Please note that this mail was generated by a script.
The described changes are computed based on the aarch64 DVD.
The full online repo contains too many changes to be listed here.

Please check the known defects of this snapshot before upgrading:
https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=3&version=Tumbleweed&build=20241113

Please do not reply to this email to report issues, rather file a bug
on bugzilla.opensuse.org. For more information on filing bugs please
see https://en.opensuse.org/openSUSE:Submitting_bug_reports

Packages changed:
  alsa (1.2.12 -> 1.2.13)
  alsa-ucm-conf (1.2.12 -> 1.2.13)
  alsa-utils (1.2.12 -> 1.2.13)
  grub2
  libheif (1.19.2 -> 1.19.3)
  libopenmpt (0.7.10 -> 0.7.11)
  libsemanage
  libsoup
  libsoup2
  llvm18
  nghttp2 (1.62.1 -> 1.64.0)
  openSUSE-release (20241112 -> 20241113)
  openssl-3
  qt6-declarative
  schily
  wget (1.24.5 -> 1.25.0)
  yast2-iscsi-client (5.0.3 -> 5.0.4)

=== Details ===

==== alsa ====
Version update (1.2.12 -> 1.2.13)
Subpackages: libasound2 libatopology2

- Update to alsa-lib 1.2.13:
  * static build fixes
  * documentation update for control remap API
  * PCM dmix fixes
  * pcm: implement snd_pcm_hw_params_get_sync() and obsolete 
snd_pcm_info_get_sync()
  * ump: Add a function to provide the packet word length of a UMP type
  * seq: Add snd_seq_{get|set}_ump_is_midi1() API functions
  * seq: Add API functions to set different tempo base values
  * seq: Add API helper functions for creating UMP Endpoint and Blocks
  * documentation fixes for UMP and sequencer API
  * test: Add an example programs for UMP
  For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-lib
- Conditionally take libtool

==== alsa-ucm-conf ====
Version update (1.2.12 -> 1.2.13)

- Update to version 1.2.13:
  * Updates for USB-audio, Mediatek, Qualcomm, ACP, SoundWire,
    wsa884x, wcd938x, Intel AVS, SOF HDA, etc
  For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-ucm-conf

==== alsa-utils ====
Version update (1.2.12 -> 1.2.13)

- Update to alsa-utils 1.2.13:
  * alsactl: add support for AMD ACP digital microphone
  * aplay: Print '=== PAUSE ===' only if it is supported
  * aplaymidi/arecordmidi: Allow to pass 0 to -u option, too
  * new aplaymidi2/arecordmidi2 for MIDI v2.0
  * aseqdump: improved UMP supports
  * various topology updates
  * aseqsend: improvement and UMP supports
  For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-utils

==== grub2 ====
Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin 
grub2-systemd-sleep-plugin

- Revert the patches related to BLS support in grub2-mkconfig, as they are not
  relevant to the current BLS integration and cause issues in older KIWI
  versions, which actively force it to be enabled by default (bsc#1233196)
  * 0002-Add-BLS-support-to-grub-mkconfig.patch
  * 0003-Add-grub2-switch-to-blscfg.patch
  * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch
  * 0008-blscfg-reading-bls-fragments-if-boot-present.patch
  * 0009-10_linux-Some-refinement-for-BLS.patch
  * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch

==== libheif ====
Version update (1.19.2 -> 1.19.3)
Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg 
libheif-jpeg libheif-openjpeg libheif-rav1e libheif-svtenc libheif1

- update to 1.19.2:
  * fixes a race condition that may lead to some image tiles not being
    included in the output image (#1379)
  * fix a potential crash when querying overlay image information

==== libopenmpt ====
Version update (0.7.10 -> 0.7.11)

- Update to 0.7.11:
  * IT: Don’t import SAx High Offset command for IT 1.xx modules.
    This feature was added in Impulse Tracker 2.00.
  * IT: Limit Vxx parameter to V80 for files made with old Schism
    Tracker versions.
  * IT / S3M: Impulse Tracker 2.14 patch version information was
    incorrect.
  * S3M: O00 effects are no longer ignored if the tracker version
    in the file header indicates Scream Tracker 3.00 / 3.01,
    but the file was clearly saved with another tool (e.g. UNMO3).
  * S3M: As files made with Scream Tracker 3.20 and 3.21 cannot be
    told apart, both versions are now listed in the tracker
    metadata.
  * ULT: Try to preserve global commands if there’s e.g. both a
    speed and tempo command in the same cell.
  * STM: Improved tracker identification metadata.
  * SymMOD: When running out of Zxx macros, try to find the closest
    macro to use instead.
  * SymMOD: Ignore unknown hunks instead of rejecting entire file,
    as that’s what Symphonie does as well.
  * OKT: Disable loop on type “B” samples if they’re used on a
    mixed channel.
  * OKT: The last sample slot was never loaded.
  * PTM: Halve offset command strength for 16-bit samples.

