ring0 (due to rpm's zstd payload support)
Since googletest is only used in build time (it's for testing after
all), this should be fine.
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
grub2
iputils
kexec-tools (2.0.18 -> 2.0.19)
openssl (1.1.1b -> 1.1.1c)
openssl-1_1 (1.1.1b -> 1.1.1c)
python-Babel (2.6.0 -> 2.7.0)
python-cryptography (2.6.1 -> 2.7)
python-pycryptodome (3.8.1 -> 3.8.2)
python-rpm-macros (20190430.5260267 -> 20190610.2ee3233)
python-six
python-urllib3 (1.24.2 -> 1.25.3)
python3 (3.7.2 -> 3.7.3)
python3-base (3.7.2 -> 3.7.3)
salt
systemd-presets-branding-MicroOS
zstd
=== Details ===
==== grub2 ====
Subpackages: grub2-i386-pc grub2-snapper-plugin grub2-x86_64-efi
- Avoid high resolution when trying to keep current mode (bsc#1133842)
* grub2-video-limit-the-resolution-for-fixed-bimap-font.patch
- Make GRUB_SAVEDEFAULT working with btrfs (bsc#1128592)
* grub2-grubenv-in-btrfs-header.patch
==== iputils ====
- Add patch ping-Fix-unwanted-bell-on-unreachable-address.patch (boo#1135118)
==== kexec-tools ====
Version update (2.0.18 -> 2.0.19)
- Bump to version 2.0.19
Changelog: http://git.kernel.org/cgit/utils/kernel/kexec/kexec-tools.git/log/?id=refs/…
==== openssl ====
Version update (1.1.1b -> 1.1.1c)
- Update to 1.1.1c release
==== openssl-1_1 ====
Version update (1.1.1b -> 1.1.1c)
Subpackages: libopenssl1_1
- Use upstream patch for the locale crash (bsc#1135550)
* https://github.com/openssl/openssl/pull/8966
- delete openssl-fix_underflow_in_errstr_handling.patch
- add 0001-build_SYS_str_reasons-Fix-a-crash-caused-by-overlong.patch
- Add s390x vectorized support for ChaCha20 and Poly1305
(jsc#SLE-6126, jsc#SLE-6129)
* 0001-s390x-assembly-pack-perlasm-support.patch
* 0002-crypto-chacha-asm-chacha-s390x.pl-add-vx-code-path.patch
* 0003-crypto-poly1305-asm-poly1305-s390x.pl-add-vx-code-pa.patch
* 0004-s390x-assembly-pack-fix-formal-interface-bug-in-chac.patch
* 0005-s390x-assembly-pack-import-chacha-from-cryptogams-re.patch
* 0006-s390x-assembly-pack-import-poly-from-cryptogams-repo.patch
- delete 0001-crypto-poly1305-asm-poly1305-s390x.pl-add-vx-code-pa.patch
- Update to 1.1.1c (bsc#1133925, jsc#SLE-6430)
* Prevent over long nonces in ChaCha20-Poly1305 (CVE-2019-1543)
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input
for every encryption operation. RFC 7539 specifies that the nonce value
(IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length
and front pads the nonce with 0 bytes if it is less than 12
bytes. However it also incorrectly allows a nonce to be set of up to 16
bytes. In this case only the last 12 bytes are significant and any
additional leading bytes are ignored.
* Add build tests for C++. These are generated files that only do one
thing, to include one public OpenSSL head file each. This tests that
the public header files can be usefully included in a C++ application.
* Enable SHA3 pre-hashing for ECDSA and DSA.
* Change the default RSA, DSA and DH size to 2048 bit instead of 1024.
This changes the size when using the genpkey app when no size is given. It
fixes an omission in earlier changes that changed all RSA, DSA and DH
generation apps to use 2048 bits by default.
* Reorganize the manual pages to consistently have RETURN VALUES,
EXAMPLES, SEE ALSO and HISTORY come in that order, and adjust
util/fix-doc-nits accordingly.
* Add the missing accessor EVP_PKEY_get0_engine()
* Have apps like 's_client' and 's_server' output the signature scheme
along with other cipher suite parameters when debugging.
* Make OPENSSL_config() error agnostic again.
* Do the error handling in RSA decryption constant time.
* Ensure that SM2 only uses SM3 as digest algorithm
- drop upstreamed patches:
* openssl-fix-handling-of-GNU-strerror_r.patch
* 0001-Fix-for-BIO_get_mem_ptr-and-related-regressions.patch
- update keyring by including Richard Levitte's key
==== python-Babel ====
Version update (2.6.0 -> 2.7.0)
- version update to 2.7.0
Possibly incompatible changes
* General: Internal uses of ``babel.util.odict`` have been replaced with
``collections.OrderedDict`` from The Python standard library.
Improvements
* CLDR: Upgrade to CLDR 35.1 - Alberto Mardegan, Aarni Koskela (#626, #643)
* General: allow anchoring path patterns to the start of a string -
Brian Cappello (#600)
* General: Bumped version requirement on pytz - @chrisbrake (#592)
* Messages: `pybabel compile`: exit with code 1 if errors were encountered
- Aarni Koskela (#647)
* Messages: Add omit-header to update_catalog - Cédric Krier (#633)
* Messages: Catalog update: keep user comments from destination by default
- Aarni Koskela (#648)
* Messages: Skip empty message when writing mo file - Cédric Krier (#564)
* Messages: Small fixes to avoid crashes on badly formatted .po files
- Bryn Truscott (#597)
* Numbers: `parse_decimal()` `strict` argument and `suggestions`
- Charly C (#590)
* Numbers: don't repeat suggestions in parse_decimal strict - Serban
Constantin (#599)
* Numbers: implement currency formatting with long display names
- Luke Plant (#585)
* Numbers: parse_decimal(): assume spaces are equivalent to non-breaking
spaces when not in strict mode - Aarni Koskela (#649)
* Performance: Cache locale_identifiers() - Aarni Koskela (#644)
Bugfixes
* CLDR: Skip alt=... for week data (minDays, firstDay, weekendStart,
weekendEnd) - Aarni Koskela (#634)
* Dates: Fix wrong weeknumber for 31.12.2018 - BT-sschmid (#621)
* Locale: Avoid KeyError trying to get data on WindowsXP - mondeja (#604)
* Locale: get_display_name(): Don't attempt to concatenate variant
information to None - Aarni Koskela (#645)
* Messages: pofile: Add comparison operators to _NormalizedString - Aarni
Koskela (#646)
* Messages: pofile: don't crash when message.locations can't be sorted
- Aarni Koskela (#646)
==== python-cryptography ====
Version update (2.6.1 -> 2.7)
- update to 2.7
* BACKWARDS INCOMPATIBLE: Removed the cryptography.hazmat.primitives.mac.MACContext interface.
The CMAC and HMAC APIs have not changed, but they are no longer registered
as MACContext instances.
* Removed support for running our tests with setup.py test.
* Add support for :class:`~cryptography.hazmat.primitives.poly1305.Poly1305`
when using OpenSSL 1.1.1 or newer.
* Support serialization with Encoding.OpenSSH and PublicFormat.OpenSSH
in :meth:`Ed25519PublicKey.public_bytes <cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PublicKey.public_bytes>` .
* Correctly allow passing a SubjectKeyIdentifier to :meth:`~cryptography.x509.AuthorityKeyIdentifier.from_issuer_subject_key_identifier`
and deprecate passing an Extension object.
- Simplify the test execution to be more understandable
==== python-pycryptodome ====
Version update (3.8.1 -> 3.8.2)
- Update Source to point to github.
- Update to 3.8.2
* GH#291: fix strict aliasing problem, emerged with GCC 9.1.
==== python-rpm-macros ====
Version update (20190430.5260267 -> 20190610.2ee3233)
- Update to version 20190610.2ee3233:
* Fix typo, missing opening brace.
* Add the first draft of pyproject_wheel and pyproject_install macros.
* Yet another attempt to preserve $PYTHONPATH set in the environment.
* Document also %pytest_arch
* Document %pytest in README.md
* Multiline macros don't work correctly on older RPMs.
* Add missing $ expansion on the pytest call
* Rewrite pytest and pytest_arch into Lua macros with multiple arguments.
* We should preserve existing PYTHONPATH.
* Add --ignore to pytest calls to ignore build directories.
- Update to version 20190610.2ee3233:
* Fix typo, missing opening brace.
- Update to version 20190511.2ed22b6:
* Add the first draft of pyproject_wheel and pyproject_install macros.
==== python-six ====
- Fix pytest call
- Fixdocumentation package generating
==== python-urllib3 ====
Version update (1.24.2 -> 1.25.3)
- Fixup pre script: the migration issue happens when changing from
python-urllib3 to python2-urllib3: the number of installed
instances of python2-urlliib3 is at this moment 1, unlike in
regular updates. This is due to a name change, which consists not
of a pure package update.
- Provides/Obsoletes does not fix the issue: we have a
directory-to-symlink switch, which cannot be handled by RPM
internally. Assist using pre script (boo#1138715).
- Fix Upgrade from Leap 42.1/42.2 by adding Obsoletes/Provides:
python-urllib3, fixes boo#1138746
- Skip test_source_address_error as we raise different error with
fixes that we provide in new python2/3
- Add more test to skip as with new openssl some behaviour changed
and we can't rely on them anymore
- Unbundle the six, rfc3986, and backports.ssl_match_hostname
- Update to 1.25.3:
* Change HTTPSConnection to load system CA certificates when ca_certs, ca_cert_dir, and ssl_context are unspecified. (Pull #1608, Issue #1603)
* Upgrade bundled rfc3986 to v1.3.2. (Pull #1609, Issue #1605)
- Update to 1.25.2:
* Change is_ipaddress to not detect IPvFuture addresses. (Pull #1583)
* Change parse_url to percent-encode invalid characters within the path, query, and target components. (Pull #1586)
* Add support for Google's Brotli package. (Pull #1572, Pull #1579)
* Upgrade bundled rfc3986 to v1.3.1 (Pull #1578)
- Require all the deps from the secure list rather than Recommend.
