Packages changed: Mesa (26.2.1 -> 26.2.2) Mesa-drivers (26.2.1 -> 26.2.2) MicroOS-release (20260830 -> 20260912) NetworkManager SDL3 (3.4.14 -> 3.4.16) appstream-glib (0.8.3 -> 0.8.4) aurorae6 (6.7.4 -> 6.7.5) baloo-widgets (26.08.0 -> 26.08.1) blog (2.47 -> 2.48) bluedevil6 (6.7.4 -> 6.7.5) boost-base breeze6 (6.7.4 -> 6.7.5) breeze6-gtk (6.7.4 -> 6.7.5) bubblewrap (0.11.2 -> 0.12.0) chrony cockpit coreutils coreutils-systemd cpio curl (8.21.0 -> 8.22.0) dialog discover6 (6.7.4 -> 6.7.5) dmidecode docker (29.4.0_ce -> 29.7.2_ce) dolphin (26.08.0 -> 26.08.1) dracut (112+suse.34.g35e16b7 -> 112+suse.51.gf078a84) exiv2 (0.28.8 -> 0.28.9) expat (2.8.2 -> 2.8.4) falkon (26.08.0 -> 26.08.1) ffmpeg-8 ffmpegthumbs (26.08.0 -> 26.08.1) flatpak-kcm6 (6.7.4 -> 6.7.5) fuse3 (3.18.2 -> 3.18.3) gcc16 glibc (2.43 -> 2.44) google-noto-fonts (20260801 -> 20260901) gpg2 (2.5.21 -> 2.5.22) gpgme (2.1.2 -> 2.2.0) gpgmepp (2.1.0 -> 2.2.0) grub2 gstreamer (1.28.6 -> 1.28.7) gstreamer-plugins-bad (1.28.6 -> 1.28.7) gstreamer-plugins-base (1.28.6 -> 1.28.7) gtk3 (3.24.52 -> 3.24.52+git59.b30343717d) harfbuzz (14.3.1 -> 14.4.0) hwdata (0.410 -> 0.411) iproute2 (7.1 -> 7.2) kaccounts-integration (26.08.0 -> 26.08.1) kaccounts-providers (26.08.0 -> 26.08.1) kactivitymanagerd6 (6.7.4 -> 6.7.5) kate (26.08.0 -> 26.08.1) kde-cli-tools6 (6.7.4 -> 6.7.5) kde-gtk-config6 (6.7.4 -> 6.7.5) kdecoration6 (6.7.4 -> 6.7.5) kdegraphics-mobipocket (26.08.0 -> 26.08.1) kdegraphics-thumbnailers (26.08.0 -> 26.08.1) kdenetwork-filesharing (26.08.0 -> 26.08.1) kdeplasma6-addons (6.7.4 -> 6.7.5) kdialog (26.08.0 -> 26.08.1) kernel-firmware-amdgpu (20260717 -> 20260829) kernel-firmware-ath10k (20260610 -> 20260809) kernel-firmware-ath12k (20260610 -> 20260813) kernel-firmware-bluetooth (20260720 -> 20260828) kernel-firmware-i915 (20260706 -> 20260806) kernel-firmware-intel (20260610 -> 20260728) kernel-firmware-iwlwifi (20260610 -> 20260820) kernel-firmware-media (20260706 -> 20260813) kernel-firmware-mediatek (20260629 -> 20260825) kernel-firmware-network (20260610 -> 20260813) kernel-firmware-qcom (20260717 -> 20260828) kernel-firmware-qlogic (20260610 -> 20260731) kernel-firmware-realtek (20260629 -> 20260731) kernel-firmware-sound (20260706 -> 20260825) kernel-firmware-ueagle (20260610 -> 20260703) kernel-source (7.2.2 -> 7.2.4) kf6-attica (6.29.0 -> 6.30.0) kf6-baloo (6.29.0 -> 6.30.0) kf6-bluez-qt (6.29.0 -> 6.30.0) kf6-breeze-icons (6.29.0 -> 6.30.0) kf6-frameworkintegration (6.29.0 -> 6.30.0) kf6-karchive (6.29.0 -> 6.30.0) kf6-kauth (6.29.0 -> 6.30.0) kf6-kbookmarks (6.29.0 -> 6.30.0) kf6-kcmutils (6.29.0 -> 6.30.0) kf6-kcodecs (6.29.0 -> 6.30.0) kf6-kcolorscheme (6.29.0 -> 6.30.0) kf6-kcompletion (6.29.0 -> 6.30.0) kf6-kconfig (6.29.0 -> 6.30.0) kf6-kconfigwidgets (6.29.0 -> 6.30.0) kf6-kcontacts (6.29.0 -> 6.30.0) kf6-kcoreaddons (6.29.0 -> 6.30.0) kf6-kcrash (6.29.0 -> 6.30.0) kf6-kdbusaddons (6.29.0 -> 6.30.0) kf6-kdeclarative (6.29.0 -> 6.30.0) kf6-kded (6.29.0 -> 6.30.0) kf6-kdesu (6.29.0 -> 6.30.0) kf6-kdnssd (6.29.0 -> 6.30.0) kf6-kdoctools (6.29.0 -> 6.30.0) kf6-kfilemetadata (6.29.0 -> 6.30.0) kf6-kglobalaccel (6.29.0 -> 6.30.0) kf6-kguiaddons (6.29.0 -> 6.30.0) kf6-kholidays (6.29.0 -> 6.30.0) kf6-ki18n (6.29.0 -> 6.30.0) kf6-kiconthemes (6.29.0 -> 6.30.0) kf6-kidletime (6.29.0 -> 6.30.0) kf6-kimageformats (6.29.0 -> 6.30.0) kf6-kio (6.29.0 -> 6.30.0) kf6-kirigami (6.29.0 -> 6.30.0) kf6-kitemmodels (6.29.0 -> 6.30.0) kf6-kitemviews (6.29.0 -> 6.30.0) kf6-kjobwidgets (6.29.0 -> 6.30.0) kf6-knewstuff (6.29.0 -> 6.30.0) kf6-knotifications (6.29.0 -> 6.30.0) kf6-knotifyconfig (6.29.0 -> 6.30.0) kf6-kpackage (6.29.0 -> 6.30.0) kf6-kparts (6.29.0 -> 6.30.0) kf6-kpty (6.29.0 -> 6.30.0) kf6-kquickcharts (6.29.0 -> 6.30.0) kf6-krunner (6.29.0 -> 6.30.0) kf6-kservice (6.29.0 -> 6.30.0) kf6-kstatusnotifieritem (6.29.0 -> 6.30.0) kf6-ksvg (6.29.0 -> 6.30.0) kf6-ktexteditor (6.29.0 -> 6.30.0) kf6-ktextwidgets (6.29.0 -> 6.30.0) kf6-kunitconversion (6.29.0 -> 6.30.0) kf6-kuserfeedback (6.29.0 -> 6.30.0) kf6-kwallet (6.29.0 -> 6.30.0) kf6-kwidgetsaddons (6.29.0 -> 6.30.0) kf6-kwindowsystem (6.29.0 -> 6.30.0) kf6-kxmlgui (6.29.0 -> 6.30.0) kf6-modemmanager-qt (6.29.0 -> 6.30.0) kf6-networkmanager-qt (6.29.0 -> 6.30.0) kf6-prison (6.29.0 -> 6.30.0) kf6-purpose (6.29.0 -> 6.30.0) kf6-qqc2-desktop-style (6.29.0 -> 6.30.0) kf6-solid (6.29.0 -> 6.30.0) kf6-sonnet (6.29.0 -> 6.30.0) kf6-syndication (6.29.0 -> 6.30.0) kf6-syntax-highlighting (6.29.0 -> 6.30.0) kgamma6 (6.7.4 -> 6.7.5) kglobalacceld6 (6.7.4 -> 6.7.5) kinfocenter6 (6.7.4 -> 6.7.5) kio-extras (26.08.0 -> 26.08.1) kio-gdrive (26.08.0 -> 26.08.1) kmenuedit6 (6.7.4 -> 6.7.5) knighttime6 (6.7.4 -> 6.7.5) konsole (26.08.0 -> 26.08.1) kpipewire6 (6.7.4 -> 6.7.5) kpmcore (26.08.0 -> 26.08.1) kquickimageeditor6 (0.6.2.1 -> 0.7.0.1) kscreen6 (6.7.4 -> 6.7.5) kscreenlocker6 (6.7.4 -> 6.7.5) ksshaskpass6 (6.7.4 -> 6.7.5) ksystemstats6 (6.7.4 -> 6.7.5) kwalletmanager (26.08.0 -> 26.08.1) kwayland-integration6 (6.7.4 -> 6.7.5) kwayland6 (6.7.4 -> 6.7.5) kwin6 (6.7.4 -> 6.7.5) layer-shell-qt6 (6.7.4 -> 6.7.5) libarchive (3.8.7 -> 3.8.9) libbpf libcupsfilters libfido2 libgcrypt (1.12.2 -> 1.12.3) libheif (1.23.1 -> 1.23.4) libjpeg-turbo libkdcraw (26.08.0 -> 26.08.1) libkexiv2-qt6 (26.08.0 -> 26.08.1) libkgapi6 (26.08.0 -> 26.08.1) libksba (1.8.0 -> 1.8.1) libkscreen6 (6.7.4 -> 6.7.5) libksysguard6 (6.7.4 -> 6.7.5) libnftnl (1.3.1 -> 1.3.2) libpisp (1.6.0 -> 1.7.0) libplasma6 (6.7.4 -> 6.7.5) libupnp (22.0.6 -> 22.1.0) libxml2 (2.15.3 -> 2.15.4) libzypp (17.38.14 -> 17.38.15) live555 (2026.08.14 -> 2026.08.25) milou6 (6.7.4 -> 6.7.5) mozilla-nspr (4.39 -> 4.40) mozilla-nss (3.126.1 -> 3.127) multipath-tools (0.15.1+227+suse.6644513 -> 0.15.1+229+suse.6c6f63e) nftables (1.1.6 -> 1.1.7) nvme-cli (3.0~b.4 -> 3.0+6.g1ac60ca4b) openssl-3 orc (0.4.43 -> 0.4.44) partitionmanager (26.08.0 -> 26.08.1) patterns-kde (20260428 -> 20260830) patterns-microos pcre2 (10.47 -> 10.48) plasma5support6 (6.7.4 -> 6.7.5) plasma6-activities (6.7.4 -> 6.7.5) plasma6-activities-stats (6.7.4 -> 6.7.5) plasma6-browser-integration (6.7.4 -> 6.7.5) plasma6-desktop (6.7.4 -> 6.7.5) plasma6-integration (6.7.4 -> 6.7.5) plasma6-nm (6.7.4 -> 6.7.5) plasma6-openSUSE plasma6-pa (6.7.4 -> 6.7.5) plasma6-print-manager (6.7.4 -> 6.7.5) plasma6-systemmonitor (6.7.4 -> 6.7.5) plasma6-workspace (6.7.4 -> 6.7.5) polkit-kde-agent-6 (6.7.4 -> 6.7.5) powerdevil6 (6.7.4 -> 6.7.5) python-dbus-python (1.3.2 -> 1.4.0) python-idna (3.18 -> 3.19) python-maturin (1.14.1 -> 1.15.0) python313-packaging (26.2 -> 26.3) qca-qt6 (2.3.10 -> 2.3.12) qemu (11.0.3 -> 11.1.1) qqc2-breeze-style6 (6.7.4 -> 6.7.5) qrca (26.08.0 -> 26.08.1) qt6-tools raspberrypi-firmware samba (4.24.5+git.481.dba78dbdea -> 4.24.6+git.488.e38f6c96c62) sdbootutil (1+git20260825.c7a5a97 -> 1+git20260909.7cfa1f0) sddm-kcm6 (6.7.4 -> 6.7.5) sdl2-compat (2.32.70 -> 2.32.72) selinux-policy (20260826 -> 20260910) sg3_utils (1.48+35.c49e7c08 -> 1.48+36.936c7ae) signon-kwallet-extension (26.08.0 -> 26.08.1) spectacle (6.7.4 -> 6.7.5) steam-devices (20251018+git.4d7e6c1 -> 20260625+git.22ec85e) sudo suse-module-tools (16.1.6 -> 16.1.7) systemsettings6 (6.7.4 -> 6.7.5) wireplumber (0.5.15 -> 0.5.17) xdg-desktop-portal-kde6 (6.7.4 -> 6.7.5) zvbi (0.2.44 -> 0.2.45) zypper (1.14.98 -> 1.14.101) === Details === ==== Mesa ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== Mesa-drivers ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== MicroOS-release ==== Version update (20260830 -> 20260912) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add NetworkManager-CVE-2026-10805.patch: dhclient: reject unsafe characters in URLs and hostnames (bsc#1267696, CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426). - Add NetworkManager-CVE-2026-19685.patch: core: 802.1x: reject ca-path for private connections (bsc#1276764, CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513). ==== SDL3 ==== Version update (3.4.14 -> 3.4.16) - Update to release 3.4.16 * Fixed loading BMP files with < 8 bits per pixel and odd widths * Fixed the depth format sample count support check in the GPU API * Removed WM_TAKE_FOCUS from WM_PROTOCOLS for X11 windows * Report SDL_PenInputFlags in SDL_PenProximityEvent * Fixed vertical high-resolution mouse wheel scaling on evdev * Fixed joystick stick calibration on Nintendo Joy-Con controllers ==== appstream-glib ==== Version update (0.8.3 -> 0.8.4) Subpackages: libappstream-glib8 - Update to version 0.8.4: + New Features: - Add symbol and sample text for Amharic and Inuktitut - Add symbol text for N'Ko and Yi script + Bugfixes: - Fix building the silo when shared-mime-info >= 2.5.1 is installed - Fix RISC-V test failure ==== aurorae6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== baloo-widgets ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== blog ==== Version update (2.47 -> 2.48) Subpackages: libblogger2 - Update to version 2.48 * Avoid fortify compiler warnings in vmcp.c * Simplify parseterm() to avoid compiler warning ==== bluedevil6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * i18n: Fix dialog translation for Forget Device * Update version for new release 6.7.5 ==== boost-base ==== Subpackages: boost-license1_91_0 libboost_filesystem1_91_0 libboost_log1_91_0 libboost_thread1_91_0 - Also install the CMake package config for the header-only Boost.System during the base build: since CMake 4 removed the FindBoost module, find_package(Boost COMPONENTS system) falls through to BoostConfig.cmake, which requires a per-component boost_system-config.cmake that the top-level b2 install no longer generates now that the compatibility stub library is gone. Package it in libboost_headers-devel. ==== breeze6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: breeze6-cursors breeze6-decoration breeze6-style breeze6-style-qt5 breeze6-wallpapers - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Use font metrics to only inset where the text can spare it (kde#523118) * Use ubuntu image for Qt5 CI * Update version for new release 6.7.5 ==== breeze6-gtk ==== Version update (6.7.4 -> 6.7.5) Subpackages: gtk3-metatheme-breeze6 metatheme-breeze6-common - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== bubblewrap ==== Version update (0.11.2 -> 0.12.0) - update to 0.12.0: * The flag --not-a-security-boundary was added. If this is enabled then failure of some sandbox setup steps (like remounting a submount) are not fatal. * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1 (or later). * This version removes the support for building a setuid bubblewrap. Changes in this version made it difficult to support and basically all modern linux distributions now support unprivileged user namespaces to some extent. * The assume_kernel build option was added, if specified no backwards compatiblity for kernels older than this is built in (and will result in hard failures at runtime). Currently specifying 5.6.0 or later will disable the fallback implementation of openat2(RESOLVE_IN_ROOT). * Bubblewrap now correctly resolves absolute symlinks during the sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx) where file or directories created during sandbox setup could follow parent symlinks out of the sandbox. ==== chrony ==== Subpackages: chrony-pool-openSUSE - Create /var/lib/chrony via tmpfiles ==== cockpit ==== Subpackages: cockpit-bridge cockpit-networkmanager cockpit-packagekit cockpit-system cockpit-ws cockpit-ws-selinux - Symlink opensuse's branding to opensuse-leap as they should share the same (bsc#1268639) ==== coreutils ==== - coreutils-uniq-fix-read-overrun-with-w.patch: Add upstream security fix (CVE-2026-56391, bsc#1272698) * uniq: '-w' no longer overruns the read buffer in multibyte locales. [bug introduced in coreutils-9.5] - coreutils-unexpand-fix-heap-overflow.patch: Add upstream security fix (CVE-2026-56392, bsc#1272699) * unexpand: '-t' no longer overflows a heap buffer for tab values > SIZE_MAX/16. [bug introduced in coreutils-9.11] - coreutils-tests-df-sync-fix-strace.patch: Add test patch to let df-sync test succeed on more architecures. ==== coreutils-systemd ==== - coreutils-uniq-fix-read-overrun-with-w.patch: Add upstream security fix (CVE-2026-56391, bsc#1272698) * uniq: '-w' no longer overruns the read buffer in multibyte locales. [bug introduced in coreutils-9.5] - coreutils-unexpand-fix-heap-overflow.patch: Add upstream security fix (CVE-2026-56392, bsc#1272699) * unexpand: '-t' no longer overflows a heap buffer for tab values > SIZE_MAX/16. [bug introduced in coreutils-9.11] - coreutils-tests-df-sync-fix-strace.patch: Add test patch to let df-sync test succeed on more architecures. ==== cpio ==== - Adjust doc mtime for reproducible cpio.info (boo#1047218) - Change cpio-use_new_ascii_format.patch to get the doc change into the package ==== curl ==== Version update (8.21.0 -> 8.22.0) Subpackages: libcurl4 - Update to 8.22.0: * Security fixes: - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476) - CVE-2026-18924: HTTP/2 server push UAF (bsc#1277477) - CVE-2026-19931: Negotiate ambient user conn reuse (bsc#1277478) - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479) - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480) - CVE-2026-80255: secure cookie attribute bypass with tab (bsc#1277482) - CVE-2026-82209: curl: domain-scoped PSL domain cookie (bsc#1278173) * Changes: - gssapi: add support for Apple GSS Framework - hardening: add API guards - RFC 9421 HTTP Message Signatures support - spnego: block NTLM fallback in SPNEGO negotiation - TLS: drop support for TLS-SRP - vquic: add option to use Apple fast UDP * Bugfixes: - altsvc: continue after unknown parameters - asyn-thrdd: retry link-local ipv6 if missing scope id - autotools: minor fixes and improvements - cd2nroff: fix backslashes for 4-space indent lines - cd2nroff: stricter checks for asterisks for italics - cfilters: fix event-based connection shutdown - conncache: apply multi limits to transfers using a shared pool - connect: only set connect timer on first socket - connection reuse: check SSL configs when doing a scheme upgrade - cookie: cookies set for an exact PSL domain is host-only - cookie: improve TAB handling - cookie: refuse to load cookies set against a PSL domain - FTP: fix TLS session reuse on the data connection - hostip: only cache negative resolves for authoritative answers - http digest: tie peer/credentials on input - http2: make server push transfers inherit share from parent - ldap: reject control characters in URL-decoded filter values - ldap: support empty username and password - md5: replace magic numbers with `MD5_DIGEST_LEN` - mime.c: avoid integer overflow in base64 size calculation - mprintf: acknowledge %F - ngtcp2+openssL: fix early data - ngtcp2: avoid NULL deref in cf_ngtcp2_send - openssl+sectrust: fix session reuse - openssl+sectrust: move session verified set into result check - openssl: avoid conn reuse if provider is used - openssl: avoid strlen() on the data from OpenSSL - openssl: prefer modern API flavors for `EVP_MD_CTX` new/free - openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` - url: fix handling of empty user in NTLM matching - url: fix negotiate/ntlm connection reuse - urlapi: allow URLs to not have userauth (hostname) - urlapi: clear password buffer on error path - vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config * Rebase libcurl-ocloexec.patch ==== dialog ==== Subpackages: libdialog15 - Update to version 1.3-20260721: + correct order of sprintf parameters for token-count error messages (patch by Xinting Zhou). + updated cs.po, zh_CN.po from https://translationproject.org/latest/dialog/ + configure script fixes for compiler warnings + updated ms.po from https://translationproject.org/latest/dialog/ + updated ar.po, ka.po, ms.po, ru.po, sr.po from https://translationproject.org/latest/dialog/ - Update to version 1.3-20260107: + modify package/debian/* to work with Debian 13+. + modify run_test.sh to set LD_LIBRARY_PATH in case "make check" is used on a system where dialog's shared library was not installed. + improve gen-pkgconfig.in by widening the filter for "-z" options. + improve layout of menu and checklist/radiolist widgets (report by Mike Castle). + add a limit-check in the tailbox widget. + correct length of input-fields in form widget (report by Mike Castle). + correct a typo for aspect ratio in files written by --create-rc (report by Mike Castle). + improve manpage description of --hline (report by Mike Castle). + update configure script macros for cross-compatibility. + added kab.po from https://translationproject.org/latest/dialog/ + updated bg.po, de.po, eo.po, fa.po, id.po, ja.po, ms.po, pl.po, pt.po, ro.po, sq.po, sv.po, uk.po from https://translationproject.org/latest/dialog/ + configure script fixes for compiler warnings + update config.guess, config.sub ==== discover6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: discover6-backend-flatpak discover6-backend-fwupd discover6-notifier - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 * Add missing Qt::Qml link * Fix updates being stuck when fwupd is unavailable (kde#521682) * fwupd: Regression, do not mistake an update for needsReboot * SnapBackend: signal completion of update check with zero upgradeable snaps (kde#524077) * DiscoverObject: Address quitting with concurrent KJobs (kde#497419,kde#522245,kde#522815,kde#518264) * rpmostree: Fix crash in notifier * rpmostree notifier: Do not query null pointers * kcm/updates: Fix incorrect