==== libsemanage ====
Subpackages: libsemanage-conf libsemanage2

- Not conflict but obsolete libsemanage1 (bsc#1229757)

==== libsoup ====
Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0

- Add 6adc0e3e.patch: websocket: Process the frame as soon as we
  read data (boo#1233287 CVE-2024-52532 glgo#GNOME/libsoup#391).
- Add 29b96fab.patch: websocket-test: disconnect error copy after
  the test ends (glgo#GNOME/libsoup#391).
- Add a35222dd.patch: be more robust against invalid input when
  parsing params (boo#1233292 CVE-2024-52531
  glgo#GNOME/libsoup!407).

==== libsoup2 ====

- Add 04df03bc.patch: strictly don't allow NUL bytes in headers
  (boo#1233285 CVE-2024-52530 glgo#GNOME/libsoup#377).
- Add libsoup-CVE-2024-52532.patch: websocket: Process the frame as
  soon as we read data (boo#1233287 CVE-2024-52532).
- Add 29b96fab.patch: websocket-test: disconnect error copy after
  the test ends (glgo#GNOME/libsoup#391).
- Add a35222dd.patch: be more robust against invalid input when
  parsing params (boo#1233292 CVE-2024-52531
  glgo#GNOME/libsoup!407).

==== llvm18 ====
Subpackages: clang18 libLLVM18 libclang-cpp18 libclang_rt18 llvm18-gold

- Require libffi when we build openmp for offloading.
- Update llvm18.keyring from upstream.
- Enable lldb on s390x and ppc64le (bsc#1232906).

==== nghttp2 ====
Version update (1.62.1 -> 1.64.0)

- version update to 1.64.0
  1.64.0
  * Change clang-format options by @tatsuhiro-t in #2240
  * build(deps): bump github.com/quic-go/quic-go from 0.46.0 to 0.47.0 by 
@dependabot in #2243
  * build(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 by @dependabot in 
#2244
  * nghttp2_map: Port ngtcp2 changes by @tatsuhiro-t in #2245
  * h2load: Fix UDP datagram send/recv metric by @tatsuhiro-t in #2248
  * build(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 by @dependabot in 
#2252
  * fix race condition on h1 connection close by @TuxInvader in #2249
  * Gha ubuntu 24.04 by @tatsuhiro-t in #2254
  * GHA: Run tests for i686-w64-mingw32 host by @tatsuhiro-t in #2255
  * cmake: Fix c-ares v1.34.0 version detection failure by @tatsuhiro-t in #2256
  * fix: -Wextra-semi errors in nghttp2_helper.h by @codebytere in #2258
  * clang-format macros that do not need semicolon at the end by @tatsuhiro-t 
in #2259
  * Remove extra semicolons by @tatsuhiro-t in #2260
  * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2261
  * Do not allow '@' in :authority or host field values by @tatsuhiro-t in #2262
  * h2load: GRO buffer size should be 64KiB by @tatsuhiro-t in #2263
  * Bump libbpf to v1.4.6 by @tatsuhiro-t in #2264
  * Update nghttp2_check_authority doc by @tatsuhiro-t in #2265
  1.63.0
  * Bump libbpf to v1.4.2 by @tatsuhiro-t in #2191
  * build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 by @dependabot in 
#2193
  * nghttpx: Fix batch UDP QUIC packet dropped on GRO read by @tatsuhiro-t in 
#2196
  * CMakeLists.txt: allow to compile the C only lib without CXX compiler by 
@ThomasDevoogdt in #2200
  * build(deps): bump github.com/quic-go/quic-go from 0.43.1 to 0.44.0 by 
@dependabot in #2197
  * Fix compiler versions in readme by @ryandesign in #2203
  * build(deps): bump golang.org/x/net from 0.25.0 to 0.26.0 by @dependabot in 
#2205
  * build(deps): bump github.com/quic-go/quic-go from 0.44.0 to 0.45.0 by 
@dependabot in #2206
  * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2207
  * build(deps): bump docker/build-push-action from 5 to 6 by @dependabot in 
#2208
  * Add wolfSSL support by @tatsuhiro-t in #2209
  * Append --shallow-submodules to git clone --recursive by @tatsuhiro-t in 
#2210
  * Always append options to extra options by @tatsuhiro-t in #2211
  * build(deps): bump github.com/quic-go/quic-go from 0.45.0 to 0.45.1 by 
@dependabot in #2213
  * Disable dependency tracking by @tatsuhiro-t in #2214
  * Fix Dockerfile.android build failure by @tatsuhiro-t in #2215
  * Fix UDP_GRO struct cmsghdr data type by @tatsuhiro-t in #2216
  * GHA: Suppress warnings by @tatsuhiro-t in #2217
  * Fix levenshtein initialization by @tatsuhiro-t in #2218
  * build(deps): bump golang.org/x/net from 0.26.0 to 0.27.0 by @dependabot in 
#2220
  * Undefine NGHTTP2_NO_SSIZE_T if BUILDING_NGHTTP2 is defined by @tatsuhiro-t 
in #2224
  * Bump clang format by @tatsuhiro-t in #2226
  * Suppress old compiler error by @tatsuhiro-t in #2228
  * build(deps): bump github.com/quic-go/quic-go from 0.45.1 to 0.45.2 by 
@dependabot in #2229
  * build(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 by @dependabot in 
#2231
  * build(deps): bump github.com/quic-go/quic-go from 0.45.2 to 0.46.0 by 
@dependabot in #2232
  * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2236
  * Bump libbpf to v1.4.5 by @tatsuhiro-t in #2237
  * Update go by @tatsuhiro-t in #2238
  * levenshtein: Use size_t by @tatsuhiro-t in #2239