This makes the check to be run always and ensure the urls are
"secure".
- Remove ndg-httpsclient as it is not needed since 2015
- Add missing dependency on brotlipy
- Fix the tests to pass again
- update to 1.25 (bsc#1132663, CVE-2019-11236):
* Require and validate certificates by default when using HTTPS
* Upgraded ``urllib3.utils.parse_url()`` to be RFC 3986 compliant.
* Added support for ``key_password`` for ``HTTPSConnectionPool`` to use
encrypted ``key_file`` without creating your own ``SSLContext`` object.
* Add TLSv1.3 support to CPython, pyOpenSSL, and SecureTransport ``SSLContext``
implementations. (Pull #1496)
* Switched the default multipart header encoder from RFC 2231 to HTML 5 working draft.
* Fixed issue where OpenSSL would block if an encrypted client private key was
given and no password was given. Instead an ``SSLError`` is raised.
* Added support for Brotli content encoding. It is enabled automatically if
``brotlipy`` package is installed which can be requested with
``urllib3[brotli]`` extra.
* Drop ciphers using DSS key exchange from default TLS cipher suites.
Improve default ciphers when using SecureTransport.
* Implemented a more efficient ``HTTPResponse.__iter__()`` method.
- Drop urllib3-test-ssl-drop-sslv3.patch . No longer needed
- Update to 1.24.2:
- Implemented a more efficient HTTPResponse.__iter__() method.
(Issue #1483)
- Upgraded urllib3.utils.parse_url() to be RFC 3986 compliant.
(Pull #1487)
- Remove Authorization header regardless of case when
redirecting to cross-site. (Issue #1510)
- Added support for key_password for HTTPSConnectionPool to use
encrypted key_file without creating your own SSLContext
object. (Pull #1489)
- Fixed issue where OpenSSL would block if an encrypted client
private key was given and no password was given. Instead an
SSLError is raised. (Pull #1489)
- Require and validate certificates by default when using HTTPS
(Pull #1507)
- Added support for Brotli content encoding. It is enabled
automatically if brotlipy package is installed which can be
requested with urllib3[brotli] extra. (Pull #1532)
- Add TLSv1.3 support to CPython, pyOpenSSL, and
SecureTransport SSLContext implementations. (Pull #1496)
- Drop ciphers using DSS key exchange from default TLS cipher
suites. Improve default ciphers when using SecureTransport.
(Pull #1496)
- Add support for IPv6 addresses in subjectAltName section of
certificates. (Issue #1269)
- Switched the default multipart header encoder from RFC 2231
to HTML 5 working draft. (Issue #303, PR #1492)
- Update to 1.24.1:
* Remove quadratic behavior within GzipDecoder.decompress()
(Issue #1467)
* Restored functionality of ciphers parameter for
create_urllib3_context(). (Issue #1462)
- Update to 1.24:
* Allow key_server_hostname to be specified when initializing a PoolManager to allow custom SNI to be overridden. (Pull #1449)
* Test against Python 3.7 on AppVeyor. (Pull #1453)
* Early-out ipv6 checks when running on App Engine. (Pull #1450)
* Change ambiguous description of backoff_factor (Pull #1436)
* Add ability to handle multiple Content-Encodings (Issue #1441 and Pull #1442)
* Skip DNS names that can't be idna-decoded when using pyOpenSSL (Issue #1405).
* Add a server_hostname parameter to HTTPSConnection which allows for overriding the SNI hostname sent in the handshake. (Pull #1397)
* Drop support for EOL Python 2.6 (Pull #1429 and Pull #1430)
* Fixed bug where responses with header Content-Type: message/* erroneously raised HeaderParsingError, resulting in a warning being logged. (Pull #1439)
* Move urllib3 to src/urllib3 (Pull #1409)
- Drop patch 1414.patch merged upstream
- Refresh patches:
* python-urllib3-recent-date.patch
* urllib3-ssl-default-context.patch
- Switch to multibuild to minize requirements for providing
urllib3 module.
- fix dependency again for passing tests for python 2.x
- Do not use ifpython2 for BRs where it does not work
- add python-ipaddress dependency for python 2.x
- Drop not needed devel and nose deps
- update to 1.23
- add 1414.patch - fix tests with new tornado
- refresh python-urllib3-recent-date.patch
- drop urllib3-test-no-coverage.patch
* Allow providing a list of headers to strip from requests when redirecting
to a different host. Defaults to the Authorization header. Different
headers can be set via Retry.remove_headers_on_redirect.
* Fix util.selectors._fileobj_to_fd to accept long
* Dropped Python 3.3 support.
* Put the connection back in the pool when calling stream()
or read_chunked() on a chunked HEAD response.
* Fixed pyOpenSSL-specific ssl client authentication issue when clients
attempted to auth via certificate + chain
* Add the port to the connectionpool connect print
* Don't use the uuid module to create multipart data boundaries.
* read_chunked() on a closed response returns no chunks.
* Add Python 2.6 support to contrib.securetransport
* Added support for auth info in url for SOCKS proxy
- Allows Recommends and Suggest in Fedora
- Recommends only for SUSE
- disable more flaky tests specifically for PowerPC
- Add python-urllib3-recent-date.patch: Fix test suite, use correct
date (gh#shazow/urllib3#1303, boo#1074247).
- use python3 for detection, in anticipation of python2 removal
- Disable tests that timeout
- update to 1.22:
* Fixed missing brackets in ``HTTP CONNECT`` when connecting to IPv6 address via
IPv6 proxy. (Issue #1222)
* Made the connection pool retry on ``SSLError``. The original ``SSLError``
is available on ``MaxRetryError.reason``. (Issue #1112)
* Drain and release connection before recursing on retry/redirect. Fixes
deadlocks with a blocking connectionpool. (Issue #1167)
* Fixed compatibility for cookiejar. (Issue #1229)
* pyopenssl: Use vendored version of ``six``. (Issue #1231)
- use pytest for running the tests. That is what upstream is doing
- update to 1.21.1:
* Fixed SecureTransport issue that would cause long delays in response body
delivery. (Pull #1154)
* Fixed regression in 1.21 that threw exceptions when users passed the
``socket_options`` flag to the ``PoolManager``. (Issue #1165)
* Fixed regression in 1.21 that threw exceptions when users passed the
``assert_hostname`` or ``assert_fingerprint`` flag to the ``PoolManager``.
* Improved performance of certain selector system calls on Python 3.5 and
later. (Pull #1095)
* Resolved issue where the PyOpenSSL backend would not wrap SysCallError
exceptions appropriately when sending data. (Pull #1125)
* Selectors now detects a monkey-patched select module after import for modules
that patch the select module like eventlet, greenlet. (Pull #1128)
* Reduced memory consumption when streaming zlib-compressed responses
(as opposed to raw deflate streams). (Pull #1129)
* Connection pools now use the entire request context when constructing the
pool key. (Pull #1016)
* ``PoolManager.connection_from_*`` methods now accept a new keyword argument,
``pool_kwargs``, which are merged with the existing ``connection_pool_kw``.
* Add retry counter for ``status_forcelist``. (Issue #1147)
* Added ``contrib`` module for using SecureTransport on macOS:
``urllib3.contrib.securetransport``. (Pull #1122)
* urllib3 now only normalizes the case of ``http://`` and ``https://`` schemes:
for schemes it does not recognise, it assumes they are case-sensitive and
leaves them unchanged.
- Relax python-nose version requirement on SLE 12 (fate#321630)
- merge python3 modifications
- update for multipython build
- update to 1.20:
* Added support for waiting for I/O using selectors other than select, improving urllib3?s behaviour with large numbers of concurrent connections. (Pull #1001)
* Updated the date for the system clock check. (Issue #1005)
* ConnectionPools now correctly consider hostnames to be case-insensitive. (Issue #1032)
* Outdated versions of PyOpenSSL now cause the PyOpenSSL contrib module to fail when it is injected, rather than at first use. (Pull #1063)
* Outdated versions of cryptography now cause the PyOpenSSL contrib module to fail when it is injected, rather than at first use. (Issue #1044)
* Automatically attempt to rewind a file-like body object when a request is retried or redirected. (Pull #1039)
* Fix some bugs that occur when modules incautiously patch the queue module. (Pull #1061)
* Prevent retries from occuring on read timeouts for which the request method was not in the method whitelist. (Issue #1059)
* Changed the PyOpenSSL contrib module to lazily load idna to avoid unnecessarily bloating the memory of programs that don?t need it. (Pull #1076)
* Add support for IPv6 literals with zone identifiers. (Pull #1013)
* Added support for socks5h:// and socks4a:// schemes when working with SOCKS proxies, and controlled remote DNS appropriately. (Issue #1035)
update to version 1.19.1
* Forgot to mention #955.
* Starting o the user guide.
* Add ipaddress marker to setup.cfg.
* CHANGES for #897
* Version added 1.17
* Change debug level to 'debug' to match ConnectionPool
* Moving some stuff to advanced usage.
* Ignore only the unused import error
* Uniform checks.
* Add test for past date in Retry-After header
* Adding all reference docs
* Ok, I just gotta see what's going on here.
* Adding app engine docs
* Keep using the good OpenSSL
* Adding timeout section
* Removing absolute import in NTLMPool
* Use the good OpenSSL.