text when changing update type * Update version for new release 6.7.5 ==== dmidecode ==== - Display slot information for EDSFF (jsc#NVIDIA-68) * dmidecode-Display-slot-information-for-EDSFF.patch ==== docker ==== Version update (29.4.0_ce -> 29.7.2_ce) Subpackages: docker-buildx docker-rootless-extras - Ship the SELinux CIL policies from contrib/selinux/, loading docker-af-alg-deny.cil (mitigates CVE-2026-31431) via semodule when SELinux is enabled (bsc#1278193). - Update to Docker 29.7.2. See upstream changelog online at - Update to buildx 0.36.1. See upstream changelog online at - Rebased patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch (renamed from 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch) * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch - Remove patches now fixed upstream: - 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch (bsc#1099277, superseded by upstream commit 528a806141 "daemon: Always reload AppArmor profile at daemon startup", which fixes the same root cause: the daemon no longer skips reinstalling the docker-default profile on upgrade) - 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch (bsc#1262346, CVE-2026-39984 fixed upstream via vendored sigstore/timestamp-authority v2.1.2) - 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch (bsc#1265782, CVE-2026-33814 fixed upstream via vendored golang.org/x/net v0.57.0) - 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch (bsc#1266625, CVE-2026-39821 fixed upstream via vendored golang.org/x/net v0.57.0) - 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch (bsc#1267827, CVE-2026-41567 fixed upstream directly in moby/moby via commit 2022313ffe) ==== dolphin ==== Version update (26.08.0 -> 26.08.1) Subpackages: dolphin-part libdolphinvcs6 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - Changes since 26.08.0: * dolphintabpage: set the active split pane from the view that activated (kde#509525) * previewssettingspage: Emit changed() if the data actually changes, not on click. * DolphinItemListView: Revert 16 to 48 in itemWidth (kde#523432) * dolphinitemlistview: do not store the fallback icon size in the cache (kde#524606) * views: Never let the item layout use a zero icon size (kde#523228) * kitemlistview: Fix group headers showing over the view's header * Dolphinview: Refresh the default zoom level when settings are applied * Close a tab on middle click whether or not it shows a close button * dolphinview: Base the default zoom level on the preview state ==== dracut ==== Version update (112+suse.34.g35e16b7 -> 112+suse.51.gf078a84) Subpackages: dracut-ima - Update to version 112+suse.51.gf078a84: * fix(fcoe): do not produce an error if there is no configuration in /etc/fcoe * fix(drm): add leds-qcom-lpg to aarch64 specific modules needed by drm * fix(dracut): correct order of "Creating image" log line * fix(systemd-cryptsetup): check all crypttab entries for socket key files - Properly enable fips/ima subpackages for i586: fips patterns are available for i586 as well (reverts aae9dca). - Update to version 112+suse.47.gec0b378: * fix(base): check first argument in load_fstype() * fix(url-lib): check error if curl fails in subshell * fix(dracut-systemd): actually make rd.break=pre-trigger stop before pre-trigger * fix(lvm): unset DM_VG_NAME and DM_LV_NAME in each iteration * fix(lvm): drop stray leading and trailing spaces from generated cmdline * fix(lvm): install the LVM system ID file again * fix(lvm): deduplicate rd.lvm.lv= arguments in cmdline() * fix(lvm): check all host devices in cmdline() * fix(iscsi): sanitize netroot= value passed to initqueue scripts - CVE-2026-6893: root code execution via dhcp options command injection (bsc#1268322, follow-up fixes recently merged) * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset - Maintain configuration in OBS ==== exiv2 ==== Version update (0.28.8 -> 0.28.9) - update to 0.28.9 (bsc#1277579, CVE-2026-68547, bsc#1277579, CVE-2026-68546, bsc#1277791, CVE-2026-49275): * https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j * https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q * https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp * https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w ==== expat ==== Version update (2.8.2 -> 2.8.4) - update to 2.8.4: * Security fixes: * CVE-2026-66046, bsc#1275732: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c * CVE-2026-76641, bsc#1275915: out-of-bounds read vulnerability that allows attackers to trigger memory corruption * CVE-2026-76957, bsc#1275859: lacks handler call depth tracking with custom encoding callbacks, use-after-free can occur * CVE-2026-76956, bsc#1275860: misinterpretation of getentropy's return code leads to insufficient entropy, vulnerable to hash flooding denial of service * Other fixes: * CMake: only add /source-charset:utf-8 when /utf-8 is not present * lib: resolve undefined behavior from overshifting a signed int * lib: support read-only hash table lookup with non-zero-terminated keys * lib: use a C99 bool for ENTITY.open * version info bumped from 13:3:12 to 13:4:12 - update to 2.8.3: * Security fixes: * CVE-2026-72522, bsc#1275594: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing * Other fixes: * fix support for 2+ GiB documents (regression from 2.8.2) * reject empty version in the XML declaration * fix printf format for AIX * CMake|AIX: enable EXPAT_DEV_URANDOM by default * version info bumped from 13:2:12 to 13:3:12 ==== falkon ==== Version update (26.08.0 -> 26.08.1) Subpackages: falkon-kde - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Enable decoders in ffmpeg-8-mini that need no extra build dependencies. This makes it possible for some packages to run testsuites with e.g. WAV files. - Add ffmpeg-8-CVE-2026-75147.patch: Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU size in the keyframe search loop. (CVE-2026-75147, bsc#1276413) - Add ffmpeg-8-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative fragment index. (CVE-2026-75146, bsc#1276412) - Add ffmpeg-8-CVE-2026-75145.patch: Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow the OBU size to (long). (CVE-2026-75145, bsc#1276411) - Add ffmpeg-8-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer. (CVE-2026-75144, bsc#1276410) - Add ffmpeg-8-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller buffer size in librist_read. (CVE-2026-75143, bsc#1276409) - Add ffmpeg-8-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream counts that overflow the system header. (CVE-2026-75142, bsc#1276408) - Add ffmpeg-8-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count. (CVE-2026-75141, bsc#1276407) - Add ffmpeg-8-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 output wider than the plane. (CVE-2026-70632, bsc#1274289) - Add ffmpeg-8-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate output shorter than the strip. (CVE-2026-70631, bsc#1274287) - Add ffmpeg-8-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject deflate output shorter than the frame. (CVE-2026-70630, bsc#1274282) - Add ffmpeg-8-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave uninitilized data when the input is too short. (CVE-2026-70629, bsc#1274270) - Add ffmpeg-8-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid signed overflow in the capacity check. (CVE-2026-70628, bsc#1274268) - Add ffmpeg-8-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check count_label against the available bytes. (CVE-2026-66037, bsc#1272764) - Add ffmpeg-8-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support dynamic frame sizes. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject unsupported frame parameter changes. This patch is for facilitate ffmpeg-CVE-2026-66036.patch. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the temp row buffer for the widest plane. (CVE-2026-65706, bsc#1272762) - Add ffmpeg-8-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove unneeded variables. (CVE-2026-65705, bsc#1272761) - Add ffmpeg-8-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 AC3 trim underflow the packet size. (CVE-2026-65704, bsc#1272760) - Add ffmpeg-8-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference frame before reallocating on size change. (CVE-2026-65703, bsc#1272759) - Add ffmpeg-8-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF objects smaller than their header. (CVE-2026-64834, bsc#1272757) - Add ffmpeg-8-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS core_size against the packet size in the HD path. (CVE-2026-64833, bsc#1272755) - Add ffmpeg-8-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit DLTA accesses stay within the row. (CVE-2026-58049, bsc#1269550) - Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9 to fill the role. [boo#1271606] - Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606] ==== ffmpegthumbs ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== flatpak-kcm6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Add missing Qt::Qml link ==== fuse3 ==== Version update (3.18.2 -> 3.18.3) Subpackages: libfuse3-4 - Update to release 3.18.3 * fuse_session_custom_io() is disabled (we do not build with `-Denable-custom-io=true`) * fusermount3 now resolves the mountpoint once, through an O_PATH|O_NOFOLLOW descriptor to avert an escalating TOCTOU issue. * fusermount3 now runs the auto-unmount probe as the calling user to avert an escalating TOCTOU issue. ==== gcc16 ==== Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Add gcc16-pr124811.patch to fix build reproducability when PCH is used - Add gcc16-znver6-cpuid.patch to fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390, make sure to configure s390x with - -disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ==== glibc ==== Version update (2.43 -> 2.44) Subpackages: glibc-locale glibc-locale-base - dt-d-rule.patch: Makerules: Make the .dt to .d conversion safe against concurrent sub-makes - math-sinh-worst-case-results.patch: math: Fix sinh worst-case results for |x| > 36.736801 (BZ #34441) - math-x86-64-tanh-floatn-aliases.patch: Fix x86_64 tanh _FloatN aliases binding to the FMA variant (BZ #34465) - elf-honor-skip-ifunc-for-ifunc-relocations.patch: elf: Honour skip_ifunc for cross-object IFUNC relocations (BZ #34428) - For the cross-x86_64 flavor also build the -m32 glibc - Enable cross-x86_64 - Update to glibc 2.44 * System-wide tunables can be applied using /etc/tunables.conf and running ldconfig * A new tunable, glibc.elf.thp, is added to map read-only segments with Transparent Huge Pages (THP) if THP is not disabled in the kernel * The THP page size in malloc is capped to MAX_THP_PAGESIZE * Additional optimized and correctly rounded mathematical functions have been imported from the CORE-MATH project * Many additional improvements to existing functions have been synchronized from the CORE-MATH project * For C++26, the assert macro is now variadic * The SVID error handling for cosh and sinh was moved to compatibility symbols * Static PIE is now supported for arm-*-linux-gnueabi * On AArch64 targets that support the Guarded Control Stack extension all GCS operations (including status, write on shadow stack, and push to shadow stack) are locked after enabling GCS with ENFORCED or OVERRIDE GCS policy * On AArch64 targets, log, exp, sin, cas, sinh, cosh, asinh, acosh, atanh single and double precision special cases have been vectorized for SVE and AdvSIMD, and vector variants of powr have been added * On RISC-V targets, vector extension optimized variants of memcmp, memccpy, memchr, memcpy, memmove, stpncpy, strcmp, strchr, strcpy, strncmp, strncpy, strlen, and strrchr have been added * On PowerPC, memchr