==== openSUSE-release ====
Version update (20241112 -> 20241113)
Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd

- automatically generated by openSUSE-release-tools/pkglistgen

==== openssl-3 ====
Subpackages: libopenssl3

- Do not use HASHBANGPERL to avoid introducing a dependency on the
  perl-base package. [bsc#1233235]
- Add missing fixes for SHA3_squeeze and quic_multistream_test on
  pcc64 arch. [jsc#PED-10280]
  * Added openssl-3-fix-sha3-squeeze-ppc64.patch
  * Added openssl-3-fix-quic_multistream_test.patch

==== qt6-declarative ====
Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 
libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 
libQt6LabsSharedImage6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 
libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 
libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 
libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 
libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 
libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 
libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 
libQt6QuickWidgets6 qt6-declarative-imports

- Replace 0001-WIP-speculative-gc-fix.patch with newer ones,
  should unbreak spectacle and some others (kde#496139):
  * 0001-Log-state-transitions-for-the-GC.patch
  * 0001-Engine-Mark-created-wrapped-objects-after-GCState-Ma.patch

==== schily ====
Subpackages: libcdrdeflt1_0 libdeflt1_0 libfile1_0 libfind4_0 librmt1_0 
librscg1_0 libscg1_0 libscgcmd1_0 libschily2_0 mkisofs spax star

- Modernize specfile

==== wget ====
Version update (1.24.5 -> 1.25.0)

- GNU wget 1.25.0:
  * New testcase for pathconf truncation
  * Fix libproxy build with --disable-debug
  * [BREAKING CHANGE] Support continious reading from stdin pipes
  * Properly re-implement userinfo parsing (rfc2396)
  * init: fix -Warray-bounds in setval_internal_tilde
  * Fix build error on MingW with `G_GETFL` and `F_SETFL` flags
  * Fix returning uninitialized variable
  * Fix a static analysis false positive
  * [BREAKING CHANGE] Fix CVE-2024-10524 (drop support for shorthand URLs)
    (bsc#1233256)
- Remove committed patches
  * properly-re-implement-userinfo-parsing.patch
- Renumber patches

==== yast2-iscsi-client ====
Version update (5.0.3 -> 5.0.4)

- Fixes for bsc#1231385
  - Do not call iscsi_offload.sh script anymore using the iscsi
    ifaces created by autoLogOn directly and exposing them in the
    UI instead of the offload card selection.
- 5.0.4


Reply via email to