* Small pass at contributing
* parse_url: Disallow non-integer digits explicitly in port numbers
* Fixup some whitespace.
* Updating copy on landing page.
* Fix flake8 E305 errors
* Use OS default certs when possible
* Fleshing out user guide.
* Fallback to the vendored ipaddress module.
* Updating intersphinx to python 3.4
* Seems like version mismatch is the issue.
* Improve the cipher suite comment
* Retry backoff time is calculated only from the last consecutive errors sequence
* Fix a typo in the user guide documentation
* Update docs guide with new dependencies
* Tests for #979
* Remove HIGH cipher suites as well.
* Adding SSL verification section to user guide.
* More CHANGES
* Changes for #1017
* Changelog for #1009.
* Vendor a backport of the ipaddress module.
* CHANGES for 1.19
* Fixed typos
* Revert "Fallback to the vendored ipaddress module."
* Use "with" to close more files eagerly and also on error
* Addressing review comments
* First stab at the new index page
* Removing unneeded scratch file.
* Fixing some references
* Moving some stuff around.
* CR fixes
* Remove 100% requirement from nosetests.
* Try using codecov
* Remove absolute import.
* Split ciphers up to individual lines.
* add warning when timeout without total is used on App Engine
* We don't want a sad @haikuginger
* RequestHistory is a namedtuple instance.
* I wonder if we're missing this.
* Switching to alabaster theme
* Prefer user-supplied host headers.
* Try shoving it in tox.ini
* Add include=urllib3/* to prevent core module coverage through six.moves
* Pointing flake8 specifically at the urllib3 package
* CHANGES for #955
* Sorry PyPy.
* Add support for ChaCha20.
* Make Travis CI fail if docs have warnings or errors
* Added CHANGES entry
* Test with OpenSSL 1.1 on Mac.
* Backport Python 3.5 match_hostname function.
* Wrap lines to under 99 chars
* Moving docs creation into tox
* Gotta use the pyenv everywhere.
* Explicitly check if a value in a multipart header is None instead of just a falsy value
* Move to a more complex bit of idna handling.
* Make codecov enforce 100% coverage.
* Error if GAE_PYTHONPATH is not set when running make test-gae
* Changes for #258.
* adding length_remaining functionality to HTTPResponse
* test TLSv1 instead of SSLv3
* fixing infinite loop when stream(None) called
* Adding proxy section
* Don't forget setup.cfg
* Removing TODO
* add changelog for #978
* Stop testing our parsing via TLS failure.
* CHANGES for #928
* Add support for OS X.
* While I'm shotgun debugging.
* Merging new release version: 1.19.1
* Clean up some bugs.
* Support date in Retry-After header
* Defer to URLFetch's default timeout instead of hard coding 5s.
* Update Travis PyPy testing to 5.4
* Remove 3DES support.
* Seems like Python 2.6 doesn't like -m pip
* Adding logging and exceptions.
* changing conditional order to prefer isclosed over closed
* Have the 'secure' flag install ipaddress.
* Respect Retry-After header for redirection
* Respect Retry-After header
* Correct the import of urljoin for Python 3
* use dunder slots for Url class slots variable
* Update README.rst to better reflect new documentation.
* Allow PyPy 5.3 to fail
* updating CHANGES and CONTRIBUTORS
* Clarifying a few things.
* Revert "Remove ipaddress marker."
* Fix GAE_PYTHONPATH error in Makefile
* Removing symlinks from dummyserver certs to fix test suite on Windows
* adding in exception for booleans and zero values in timeouts
* CHANGES for #930
* add domain and method aware logging to connectionpool (#897)
* Add release note about #941 (#943)
* Make HTTPResponse.stream() work with file-like body of non-HTTPResponse type (eg StringIO)
* Use HTTPException, LifoQueue, Empty, and Full from six
* CHANGES for #858 and #887
* Updating links to SSL warning help page. Fixes #918
* More alabaster customizations, starting on TOC
* CHANGES for #835
* It's possible but unlikely that we need combine
* We actually require cryptography-based PyOpenSSL now.
* PySocks 1.5.7 causes problems with IPv6.
* fixing socks and ssl docstrings.
* Fix doc syntax in user-guide.rst
* Urllib3 -> urllib3
* Removing uneeded files.
* Dear tox: plz propagate env vars. Thanks.
* Favour our own match_hostname over old versions.
* Bow before our fruit overlords.
* enforce_content_length for incrementally read responses
* fixing incorrect message for IncompleteRead
* Update setup.cfg
* Changelog for #986.
* Spelling fixes
* Line breaks.
* Adding docs/requirements.txt for readthedocs.
* CHANGES for #989.
* Normalize the scheme and host in the URL parser
* Update changes for 1.17
* Changes for #979
* Changelog update for #947.
* Update connectionpool.py
* Make BodyNotHttplibCompatible inherit from HttpError, urllib3's base exception class, only
* Update changes for 1.18
* Update PyOpenSSL to not use ndg-httpsclient or pyasn1
* Retry history changed from list to tuple
* Add a cert with IP SAN and test for it.
* parse_retry_after: Disallow non-integer digits, allow whitespace
* Add failing test for #1009.
* Remove markers from setup.py.
* Use Travis supplied PyPy 5.3
* Support retry for 413, 429 and 503 status code
* Remove ipaddress marker.
* Revert "Vendor a backport of the ipaddress module."
* Adding retry section
* CVE-2016-9015: Correct set verify flags.
* Update CHANGES.rst for #911
* Tests for case-insensitivity in the scheme and host
* Add changelog for #967.
* Try updating setuptools.
* Updating flake8 locations
* Forward-port 1.18.1 changelog.
* Update [secure] extra.
* Add more advanced usage docs
* CHANGES for #990
* [contrib/pyopenssl] remove unused ssl_wrap_socket
* Import more from six
- update to 1.16:
* Disable IPv6 DNS when IPv6 connections are not possible. (Issue #840)
* Provide ``key_fn_by_scheme`` pool keying mechanism that can be
overridden. (Issue #830)
* Normalize scheme and host to lowercase for pool keys, and include
``source_address``. (Issue #830)
* Cleaner exception chain in Python 3 for ``_make_request``.
(Issue #861)
* Fixed installing ``urllib3[socks]`` extra. (Issue #864)
* Fixed signature of ``ConnectionPool.close`` so it can actually safely be
called by subclasses. (Issue #873)
* Retain ``release_conn`` state across retries. (Issues #651, #866)
* Add customizable ``HTTPConnectionPool.ResponseCls``, which defaults to
``HTTPResponse`` but can be replaced with a subclass. (Issue #879)
- Use pypi.io as Source url
- update to 1.15.1:
* Fix packaging to include backports module. (Issue #841)
* Added Retry(raise_on_status=False). (Issue #720)
* Always use setuptools, no more distutils fallback. (Issue #785)
* Dropped support for Python 3.2. (Issue #786)
* Chunked transfer encoding when requesting with ``chunked=True``.
* Fixed regression with IPv6 port parsing. (Issue #801)
* Append SNIMissingWarning messages to allow users to specify it in
the PYTHONWARNINGS environment variable. (Issue #816)
* Handle unicode headers in Py2. (Issue #818)
* Log certificate when there is a hostname mismatch. (Issue #820)
* Preserve order of request/response headers. (Issue #821)
- change Requires on pyopenssl, pyasn1 into Recommends,
add ndg-httpsclient as well
(these are dependencies of urrlib3's pyopenssl module, which can be
used if native python's ssl capabilities are not good enough)
- Update 1.14 source tar.gz from the source
* Rebase urllib3-test-no-coverage.patch
- Update to Version 1.14 (2015-12-29)
* contrib: SOCKS proxy support! (Issue #762)
* Fixed AppEngine handling of transfer-encoding header and bug in
Timeout defaults checking. (Issue #763)
- Update to Version 1.13.1 (2015-12-18)
* Fixed regression in IPv6 + SSL for match_hostname. (Issue #761)
- Update to Version 1.13 (2015-12-14)
* Fixed pip install urllib3[secure] on modern pip. (Issue #706)
* pyopenssl: Fixed SSL3_WRITE_PENDING error. (Issue #717)
* pyopenssl: Support for TLSv1.1 and TLSv1.2. (Issue #696)
* Close connections more defensively on exception. (Issue #734)
* Adjusted read_chunked to handle gzipped, chunk-encoded bodies
without repeatedly flushing the decoder, to function better on
Jython. (Issue #743)
* Accept ca_cert_dir for SSL-related PoolManager configuration.
(Issue #758)
- removed ready-event.patch: applied upstream
- disabled more dysfunctional tests
- restored ability to build with openSUSE <= 13.2
- removed python-certifi dependency, we don't want to use it
- drop 0001-Don-t-pin-dependency-to-exact-version.patch because it's
not needed anymore
- re-enable tests, re-add relevant dependencies
* don't exclude test_util.py
* exclude proxy timeout tests that fail for spurious reasons
- urllib3-ssl-default-context.patch - use set_default_verify_paths()
if no certificate path specified and verification not explicitly
disabled
- urllib3-test-ssl-drop-sslv3.patch - don't use "SSLv3" constants
in python 2.7.9 and up
- ready-event.patch - fix race conditions in timeout tests
- drop %pre section because apparently "egg-info as file" is no longer
true and this breaks builds
- Delete the system egg-info during pre phase: older versions of
the package installed it as a directory, the latest update
creates a file, and rpm has known issues with replacing this.