optimized for Power10 has been re-added * Pre-built ld.so.cache files can be installed with ldconfig * A new locale has been added: hrx_BR (Hunsrik language spoken in Brazil) * Although malloc and related functions currently return pointers aligned to alignof (max_align_t), the documentation now says future versions of glibc may relax alignment requirements for small allocations * GLIBC-SA-2026-0013: Potential stack-based buffer clash during tilde expansion in wordexp (CVE-2026-6791) * GLIBC-SA-2026-0014: wordexp with WRDE_APPEND may result in an invalid call to free() (CVE-2026-6368) - resolv-count-resource-records.patch, resolv-check-hostname.patch, ldbl-128ibm-ceill-floorl-roundl-truncl.patch, getlogin-utmp-fallback.patch, nss-malloc-failure-checks.patch, nss-database-for-fork.patch, malloc-sys-kernel-mm.patch, tests-aarch64-makefile-deps-bti.patch, aarch64-lock-gcs-startup.patch, elf-strlen-redir-ifunc.patch, riscv-redir-memcpy-generic.patch, tst-rseq-linux-7.patch, sys-mount-cloexec-flag.patch, sys-mount-open-tree-macros.patch, ibm139x-pending-char-state.patch, ungetwc-byte-stream.patch, scanf-mc-buffer-overflow.patch, fma-shift-ub.patch, struct-reserved-members.patch, iconv-translit-intermediate-errors.patch, arm-vfp-plt-trampoline.patch, resolv-sprintrrf-unkown-types.patch, resolv-sprintrrf-inet-ntop-check.patch, resolv-sprintrrf-buffer-overreads.patch: Removed ==== google-noto-fonts ==== Version update (20260801 -> 20260901) Subpackages: google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20260901: * Serif Toto: - Improve the Kerning of BREATHY EO - Reverts the change to the dot under TOTO LETTER WA * Sans Miao: Add 9 Miao glyph variants for the Lipo language ==== gpg2 ==== Version update (2.5.21 -> 2.5.22) - Update to 2.5.22: * gpg: New option "primary" for the --card-edit "generate" command. This option is useful create only the primary key on the first slot of an OpenPGP card * gpgsm: Emit issuer and serial no. when the certificate is not found * A range of bug fixes ==== gpgme ==== Version update (2.1.2 -> 2.2.0) - Update to 2.2.0: * gpgme_verify_result_t now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Handle the new SIGINFO status line * Ignore TRUST_ status lines if no NEWSIG was seen ==== gpgmepp ==== Version update (2.1.0 -> 2.2.0) - Update to 2.2.0: * Signature now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Added missing getters for the number of notations of a signature and the numbers of created signatures and of invalid signing keys of a signing result ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin - Backport merged upstream patch * 0001-fs-btrfs-mark-Btrfs-on-disk-structs-as-GRUB_PACKED.patch * 0002-fs-btrfs-add-btrfs-info-command.patch * 0003-fs-btrfs-add-btrfs-list-subvols-command.patch * 0004-fs-btrfs-add-btrfs-get-default-subvol-command.patch - Patch rebased * grub2-btrfs-01-add-ability-to-boot-from-subvolumes.patch * grub2-btrfs-06-subvol-mount.patch * grub2-btrfs-10-config-directory.patch - Drop local patch * grub2-btrfs-09-get-default-subvolume.patch ==== gstreamer ==== Version update (1.28.6 -> 1.28.7) Subpackages: libgstreamer-1_0-0 - Update to version 1.28.7: + Highlighted bugfixes: - Various security fixes and playback fixes - appsrc EOS handling regression fix for applications pushing EOS into a blocked appsrc - glcolorconvert fixes for older OpenGL/GLSL versions - mxfdemux: Fix keyframe detection regression and possible artefacts after seeking - QML6 GL Overlay output texture lifetime handling fixes - opencv: Add support for building against OpenCV 5 - hip: Add missing API version suffix in HIP support library filename and fix hipcc detection on Windows with HIP SDK 7.x - analytics: fix classes off-by-one in ssdtensordec leading to mislabelling of objects in the examples - isobmff: Fix min_display_mastering_luminance in mdcv box - rtpbin2: rtprecv: limit the number of remote sources being tracked - st2038anc: parity bit handling fixes for ST 291 ADF words - video converter and videoconvertscale fixes - mpegdemux: restore gap event sending in MPEG-PS demuxer - typefinding: fix typefinding regressions for ogg and text files - Fix x264enc high bit depth support in binary packages - Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements + gstreamer: - cpuid: Clean up NEON and ASIMD getauxval detection + port Orc's elf_aux_info support - dataurisrc: Fix empty payloads and unsupported charset conversion - pipeline: Avoid lock inversion when handling GST_MESSAGE_RESET_TIME - validate: Use a single value type in configs lists ==== gstreamer-plugins-bad ==== Version update (1.28.6 -> 1.28.7) Subpackages: libgstphotography-1_0-0 libgstplay-1_0-0 - Update to version 1.28.7: + amc: Don't set the Hardware class in metadata for sw video codecs + d3d12: Fix copy-paste typos + d3d12cmdqueue: Fix deadlock during GC + d3d12screencapturesrc: Fix out-of-bounds access with monochrome cursors + dwritebaseoverlay: Fix assertion 'G_VALUE_HOLDS_UINT (value)' + hip: Add missing API version suffix in library filename + gstreamer-hip api_version failure + hip: Fix hipcc detection on Windows with HIP SDK 7.x + hipstream: Return actual device_id instead of vendor from device_id getter + hipmemorycopy: Add missing ifdef guard + jpegparse: Fix byte order of JFIF density fields + mpegdemux: restore gap sending + mxfdemux: Fix keyframe detection + onnx: Fix nullptr dereference on ORT init failure + onnxinference: fix dead lock with wrong model file + opencv: Support OpenCV 5 + pnmdec: Protect against bogus dimensions headers + ssdtensordec: The classes were off by one + tsdemux: Add 'stream-format' field for AC-4 caps + validate: Use a single value type in configs lists + vulkan(av1,vp9)dec: set access NONE at buffer pool allocation parameters - Disable msdk plugin, currently broken, and in practice abandoned