- add python-pyOpenSSL, python-certifi and python-pyasn1 requirements
- Comment out test requirements, as tests are disabled anyway, and
one of these packages depend on python-requests, which depends on
this package resulting in a circular dependency for openSUSE <= 13.1
- Update to version 1.12
* Rely on six for importing httplib to work around conflicts with
other Python 3 shims. (Issue #688)
* Add support for directories of certificate authorities, as
supported by OpenSSL. (Issue #701)
* New exception: NewConnectionError, raised when we fail to
establish a new connection, usually ECONNREFUSED socket error.
- Fix version dependencies
- Add new build requirements following upstream changes
* python-nose-exclude
* python-tox
* python-twine
* python-wheel
- Update 0001-Don-t-pin-dependency-to-exact-version.patch
- Disable tests for now, as there require network
==== python3 ====
Version update (3.7.2 -> 3.7.3)
- Set _lto_cflags to nil as the package is using LTO via --enable-lto.
That will prevent to propage LTO for Python modules that are
built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
- Fix metadata of patches.
- Rename boo1071941-make-install-in-sep-loc.patch to
00251-change-user-install-location.patch which is the original
name, so it can be looked up in the Fedora VCS.
- Mark distutils bdist_wininst command unsupported
with 00316-mark-bdist_wininst-unsupported.patch
- Remove Windows bdist_wininst executables from runtime package
- Update to 3.7.3, which is the maintenance release without any
significant changes in API.
- Updated patches:
- CVE-2019-5010-null-defer-x509-cert-DOS.patch
- distutils-reproducible-compile.patch
- python-3.3.0b1-fix_date_time_compiler.patch
- python-3.6.0-multilib.patch
- raise_SIGING_not_handled.patch
- Remove building of Qt Develop help files.
==== python3-base ====
Version update (3.7.2 -> 3.7.3)
Subpackages: libpython3_7m1_0
- Set _lto_cflags to nil as the package is using LTO via --enable-lto.
That will prevent to propage LTO for Python modules that are
built in a separate package.
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised.
- Fix metadata of patches.
- Rename boo1071941-make-install-in-sep-loc.patch to
00251-change-user-install-location.patch which is the original
name, so it can be looked up in the Fedora VCS.
- Mark distutils bdist_wininst command unsupported
with 00316-mark-bdist_wininst-unsupported.patch
- Remove Windows bdist_wininst executables from runtime package
- Update to 3.7.3, which is the maintenance release without any
significant changes in API.
- Updated patches:
- CVE-2019-5010-null-defer-x509-cert-DOS.patch
- distutils-reproducible-compile.patch
- python-3.3.0b1-fix_date_time_compiler.patch
- python-3.6.0-multilib.patch
- raise_SIGING_not_handled.patch
==== salt ====
Subpackages: python3-salt salt-master salt-minion
- Fix zypper pkg.list_pkgs test expectation and dpkg mocking
- Added:
* fix-zypper-pkg.list_pkgs-expectation-and-dpkg-mockin.patch
- Set 'salt' group for files and directories created by
salt-standalone-formulas-configuration package
- Various fixes for virt module
- Fix virt.volume_infos raising an exception when there is only virtual machine on the minion.
- Fix virt.purge() on all non-KVM hypervisors. For instance on Xen, virt.purge would simply throw an exception about unsupported flag
- Building a libvirt pool starts it. When defining a new pool, we need to
let build start it or we will get libvirt errors.
- Fix handling of Virtual Machines with white space in their name.
- Added:
* virt.pool_running-fix-pool-start.patch
* virt-handle-whitespaces-in-vm-names.patch
* virt.volume_infos-fix-for-single-vm.patch
* try-except-undefineflags-as-this-operation-is-not-su.patch
- avoid batch.py exception when minion does not respond (bsc#1135507)
- Added:
* batch.py-avoid-exception-when-minion-does-not-respon.patch
- Preserve already defined DESTRUCTIVE_TESTS and EXPENSIVE_TESTS
env variables
- Added:
* preserve-already-defined-destructive_tests-and-expen.patch
- Do not break repo files with multiple line values on yumpkg (bsc#1135360)
- Added:
* do-not-break-repo-files-with-multiple-line-values-on.patch
==== systemd-presets-branding-MicroOS ====
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
==== zstd ====
- Remove googletest-devel BuildRequires and pzstd-global-gtest.patch
because we want zstd in ring0 (due to rpm's zstd payload support)
Since googletest is only used in build time (it's for testing after
all), this should be fine.
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
gpgme (1.13.0 -> 1.13.1)
libarchive (3.3.3 -> 3.4.0)
=== Details ===
==== gpgme ====
Version update (1.13.0 -> 1.13.1)
- gpgme 1.13.1:
* core: At debug levels up to 9 print only an ascii dump.
* core: Add commented debug helper to posix-io.c.
* core: Fix error return value of _gpgme_run_io_cb.
* core: Prettify _gpgme_io_select debug output again and fix TRACE_SYSRES.
* core: Improve the debug messages even more.
* core: Avoid explicit locks in the debug code.
* json: Print "nan", "-inf", "inf" if needed.
* json: Improve handling of large exponents in the JSON parsor.
* core: Implement recpstring option parsing for gpgsm.
* core: Make gpgme_op_encrypt_ext work for CMS.
* python: Fix typo in DecryptionError exception.
* python: Make EXTRA_DIST files explicit.
* Python, doc: Minor style improvement.
* Always use maintainer mode -Wno cflags.
* cpp: Fix initialization warning.
* python: stop raising BadSignatures from decrypt(verify=True)
* cpp: Add wrapper for gpgme_set_global_flag.
* core: Fix duplication of close_notify_handler for gpgsm.
==== libarchive ====
Version update (3.3.3 -> 3.4.0)
- Update to version 3.4.0
* Support for file and directory symlinks on Windows
* Read support for RAR 5.0 archives
* Read support for ZIPX archives with xz, lzma, ppmd8 and
bzip2 compression
* Support for non-recursive list and extract
* New tar option: --exclude-vcs
* Improved file attribute support on Linux and file flags support
on FreeBSD
* Fix reading Android APK archives (#1055 )
* Fix problems related to unreadable directories (#1167)
* A two-digit number of OSS-Fuzz issues was resolved in this release
- Add libarchive.keyring and validate the tarball signature
- Drop all security patches, fixed upstream:
* CVE-2018-1000877.patch
* CVE-2018-1000878.patch
* CVE-2018-1000879.patch
* CVE-2018-1000880.patch
* CVE-2019-1000019.patch
* CVE-2019-1000020.patch
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
gpgme (1.13.0 -> 1.13.1)
libarchive (3.3.3 -> 3.4.0)
rpcbind
=== Details ===
==== gpgme ====
Version update (1.13.0 -> 1.13.1)
- gpgme 1.13.1:
* core: At debug levels up to 9 print only an ascii dump.
* core: Add commented debug helper to posix-io.c.
* core: Fix error return value of _gpgme_run_io_cb.
* core: Prettify _gpgme_io_select debug output again and fix TRACE_SYSRES.
* core: Improve the debug messages even more.
* core: Avoid explicit locks in the debug code.
* json: Print "nan", "-inf", "inf" if needed.
* json: Improve handling of large exponents in the JSON parsor.
* core: Implement recpstring option parsing for gpgsm.
* core: Make gpgme_op_encrypt_ext work for CMS.
* python: Fix typo in DecryptionError exception.
* python: Make EXTRA_DIST files explicit.
* Python, doc: Minor style improvement.
* Always use maintainer mode -Wno cflags.
* cpp: Fix initialization warning.
* python: stop raising BadSignatures from decrypt(verify=True)
* cpp: Add wrapper for gpgme_set_global_flag.
* core: Fix duplication of close_notify_handler for gpgsm.
==== libarchive ====
Version update (3.3.3 -> 3.4.0)
- Update to version 3.4.0
* Support for file and directory symlinks on Windows
* Read support for RAR 5.0 archives
* Read support for ZIPX archives with xz, lzma, ppmd8 and
bzip2 compression
* Support for non-recursive list and extract
* New tar option: --exclude-vcs
* Improved file attribute support on Linux and file flags support
on FreeBSD
* Fix reading Android APK archives (#1055 )
* Fix problems related to unreadable directories (#1167)
* A two-digit number of OSS-Fuzz issues was resolved in this release
- Add libarchive.keyring and validate the tarball signature
- Drop all security patches, fixed upstream:
* CVE-2018-1000877.patch
* CVE-2018-1000878.patch
* CVE-2018-1000879.patch
* CVE-2018-1000880.patch
* CVE-2019-1000019.patch
* CVE-2019-1000020.patch
==== rpcbind ====
- change rpcbind locking path from /var/run/rpcbind.lock to
/run/rpcbind.lock (bsc#1134659)
add 0001-change-lockingdir-to-run.patch
- change the order of socket/service in the %postun scriptlet to
avoid an error from rpcbind.socket when rpcbind is running
during package update
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
curl (7.65.0 -> 7.65.1)
open-iscsi
openssl-1_1
patterns-containers
python-PyYAML (5.1 -> 5.1.1)
=== Details ===
==== curl ====
Version update (7.65.0 -> 7.65.1)
Subpackages: libcurl4
- Update to 7.65.1
* Bugfixes:
- CURLOPT_LOW_SPEED_* repaired
- NTLM: reset proxy "multipass" state when CONNECT request is done
- PolarSSL: deprecate support step 1. Removed from configure
- cmake: check for if_nametoindex()
- cmake: support CMAKE_OSX_ARCHITECTURES when detecting SIZEOF variables
- conncache: Remove the DEBUGASSERT on length check
- conncache: make "bundles" per host name when doing proxy tunnels
- curl_share_setopt.3: improve wording
- dump-header.d: spell out that no headers == empty file
- example/http2-download: fix format specifier
- examples: cleanups and compiler warning fixes
- http2: Stop drain from being permanently set
- http: don't parse body-related headers in bodyless responses
- md4: build correctly with openssl without MD4
- md4: include the mbedtls config.h to get the MD4 info
- multi: track users of a socket better
- nss: allow to specify TLS 1.3 ciphers if supported by NSS
- parse_proxy: make sure portptr is initialized
- parse_proxy: use the IPv6 zone id if given
- sectransp: handle errSSLPeerAuthCompleted from SSLRead()
- singlesocket: use separate variable for inner loop
- ssl: Update outdated "openssl-only" comments for supported backends
- tests: add HAProxy keywords
- tests: make test 1420 and 1406 work with rtsp-disabled libcurl
- tls13-docs: mention it is only for OpenSSL >= 1.1.1
- tool_setopt: for builds with disabled-proxy, skip all proxy setopts()
- url: fix bad feature-disable #ifdef
- url: use correct port in ConnectionExists()
==== open-iscsi ====
Subpackages: iscsiuio libopeniscsiusr0_2_0
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
- Added latest upstream changes, including:
- iscsiuio: Stop using /var directory for PIDfile and locks
- iscsiuio: improve daemon synchronization (bsc#1135070)
- fix pipe notification code
- add systemd support for iscsiuio
- make iscsid systemd usage optional
- fix possible discovery hang timeout
- fix iscsiuio systemd disablement
Updating:
* open-iscsi-SUSE-latest.diff.bz2
==== openssl-1_1 ====
Subpackages: libopenssl1_1
- add 0001-Fix-for-BIO_get_mem_ptr-and-related-regressions.patch
(bnc#1136522)
- Fix a crash caused by long locale messages (bsc#1135550)
* add openssl-fix_underflow_in_errstr_handling.patch
==== patterns-containers ====
- Add flannel-k8s-yaml
==== python-PyYAML ====
Version update (5.1 -> 5.1.1)
- update to 5.1.1
* Re-release of 5.1 with regenerated Cython sources to build properly for Python 3.8
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
cilium (1.5.1 -> 1.5.3)
curl (7.65.0 -> 7.65.1)
kubic-control (0.5.0 -> 0.5.1)
open-iscsi
openssl-1_1
patterns-containers
python-PyYAML (5.1 -> 5.1.1)
=== Details ===
==== cilium ====
Version update (1.5.1 -> 1.5.3)
- Switch container image URI from devel:kubic:containers to
openSUSE:Containers:Tumbleweed.
- Update to version 1.5.3:
* pkg/kvstore: do not always UpdateIfDifferent with and without lease
* daemon: Refactor individual endpoint restore
* daemon: Don't log endpoint restore if IP alloc fails
* Don't overwrite minRequired in WaitforNPods
* node: Delay handling of node delete events received via kvstore
* kvstore/store: Do not remove local key on sync failure
* node/store: Do not delete node key in kvstore on node registration failure
* Jenkinsfile: backport all Jenkinsfile from master
* test/provision: bump k8s 1.12 to 1.12.9
* test: do not spawn goroutines to wait for canceled context in `RunCommandContext`
* test: provide context which will be cancled to `CiliumExecContext`
==== curl ====
Version update (7.65.0 -> 7.65.1)
Subpackages: libcurl4
- Update to 7.65.1
* Bugfixes:
- CURLOPT_LOW_SPEED_* repaired
- NTLM: reset proxy "multipass" state when CONNECT request is done
- PolarSSL: deprecate support step 1. Removed from configure
- cmake: check for if_nametoindex()
- cmake: support CMAKE_OSX_ARCHITECTURES when detecting SIZEOF variables
- conncache: Remove the DEBUGASSERT on length check
- conncache: make "bundles" per host name when doing proxy tunnels
- curl_share_setopt.3: improve wording
- dump-header.d: spell out that no headers == empty file
- example/http2-download: fix format specifier
- examples: cleanups and compiler warning fixes
- http2: Stop drain from being permanently set
- http: don't parse body-related headers in bodyless responses
- md4: build correctly with openssl without MD4
- md4: include the mbedtls config.h to get the MD4 info
- multi: track users of a socket better
- nss: allow to specify TLS 1.3 ciphers if supported by NSS
- parse_proxy: make sure portptr is initialized
- parse_proxy: use the IPv6 zone id if given
- sectransp: handle errSSLPeerAuthCompleted from SSLRead()
- singlesocket: use separate variable for inner loop
- ssl: Update outdated "openssl-only" comments for supported backends
- tests: add HAProxy keywords
- tests: make test 1420 and 1406 work with rtsp-disabled libcurl
- tls13-docs: mention it is only for OpenSSL >= 1.1.1
- tool_setopt: for builds with disabled-proxy, skip all proxy setopts()
- url: fix bad feature-disable #ifdef
- url: use correct port in ConnectionExists()
==== kubic-control ====
Version update (0.5.0 -> 0.5.1)
Subpackages: kubicctl kubicd
- Update to version 0.5.1
- Use local flannel.yaml file to deploy flannel
==== open-iscsi ====
Subpackages: iscsiuio libopeniscsiusr0_2_0
- BuildRequire pkgconfig(systemd) instead of systemd: allow OBS to
shortcut the build queues by allowing usage of systemd-mini
- Added latest upstream changes, including:
- iscsiuio: Stop using /var directory for PIDfile and locks
- iscsiuio: improve daemon synchronization (bsc#1135070)
- fix pipe notification code
- add systemd support for iscsiuio
- make iscsid systemd usage optional
- fix possible discovery hang timeout
- fix iscsiuio systemd disablement
Updating:
* open-iscsi-SUSE-latest.diff.bz2
==== openssl-1_1 ====
Subpackages: libopenssl1_1
- add 0001-Fix-for-BIO_get_mem_ptr-and-related-regressions.patch
(bnc#1136522)
- Fix a crash caused by long locale messages (bsc#1135550)
* add openssl-fix_underflow_in_errstr_handling.patch
==== patterns-containers ====
Subpackages: patterns-containers-container_runtime patterns-containers-container_runtime_kubernetes patterns-containers-kubeadm patterns-containers-kubic_admin patterns-containers-kubic_worker
- Add flannel-k8s-yaml
==== python-PyYAML ====
Version update (5.1 -> 5.1.1)
- update to 5.1.1
* Re-release of 5.1 with regenerated Cython sources to build properly for Python 3.8
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
ceph (14.2.1.463+g99339b576a -> 14.2.1.468+g994fd9e0cc)
cri-o
ding-libs
e2fsprogs (1.45.1 -> 1.45.2)
elfutils
file (5.36 -> 5.37)
gettext-runtime
iptables (1.8.2 -> 1.8.3)
kexec-tools
libidn2 (2.1.1 -> 2.2.0)
libnftnl (1.1.2 -> 1.1.3)
libselinux
libssh
metallb
numactl
podman (1.3.1 -> 1.4.0)
salt
shadow
sqlite3 (3.27.2 -> 3.28.0)
tar (1.31 -> 1.32)
thin-provisioning-tools (0.7.6 -> 0.8.3)
xz
=== Details ===
==== ceph ====
Version update (14.2.1.463+g99339b576a -> 14.2.1.468+g994fd9e0cc)
Subpackages: ceph-common libcephfs2 librados2 libradosstriper1 librbd1 librgw2 python3-ceph-argparse python3-cephfs python3-rados python3-rbd python3-rgw
- Update to 14.2.1-468-g994fd9e0cc:
+ spec:
* install grafana dashboards world readable (bsc#1136110)
* put "without python2" conditionals around python3-* provides/obsoletes
(align with upstream)
- Update to 14.2.1-467-g9e10776aa2:
+ mon/Monitor: allow probe if MMonProbe::mon_release == 0 (bsc#1132396)
+ spec: make python3-rgw replace python-rgw on upgrade
==== cri-o ====
Subpackages: cri-o-kubeadm-criconfig
- Add apparmor-parser as dependency
==== ding-libs ====
Subpackages: libbasicobjects0 libcollection4 libdhash1 libini_config5 libpath_utils1 libref_array1
- Update to 0.6.1:
* No upstream changelog
- Update URL
* Remove the git link info as it 404 atm
- Add patches from upstream to fix ini behaviour:
* INI-Fix-detection-of-error-messages.patch
* INI-Silence-ini_augment-match-failures.patch
* TEST-validators_ut_check-Fix-fail-with-new-glibc.patch
==== e2fsprogs ====
Version update (1.45.1 -> 1.45.2)
Subpackages: libcom_err2 libext2fs2
- Package e2scrub unit files and separate scrubbing bits into a separate
subpackage e2fsprogs-scrub
- Update to 1.45.2
* Fixed e2scrub_all issues running from cron
* When mke2fs asks to proceed, fall back on English Y/y
* Fix spurious complaint of blocks beyond i_size
* Fixed 'make install' failure when the cron.d dir doesn't exist
==== elfutils ====
Subpackages: libasm1 libdw1 libebl-plugins libelf1
- Update License tag to GPL-3.0-or-later, as requested by legal
review.
- Add fix-bsc-1110929.diff [bsc#1110929]
==== file ====
Version update (5.36 -> 5.37)
Subpackages: file-magic libmagic1
- Update to file version 5.37
* Make sure that continuation separators are printed
with -k within softmagic
* Change SIGPIPE saving and restoring during compression to use
sigaction(2) instead of signal(3) and cache it. (Denys Vlasenko)
* Cache stat(2) calls more to reduce number of calls (Denys Vlasenko)
* PR/77: Handle --mime-type and -k correctly.
* Switch decompression code to use vfork() because
tools like rpmdiff and rpmbuild call libmagic
with large process footprints (Denys Vlasenko)
* PR/75: --enable-zlib, did not work.
* Improve regex efficiency (Michael Schroeder) by:
1. Prefixing regex searches with regular search
for keywords where possible
2. Using memmem(3) where available
- Modify the patches
* file-5.12-zip.dif
* file-5.16-ocloexec.patch
* file-5.17-option.dif
* file-5.19-biorad.dif
* file-5.19-zip2.0.dif
* file-5.22-elf.dif
* file-5.24-nitpick.dif
* file-5.28-btrfs-image.dif
* file-secure_getenv.patch
- Modify and rename patch file-5.36.dif which becomes file-5.37.dif
==== gettext-runtime ====
- reproducible.patch: generate timestamp in .pot files from SOURCE_DATE_EPOCH
for reproducible builds
==== iptables ====
Version update (1.8.2 -> 1.8.3)
Subpackages: libxtables12 xtables-plugins
- Update to new upstream release 1.8.3
* ebtables: Fix rule listing with counters
* ebtables-nft: Support user-defined chain policies
- Remove 0001-include-extend-the-headers-conflict-workaround-to-in.patch
0001-include-fix-build-with-kernel-headers-before-4.2.patch
(upstreamed)
- Add 0001-include-fix-build-with-kernel-headers-before-4.2.patch,
0001-include-extend-the-headers-conflict-workaround-to-in.patch
to fix build with older linux-glibc-devel. [boo#1132821]
==== kexec-tools ====
- Use %license instead of %doc [bsc#1082318]
==== libidn2 ====
Version update (2.1.1 -> 2.2.0)
- Update to version 2.2.0:
* Perform A-Label roundtrip for lookup functions by default
* Stricter check of input to punycode decoder
* Fix punycode decoding with no ASCII chars but given delimiter
* Fix 'idn2 --no-tr64' (was a no-op)
* Allow _ as a basic code point in domain labels
* Fail building documentation if 'ronn' isn't installed
* git tag changed to reflect https://semver.org/
==== libnftnl ====
Version update (1.1.2 -> 1.1.3)
- Update to new upstream release 1.1.3
* expr: osf: add version option support
* udata: add NFTNL_UDATA_* definitions
* chain: support per chain rules listing
==== libselinux ====
Subpackages: libselinux1 selinux-tools
- In selinux-ready
* Removed check for selinux-policy package as we don't ship one
(bsc#1136845)
* Add check that restorecond is installed and enabled
==== libssh ====
- Fix the typo in Obsoletes for -devel-doc subpackage
- Actually remove the description for -devel-doc subpackage
==== metallb ====
- Use official image from registry.opensuse.org
- Use our golang macros as far as possible
- metallb.yaml: use images from opensuse registry
==== numactl ====
- For obs regression checker, this version includes following SLE
fixes:
- enable build for aarch64 (fate#319973) (bsc#976199)
factory has an extra patch to disable ARM 32 bit archs which
looks a bit misleading as %arm macro only covers 32 bit ARM.
- Bug 955334 - numactl/libnuma: add patch for Dynamic Reconfiguration
bsc#955334
==== podman ====
Version update (1.3.1 -> 1.4.0)
Subpackages: podman-cni-config
- Update podman to v1.4.0:
- The podman checkpoint and podman restore commands can now be
used to migrate containers between Podman installations on
different systems
- The podman cp command now supports a pause flag to pause
containers while copying into them
- The remote client now supports a configuration file for
pre-configuring connections to remote Podman installations
- Fixed CVE-2019-10152 - The podman cp command improperly
dereferenced symlinks in host context
- Fixed a bug where podman commit could improperly set
environment variables that contained = characters
- Fixed a bug where rootless Podman would sometimes fail to start
containers with forwarded ports
- Fixed a bug where podman version on the remote client could
segfault
- Fixed a bug where podman container runlabel would use
/proc/self/exe instead of the path of the Podman command when
printing the command being executed
- Fixed a bug where filtering images by label did not work
- Fixed a bug where specifying a bing mount or tmpfs mount over
an image volume would cause a container to be unable to start
- Fixed a bug where podman generate kube did not work with
containers with named volumes
- Fixed a bug where rootless Podman would receive permission
denied errors accessing conmon.pid
- Fixed a bug where podman cp with a folder specified as target
would replace the folder, as opposed to copying into it
- Fixed a bug where rootless Podman commands could double-unlock
a lock, causing a crash
- Fixed a bug where Podman incorrectly set tmpcopyup on /dev/
mounts, causing errors when using the Kata containers runtime
- Fixed a bug where podman exec would fail on older kernels
- The podman commit command is now usable with the Podman remote
client
- The --signature-policy flag (used with several image-related
commands) has been deprecated
- The podman unshare command now defines two environment
variables in the spawned shell: CONTAINERS_RUNROOT and
CONTAINERS_GRAPHROOT, pointing to temporary and permanent
storage for rootless containers
- Updated vendored containers/storage and containers/image
libraries with numerous bugfixes
- Updated vendored Buildah to v1.8.3
- Podman now requires Conmon v0.2.0
- The podman cp command is now aliased as podman container cp
- Rootless Podman will now default init_path using root Podman's
configuration files (/etc/containers/libpod.conf and
/usr/share/containers/libpod.conf) if not overridden in the
rootless configuration
- Add fuse-overlayfs dependency to support overlay based rootless image
manipulations
- Update podman to v1.3.2:
- Fixed a bug where podman would fail to run if a volume was
mounted over an image volume
==== salt ====
Subpackages: python3-salt salt-master salt-minion
- Fix return status when installing or updating RPM packages
with "ppc64le" arch (bsc#1133647)
- Added:
* add-ppc64le-as-a-valid-rpm-package-architecture.patch
- Add new "salt-standalone-formulas-configuration" package
- Added:
* add-standalone-configuration-file-for-enabling-packa.patch
==== shadow ====
- Make building more verbose
- Use spec-cleaner
- don't specify MOTD_FILE in login.defs but fall back to built in
defaults of login (boo#1133929)
==== sqlite3 ====
Version update (3.27.2 -> 3.28.0)
- Upgrade to 3.28.0:
* CVE-2019-9936, bsc#1130326: running fts5 prefix queries inside
a transaction could trigger a heap-based buffer over-read.
* CVE-2019-9937, bsc#1130325: interleaving reads and writes in a
single transaction with an fts5 virtual table will lead to a
NULL Pointer Dereference.
* Enhanced window functions
* Enhanced VACUUM INTO so that it works for read-only databases.
* New query optimizations.
* Added the sqlite3_value_frombind() API for determining if the
argument to an SQL function is from a bound parameter.
* Security and compatibilities enhancements to fts3_tokenizer().
* Improved robustness against corrupt database files.
==== tar ====
Version update (1.31 -> 1.32)
- update to version 1.32
* Fix the use of --checkpoint without explicit --checkpoint-action
* Fix extraction with the -U option
* Fix iconv usage on BSD-based systems
* Fix possible NULL dereference (savannah bug #55369)
[bsc#1130496] [CVE-2019-9923]
* Improve the testsuite
- remove tar-1.31-tests_dirrem.patch and
tar-1.31-racy_compress_tests.patch that are no longer needed
(applied usptream)
==== thin-provisioning-tools ====
Version update (0.7.6 -> 0.8.3)
- Update to version 0.8.3:
* Mostly internal changes
==== xz ====
Subpackages: liblzma5
- add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=microos&groupid=1&version…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
ding-libs
e2fsprogs (1.45.1 -> 1.45.2)
elfutils
file (5.36 -> 5.37)
gettext-runtime
iptables (1.8.2 -> 1.8.3)
kexec-tools
libidn2 (2.1.1 -> 2.2.0)
libnftnl (1.1.2 -> 1.1.3)
libselinux
libssh
numactl
podman (1.3.1 -> 1.4.0)
shadow
sqlite3 (3.27.2 -> 3.28.0)
tar (1.31 -> 1.32)
thin-provisioning-tools (0.7.6 -> 0.8.3)
xz
=== Details ===
==== ding-libs ====
Subpackages: libbasicobjects0 libcollection4 libdhash1 libini_config5 libpath_utils1 libref_array1
- Update to 0.6.1:
* No upstream changelog
- Update URL
* Remove the git link info as it 404 atm
- Add patches from upstream to fix ini behaviour:
* INI-Fix-detection-of-error-messages.patch
* INI-Silence-ini_augment-match-failures.patch
* TEST-validators_ut_check-Fix-fail-with-new-glibc.patch
==== e2fsprogs ====
Version update (1.45.1 -> 1.45.2)
Subpackages: libcom_err2 libext2fs2
- Package e2scrub unit files and separate scrubbing bits into a separate
subpackage e2fsprogs-scrub
- Update to 1.45.2
* Fixed e2scrub_all issues running from cron
* When mke2fs asks to proceed, fall back on English Y/y
* Fix spurious complaint of blocks beyond i_size
* Fixed 'make install' failure when the cron.d dir doesn't exist
==== elfutils ====
Subpackages: libasm1 libdw1 libebl-plugins libelf1
- Update License tag to GPL-3.0-or-later, as requested by legal
review.
- Add fix-bsc-1110929.diff [bsc#1110929]
==== file ====
Version update (5.36 -> 5.37)
Subpackages: file-magic libmagic1
- Update to file version 5.37
* Make sure that continuation separators are printed
with -k within softmagic
* Change SIGPIPE saving and restoring during compression to use
sigaction(2) instead of signal(3) and cache it. (Denys Vlasenko)
* Cache stat(2) calls more to reduce number of calls (Denys Vlasenko)
* PR/77: Handle --mime-type and -k correctly.
* Switch decompression code to use vfork() because
tools like rpmdiff and rpmbuild call libmagic
with large process footprints (Denys Vlasenko)
* PR/75: --enable-zlib, did not work.
* Improve regex efficiency (Michael Schroeder) by:
1. Prefixing regex searches with regular search
for keywords where possible
2. Using memmem(3) where available
- Modify the patches
* file-5.12-zip.dif
* file-5.16-ocloexec.patch
* file-5.17-option.dif
* file-5.19-biorad.dif
* file-5.19-zip2.0.dif
* file-5.22-elf.dif
* file-5.24-nitpick.dif
* file-5.28-btrfs-image.dif
* file-secure_getenv.patch
- Modify and rename patch file-5.36.dif which becomes file-5.37.dif
==== gettext-runtime ====
- reproducible.patch: generate timestamp in .pot files from SOURCE_DATE_EPOCH
for reproducible builds
==== iptables ====
Version update (1.8.2 -> 1.8.3)
Subpackages: libxtables12 xtables-plugins
- Update to new upstream release 1.8.3
* ebtables: Fix rule listing with counters
* ebtables-nft: Support user-defined chain policies
- Remove 0001-include-extend-the-headers-conflict-workaround-to-in.patch
0001-include-fix-build-with-kernel-headers-before-4.2.patch
(upstreamed)
- Add 0001-include-fix-build-with-kernel-headers-before-4.2.patch,
0001-include-extend-the-headers-conflict-workaround-to-in.patch
to fix build with older linux-glibc-devel. [boo#1132821]
==== kexec-tools ====
- Use %license instead of %doc [bsc#1082318]
==== libidn2 ====
Version update (2.1.1 -> 2.2.0)
- Update to version 2.2.0:
* Perform A-Label roundtrip for lookup functions by default
* Stricter check of input to punycode decoder
* Fix punycode decoding with no ASCII chars but given delimiter
* Fix 'idn2 --no-tr64' (was a no-op)
* Allow _ as a basic code point in domain labels
* Fail building documentation if 'ronn' isn't installed
* git tag changed to reflect https://semver.org/
==== libnftnl ====
Version update (1.1.2 -> 1.1.3)
- Update to new upstream release 1.1.3
* expr: osf: add version option support
* udata: add NFTNL_UDATA_* definitions
* chain: support per chain rules listing
==== libselinux ====
Subpackages: libselinux1 selinux-tools
- In selinux-ready
* Removed check for selinux-policy package as we don't ship one
(bsc#1136845)
* Add check that restorecond is installed and enabled
==== libssh ====
- Fix the typo in Obsoletes for -devel-doc subpackage
- Actually remove the description for -devel-doc subpackage
==== numactl ====
- For obs regression checker, this version includes following SLE
fixes:
- enable build for aarch64 (fate#319973) (bsc#976199)
factory has an extra patch to disable ARM 32 bit archs which
looks a bit misleading as %arm macro only covers 32 bit ARM.
- Bug 955334 - numactl/libnuma: add patch for Dynamic Reconfiguration
bsc#955334
==== podman ====
Version update (1.3.1 -> 1.4.0)
Subpackages: podman-cni-config
- Update podman to v1.4.0:
- The podman checkpoint and podman restore commands can now be
used to migrate containers between Podman installations on
different systems
- The podman cp command now supports a pause flag to pause
containers while copying into them
- The remote client now supports a configuration file for
pre-configuring connections to remote Podman installations
- Fixed CVE-2019-10152 - The podman cp command improperly
dereferenced symlinks in host context
- Fixed a bug where podman commit could improperly set
environment variables that contained = characters
- Fixed a bug where rootless Podman would sometimes fail to start
containers with forwarded ports
- Fixed a bug where podman version on the remote client could
segfault
- Fixed a bug where podman container runlabel would use
/proc/self/exe instead of the path of the Podman command when
printing the command being executed
- Fixed a bug where filtering images by label did not work
- Fixed a bug where specifying a bing mount or tmpfs mount over
an image volume would cause a container to be unable to start
- Fixed a bug where podman generate kube did not work with
containers with named volumes
- Fixed a bug where rootless Podman would receive permission
denied errors accessing conmon.pid
- Fixed a bug where podman cp with a folder specified as target
would replace the folder, as opposed to copying into it
- Fixed a bug where rootless Podman commands could double-unlock
a lock, causing a crash
- Fixed a bug where Podman incorrectly set tmpcopyup on /dev/
mounts, causing errors when using the Kata containers runtime
- Fixed a bug where podman exec would fail on older kernels
- The podman commit command is now usable with the Podman remote
client
- The --signature-policy flag (used with several image-related
commands) has been deprecated
- The podman unshare command now defines two environment
variables in the spawned shell: CONTAINERS_RUNROOT and
CONTAINERS_GRAPHROOT, pointing to temporary and permanent
storage for rootless containers
- Updated vendored containers/storage and containers/image
libraries with numerous bugfixes
- Updated vendored Buildah to v1.8.3
- Podman now requires Conmon v0.2.0
- The podman cp command is now aliased as podman container cp
- Rootless Podman will now default init_path using root Podman's
configuration files (/etc/containers/libpod.conf and
/usr/share/containers/libpod.conf) if not overridden in the
rootless configuration
- Add fuse-overlayfs dependency to support overlay based rootless image
manipulations
- Update podman to v1.3.2:
- Fixed a bug where podman would fail to run if a volume was
mounted over an image volume
==== shadow ====
- Make building more verbose
- Use spec-cleaner
- don't specify MOTD_FILE in login.defs but fall back to built in
defaults of login (boo#1133929)
==== sqlite3 ====
Version update (3.27.2 -> 3.28.0)
- Upgrade to 3.28.0:
* CVE-2019-9936, bsc#1130326: running fts5 prefix queries inside
a transaction could trigger a heap-based buffer over-read.
* CVE-2019-9937, bsc#1130325: interleaving reads and writes in a
single transaction with an fts5 virtual table will lead to a
NULL Pointer Dereference.
* Enhanced window functions
* Enhanced VACUUM INTO so that it works for read-only databases.
* New query optimizations.
* Added the sqlite3_value_frombind() API for determining if the
argument to an SQL function is from a bound parameter.
* Security and compatibilities enhancements to fts3_tokenizer().
* Improved robustness against corrupt database files.
==== tar ====
Version update (1.31 -> 1.32)
- update to version 1.32
* Fix the use of --checkpoint without explicit --checkpoint-action
* Fix extraction with the -U option
* Fix iconv usage on BSD-based systems
* Fix possible NULL dereference (savannah bug #55369)
[bsc#1130496] [CVE-2019-9923]
* Improve the testsuite
- remove tar-1.31-tests_dirrem.patch and
tar-1.31-racy_compress_tests.patch that are no longer needed
(applied usptream)
==== thin-provisioning-tools ====
Version update (0.7.6 -> 0.8.3)
- Update to version 0.8.3:
* Mostly internal changes
==== xz ====
Subpackages: liblzma5
- add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
Please note that this mail was generated by a script.
The described changes are computed based on the x86_64 DVD.
The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=kubic&groupid=1&version=T…
https://bugzilla.opensuse.org/buglist.cgi?product=openSUSE%20Tumbleweed&com…
Please do not reply to this email to report issues, rather file a bug on bugzilla.…
[View More]opensuse.org.
For more information on filing bugs please see https://en.opensuse.org/openSUSE:Submitting_bug_reports
Packages changed:
ceph (14.2.1.463+g99339b576a -> 14.2.1.468+g994fd9e0cc)
cri-o
ding-libs
e2fsprogs (1.45.1 -> 1.45.2)
elfutils
file (5.36 -> 5.37)
gettext-runtime
iptables (1.8.2 -> 1.8.3)
kexec-tools
libidn2 (2.1.1 -> 2.2.0)
libnftnl (1.1.2 -> 1.1.3)
libselinux
libssh
metallb
numactl
podman (1.3.1 -> 1.4.0)
salt
shadow
sqlite3 (3.27.2 -> 3.28.0)
tar (1.31 -> 1.32)
thin-provisioning-tools (0.7.6 -> 0.8.3)
xz
=== Details ===
==== ceph ====
Version update (14.2.1.463+g99339b576a -> 14.2.1.468+g994fd9e0cc)
Subpackages: ceph-common libcephfs2 librados2 libradosstriper1 librbd1 librgw2 python3-ceph-argparse python3-cephfs python3-rados python3-rbd python3-rgw
- Update to 14.2.1-468-g994fd9e0cc:
+ spec:
* install grafana dashboards world readable (bsc#1136110)
* put "without python2" conditionals around python3-* provides/obsoletes
(align with upstream)
- Update to 14.2.1-467-g9e10776aa2:
+ mon/Monitor: allow probe if MMonProbe::mon_release == 0 (bsc#1132396)
+ spec: make python3-rgw replace python-rgw on upgrade
==== cri-o ====
Subpackages: cri-o-kubeadm-criconfig
- Add apparmor-parser as dependency
==== ding-libs ====
Subpackages: libbasicobjects0 libcollection4 libdhash1 libini_config5 libpath_utils1 libref_array1
- Update to 0.6.1:
* No upstream changelog
- Update URL
* Remove the git link info as it 404 atm
- Add patches from upstream to fix ini behaviour:
* INI-Fix-detection-of-error-messages.patch
* INI-Silence-ini_augment-match-failures.patch
* TEST-validators_ut_check-Fix-fail-with-new-glibc.patch
==== e2fsprogs ====
Version update (1.45.1 -> 1.45.2)
Subpackages: libcom_err2 libext2fs2
- Package e2scrub unit files and separate scrubbing bits into a separate
subpackage e2fsprogs-scrub
- Update to 1.45.2
* Fixed e2scrub_all issues running from cron
* When mke2fs asks to proceed, fall back on English Y/y
* Fix spurious complaint of blocks beyond i_size
* Fixed 'make install' failure when the cron.d dir doesn't exist
==== elfutils ====
Subpackages: libasm1 libdw1 libebl-plugins libelf1
- Update License tag to GPL-3.0-or-later, as requested by legal
review.
- Add fix-bsc-1110929.diff [bsc#1110929]
==== file ====
Version update (5.36 -> 5.37)
Subpackages: file-magic libmagic1
- Update to file version 5.37
* Make sure that continuation separators are printed
with -k within softmagic
* Change SIGPIPE saving and restoring during compression to use
sigaction(2) instead of signal(3) and cache it. (Denys Vlasenko)
* Cache stat(2) calls more to reduce number of calls (Denys Vlasenko)
* PR/77: Handle --mime-type and -k correctly.
* Switch decompression code to use vfork() because
tools like rpmdiff and rpmbuild call libmagic
with large process footprints (Denys Vlasenko)
* PR/75: --enable-zlib, did not work.
* Improve regex efficiency (Michael Schroeder) by:
1. Prefixing regex searches with regular search
for keywords where possible
2. Using memmem(3) where available
- Modify the patches
* file-5.12-zip.dif
* file-5.16-ocloexec.patch
* file-5.17-option.dif
* file-5.19-biorad.dif
* file-5.19-zip2.0.dif
* file-5.22-elf.dif
* file-5.24-nitpick.dif
* file-5.28-btrfs-image.dif
* file-secure_getenv.patch
- Modify and rename patch file-5.36.dif which becomes file-5.37.dif
==== gettext-runtime ====
- reproducible.patch: generate timestamp in .pot files from SOURCE_DATE_EPOCH
for reproducible builds
==== iptables ====
Version update (1.8.2 -> 1.8.3)
Subpackages: libxtables12 xtables-plugins
- Update to new upstream release 1.8.3
* ebtables: Fix rule listing with counters
* ebtables-nft: Support user-defined chain policies
- Remove 0001-include-extend-the-headers-conflict-workaround-to-in.patch
0001-include-fix-build-with-kernel-headers-before-4.2.patch
(upstreamed)
- Add 0001-include-fix-build-with-kernel-headers-before-4.2.patch,
0001-include-extend-the-headers-conflict-workaround-to-in.patch
to fix build with older linux-glibc-devel. [boo#1132821]
==== kexec-tools ====
- Use %license instead of %doc [bsc#1082318]
==== libidn2 ====
Version update (2.1.1 -> 2.2.0)
- Update to version 2.2.0:
* Perform A-Label roundtrip for lookup functions by default
* Stricter check of input to punycode decoder
* Fix punycode decoding with no ASCII chars but given delimiter
* Fix 'idn2 --no-tr64' (was a no-op)
* Allow _ as a basic code point in domain labels
* Fail building documentation if 'ronn' isn't installed
* git tag changed to reflect https://semver.org/
==== libnftnl ====
Version update (1.1.2 -> 1.1.3)
- Update to new upstream release 1.1.3
* expr: osf: add version option support
* udata: add NFTNL_UDATA_* definitions
* chain: support per chain rules listing
==== libselinux ====
Subpackages: libselinux1 selinux-tools
- In selinux-ready
* Removed check for selinux-policy package as we don't ship one
(bsc#1136845)
* Add check that restorecond is installed and enabled
==== libssh ====
- Fix the typo in Obsoletes for -devel-doc subpackage
- Actually remove the description for -devel-doc subpackage
==== metallb ====
- Use official image from registry.opensuse.org
- Use our golang macros as far as possible
- metallb.yaml: use images from opensuse registry
==== numactl ====
- For obs regression checker, this version includes following SLE
fixes:
- enable build for aarch64 (fate#319973) (bsc#976199)
factory has an extra patch to disable ARM 32 bit archs which
looks a bit misleading as %arm macro only covers 32 bit ARM.
- Bug 955334 - numactl/libnuma: add patch for Dynamic Reconfiguration
bsc#955334
==== podman ====
Version update (1.3.1 -> 1.4.0)
Subpackages: podman-cni-config
- Update podman to v1.4.0:
- The podman checkpoint and podman restore commands can now be
used to migrate containers between Podman installations on
different systems
- The podman cp command now supports a pause flag to pause
containers while copying into them
- The remote client now supports a configuration file for
pre-configuring connections to remote Podman installations
- Fixed CVE-2019-10152 - The podman cp command improperly
dereferenced symlinks in host context
- Fixed a bug where podman commit could improperly set
environment variables that contained = characters
- Fixed a bug where rootless Podman would sometimes fail to start
containers with forwarded ports
- Fixed a bug where podman version on the remote client could
segfault
- Fixed a bug where podman container runlabel would use
/proc/self/exe instead of the path of the Podman command when
printing the command being executed
- Fixed a bug where filtering images by label did not work
- Fixed a bug where specifying a bing mount or tmpfs mount over
an image volume would cause a container to be unable to start
- Fixed a bug where podman generate kube did not work with
containers with named volumes
- Fixed a bug where rootless Podman would receive permission
denied errors accessing conmon.pid
- Fixed a bug where podman cp with a folder specified as target
would replace the folder, as opposed to copying into it
- Fixed a bug where rootless Podman commands could double-unlock
a lock, causing a crash
- Fixed a bug where Podman incorrectly set tmpcopyup on /dev/
mounts, causing errors when using the Kata containers runtime
- Fixed a bug where podman exec would fail on older kernels
- The podman commit command is now usable with the Podman remote
client
- The --signature-policy flag (used with several image-related
commands) has been deprecated
- The podman unshare command now defines two environment
variables in the spawned shell: CONTAINERS_RUNROOT and
CONTAINERS_GRAPHROOT, pointing to temporary and permanent
storage for rootless containers
- Updated vendored containers/storage and containers/image
libraries with numerous bugfixes
- Updated vendored Buildah to v1.8.3
- Podman now requires Conmon v0.2.0
- The podman cp command is now aliased as podman container cp
- Rootless Podman will now default init_path using root Podman's
configuration files (/etc/containers/libpod.conf and
/usr/share/containers/libpod.conf) if not overridden in the
rootless configuration
- Add fuse-overlayfs dependency to support overlay based rootless image
manipulations
- Update podman to v1.3.2:
- Fixed a bug where podman would fail to run if a volume was
mounted over an image volume
==== salt ====
Subpackages: python3-salt salt-master salt-minion
- Fix return status when installing or updating RPM packages
with "ppc64le" arch (bsc#1133647)
- Added:
* add-ppc64le-as-a-valid-rpm-package-architecture.patch
- Add new "salt-standalone-formulas-configuration" package
- Added:
* add-standalone-configuration-file-for-enabling-packa.patch
==== shadow ====
- Make building more verbose
- Use spec-cleaner
- don't specify MOTD_FILE in login.defs but fall back to built in
defaults of login (boo#1133929)
==== sqlite3 ====
Version update (3.27.2 -> 3.28.0)
- Upgrade to 3.28.0:
* CVE-2019-9936, bsc#1130326: running fts5 prefix queries inside
a transaction could trigger a heap-based buffer over-read.
* CVE-2019-9937, bsc#1130325: interleaving reads and writes in a
single transaction with an fts5 virtual table will lead to a
NULL Pointer Dereference.
* Enhanced window functions
* Enhanced VACUUM INTO so that it works for read-only databases.
* New query optimizations.
* Added the sqlite3_value_frombind() API for determining if the
argument to an SQL function is from a bound parameter.
* Security and compatibilities enhancements to fts3_tokenizer().
* Improved robustness against corrupt database files.
==== tar ====
Version update (1.31 -> 1.32)
- update to version 1.32
* Fix the use of --checkpoint without explicit --checkpoint-action
* Fix extraction with the -U option
* Fix iconv usage on BSD-based systems
* Fix possible NULL dereference (savannah bug #55369)
[bsc#1130496] [CVE-2019-9923]
* Improve the testsuite
- remove tar-1.31-tests_dirrem.patch and
tar-1.31-racy_compress_tests.patch that are no longer needed
(applied usptream)
==== thin-provisioning-tools ====
Version update (0.7.6 -> 0.8.3)
- Update to version 0.8.3:
* Mostly internal changes
==== xz ====
Subpackages: liblzma5
- add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0
11 Jun '19
Hi,
to make it much easier to setup kubernetes on openSUSE Kubic, we
integrated kubicd/kubicctl into YaST. So there is nothing to
configure anymore for KubicD, you can login and immeaditly
start deploying Kubernetes with kubicctl. Ok, almost, to add a node,
you have to configure and start a salt-minion on a worker node. We
are still looking for a YaST developer, who could integrate this
into the installation process ;)
It is still marked as "Alpha", but works already fine.
A describtion …
[View More]how to use it can be found here:
https://en.opensuse.org/Kubic:KubicD_and_kubicctl
Thorsten
--
Thorsten Kukuk, Distinguished Engineer, Senior Architect SLES & MicroOS
SUSE Linux GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany
GF: Felix Imendoerffer, Mary Higgins, Sri Rasiah, HRB 21284 (AG Nuernberg)
--
To unsubscribe, e-mail: opensuse-kubic+unsubscribe(a)opensuse.org
To contact the owner, e-mail: opensuse-kubic+owner(a)opensuse.org
[View Less]
1
0