upstream. It is also ranked as 0, so to even attempt to use it, users have to manually enable it via the command line. ==== gstreamer-plugins-base ==== Version update (1.28.6 -> 1.28.7) Subpackages: libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 - Update to version 1.28.7: + appsrc: Don't push EOS directly in event handler (regression fix) + glcolorconvert: don't rely on integer modulus '%' + mikey: use TEK_WITH_SALT for proper key/salt separation in KEY_DATA + overlay-composition: Don't try to scale high bitdepth rectangles + rtpbasedepayload: Don't assert if previous buffer's delayed header extensions are still queued + rtsp: message: fix crash when an auth value started with whitespace + typefindhelper: Revert "Drop unnecessary check for factories without a function" + typefind: regression causes txt file to be detected as subtitle + typefindfunctions: Critical warnings when typefinding invalid ogv file + validate: Use a single value type in configs lists + video-converter: Fix GRAY output border color + video-format: Fix annotation on component function + videoconvertscale: keep input colorimetry in scale-only elements + videotimecode: Fix documentation bug and update annotations ==== gtk3 ==== Version update (3.24.52 -> 3.24.52+git59.b30343717d) Subpackages: gtk3-data gtk3-schema gtk3-tools libgtk-3-0 typelib-1_0-Gtk-3_0 - Update to version 3.24.52+git59.b30343717d: + filechooser: Avoid converting CSS font size twice + a11y: Do not emit false focus changes for a notebook tab on page changes + Window: Free empty string set to gtk-menu-bar-accel + wayland: Align decoration layout fallback with GtkSettings + filechooserwidget: stop the location and load timeouts in dispose - Update to version 3.24.52+git48.b9cc75f19f: + menu: Avoid scrolling too far + gtkapplication: Fix gtk_application_dbus_register return value + gtk/window: NULL check settings before disconnecting handler + gtkwindow: Clear active state on disappearing pointer + gdk/wayland: Remove unused field in _GdkWaylandSelection + gdk/wayland: Make primary selection and clipboard updates less racy + gdk/wayland: Clear dnd targets + gdk/wayland: Set clipboard targets atomically + Focus does not return to the main window when closing File Chooser + gdk/wayland: Add support for wl_fixes.ack_global_remove + x11: Fix wrong display when getting xatom - Drop gtk3-fix-xi2-xatom.patch:fixed upstream. ==== harfbuzz ==== Version update (14.3.1 -> 14.4.0) Subpackages: libharfbuzz-gobject0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.4.0: + Glyph positions and extents now saturate instead of overflowing. + Arabic Windows-1256 fallback shaping is now enabled on all platforms. + Fix cluster values and a dropped glyph advance in the Graphite shaper. + Fix `avar` axis value mapping in fonts that repeat the boundary entries. + Fix `avar` version 2 partial instancing. + Fix `COLR` sweep gradient truncation and unbounded memory use. + Faster subsetting, especially for large `GSUB`/`GPOS` and `CFF` tables. + Faster extraction of the experimental glyph dependency graph. + Various shaping speedups. + Various fixes for crashes and hangs with malformed fonts. + Various fixes to the experimental raster, vector, and GPU libraries. + Various improvements to the HarfRust integration shaper. + The DirectWrite backend no longer uses the C++ runtime. + Various build, portability, and fuzzing fixes. + New API: +hb_set_intersects() ==== hwdata ==== Version update (0.410 -> 0.411) - Update to version 0.411: * Update pci and vendor ids ==== iproute2 ==== Version update (7.1 -> 7.2) - Update to release 7.2 * dpll: Added frequency monitoring support * dpll: monitor: add -t/--timestamp and --tshort options * rdma: netns can now be specified by PID * bridge: vlan: Added support for neigh_forward_grat * netshaper: Added bw-min and weight parameter support * netshaper: Added group command for creating scheduling hierarchies * iplink: bridge: Added stp_mode support * devlink: Added dump support for resource show - Ditch libnetlink-devel. This was never really a public API, and mipv6d (its original user back in 2014) has long had its own copy of libnetlink. ==== kaccounts-integration ==== Version update (26.08.0 -> 26.08.1) Subpackages: libkaccounts6-2 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kaccounts-providers ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kactivitymanagerd6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * QSet is not ordered, use contains instead of binary_search * StatsPlugin: Do not crash with wrong dbus calls * Update version for new release 6.7.5 ==== kate ==== Version update (26.08.0 -> 26.08.1) Subpackages: kate-plugins - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kde-cli-tools6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kde-gtk-config6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: kde-gtk-config6-gtk3 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kdecoration6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libkdecorations3-6 libkdecorations3private2 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kdegraphics-mobipocket ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kdegraphics-thumbnailers ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kdenetwork-filesharing ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kdeplasma6-addons ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * applets/weather: don't process pending events inside ioncontrol_p destructor (kde#524929) * kameleon-qmk-helper: Update zbus_polkit to 5.1.0 in Cargo.lock * applets/weather: properly hide info button when it won't work (kde#519676) * kickerdash, notes: update BugReportUrl * Update version for new release 6.7.5 - Reintroduce _service, got deleted by accident ==== kdialog ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kernel-firmware-amdgpu ==== Version update (20260717 -> 20260829) - Update to version 20260829 (git commit 458e40fdbb4d): * amdgpu: DMCUB updates for various ASICs - Update to version 20260828 (git commit b6bdea3726dc): * amdgpu: add VCN 5.3.0 firmware - Update to version 20260821 (git commit 8c7fac62c0d1): * amdgpu: add VPE 2.0.0 firmware * amdgpu: add SDMA 6.1.4 firmware * amdgpu: add DCN 4.2 firmware * amdgpu: add PSP 15.0.9 firmware * amdgpu: add PSP 15.0.0 firmware * amdgpu: add GC 11.7.1 firmware * amdgpu: add GC 11.7.0 firmware * amdgpu: DMCUB update for DCN314 - Update to version 20260814 (git commit 2398c20fc656): * amdgpu: DMCUB updates for various ASICs - Update to version 20260813 (git commit 984503d80fd6): * Revert "amdgpu: update GC 10.3.6 firmware" * amdgpu: update vangogh firmware * amdgpu: update VPE 6.1.1 firmware * amdgpu: update VCN 4.0.6 firmware * amdgpu: update PSP 14.0.1 firmware * amdgpu: update GC 11.5.1 firmware * amdgpu: update VPE 6.1.0 firmware * amdgpu: update VCN 4.0.5 firmware * amdgpu: update PSP 14.0.0 firmware * amdgpu: update GC 11.5.0 firmware * amdgpu: update renoir firmware * amdgpu: update yellow carp firmware * amdgpu: update raven2 firmware * amdgpu: update raven firmware * amdgpu: update VCN 3.1.2 firmware * amdgpu: update PSP 13.0.5 firmware * amdgpu: update GC 10.3.6 firmware * amdgpu: update picasso firmware * amdgpu: update PSP 13.0.11 firmware * amdgpu: update GC 11.0.4 firmware * amdgpu: update VCN 4.0.2 firmware * amdgpu: update PSP 13.0.4 firmware * amdgpu: update GC 11.0.1 firmware * amdgpu: update VCN 5.0.0 firmware * amdgpu: update SMU 14.0.3 firmware * amdgpu: update PSP 14.0.3 firmware * amdgpu: update GC 12.0.1 firmware * amdgpu: update SMU 14.0.2 firmware * amdgpu: update PSP 14.0.2 firmware * amdgpu: update GC 12.0.0 firmware * amdgpu: update vcn 4.0.4 firmware * amdgpu: update SMU 13.0.7 firmware * amdgpu: update PSP 13.0.7 firmware * amdgpu: update GC 11.0.2 firmware * amdgpu: update SMU 13.0.10 firmware * amdgpu: update SDMA 6.0.3 firmware * amdgpu: update PSP 13.0.10 firmware * amdgpu: update GC 11.0.3 firmware * amdgpu: update VCN 4.0.0 firmware * amdgpu: update SMU 13.0.0 firmware * amdgpu: update PSP 13.0.0 firmware * amdgpu: update GC 11.0.0 firmware * amdgpu: update beige goby firmware * amdgpu: update dimgrey cavefish firmware * amdgpu: update navy flounder firmware * amdgpu: update sienna cichlid firmware * amdgpu: update navi14 firmware * amdgpu: update navi12 firmware * amdgpu: update navi10 firmware * amdgpu: add PSP 13.0.15 firmware * amdgpu: update VCN 5.0.1 firmware * amdgpu: update PSP 13.0.12 firmware * amdgpu: update GC 9.5.0 firmware * amdgpu: update PSP 13.0.14 firmware * amdgpu: update GC 9.4.4 firmware * amdgpu: update PSP 14.0.5 firmware * amdgpu: update GC 11.5.3 firmware * amdgpu: update VPE 6.1.3 firmware * amdgpu: update PSP 14.0.4 firmware * amdgpu: update GC 11.5.2 firmware * amdgpu: update green sardine firmware * amdgpu: update arcturus firmware * amdgpu: update VCN 4.0.3 firmware * amdgpu: update PSP 13.0.6 firmware * amdgpu: update GC 9.4.3 firmware * amdgpu: update aldebaran firmware - Update to version 20260728 (git commit 543b8f5f987c): * amdgpu: DMCUB updates for various ASICs ==== kernel-firmware-ath10k ==== Version update (20260610 -> 20260809) - Update to version 20260809 (git commit 6f221d80d2fa): * ath10k: WCN3990 hw1.0: update board-2.bin ==== kernel-firmware-ath12k ==== Version update (20260610 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * ath12k: QCC2072 hw1.0: update to WLAN.COL.1.0.c2-00228-QCACOLSWPL_V1_TO_SILICON-1 ==== kernel-firmware-bluetooth ==== Version update (20260720 -> 20260828) - Update to version 20260828 (git commit b6bdea3726dc): * linux-firmware: Update firmware file for Intel BlazarIW core * linux-firmware: Update firmware file for Intel BlazarU core * linux-firmware: Update firmware file for Intel Scorpius core - Update to version 20260825 (git commit 0305399a8783): * QCA: Update Bluetooth WCN3988 firmware 2.1.5.c5-00042 to 2.1.5.c5-00060 - Update to version 20260821 (git commit 8c7fac62c0d1): * qca: Update Bluetooth QCC2072 UART interface firmware from 1.1.0-00295 to 1.1.0-00340 ==== kernel-firmware-i915 ==== Version update (20260706 -> 20260806) - Update to version 20260806 (git commit 16d815da3637): * xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S ==== kernel-firmware-intel ==== Version update (20260610 -> 20260728) - Update to version 20260728 (git commit 543b8f5f987c): * intel_vpu: Update NPU firmware ==== kernel-firmware-iwlwifi ==== Version update (20260610 -> 20260820) - Update to version 20260820 (git commit f2ab551dea14): * iwlwifi: add Bz/Sc FW for core24.70-49 release * iwlwifi: Add Hr/Gf firmware for core24.70-49 release * iwlwifi: update ty/So/Ma firmwares for core24.70-49 release * iwlwifi: update cc/Qu/QuZ firmwares for core24.70-49 release - Update to version 20260703 (git commit c95059a3774b): * iwlwifi: add Bz/Sc FW for core24.60-33 release * iwlwifi: Add Hr/Gf firmware for core24.60-33 release * iwlwifi: update ty/So/Ma firmwares for core24.60-33 release * iwlwifi: update cc/Qu/QuZ firmwares for core24.60-33 release ==== kernel-firmware-media ==== Version update (20260706 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * qcom: vpu: add Gen2 firmware binary for Eliza - Update to version 20260731 (git commit a968c5c2962e): * qcom: venus-5.4: fix vp9 decoder assertion failure ==== kernel-firmware-mediatek ==== Version update (20260629 -> 20260825) - Update to version 20260825 (git commit 0305399a8783): * mediatek MT7925: update bluetooth firmware to 20260813113236 * linux-firmware: update firmware for MT7925 WiFi device - Update to version 20260813 (git commit 984503d80fd6): * linux-firmware: update firmware for MT7922 WiFi device - Update to version 20260805 (git commit 31883adc3365): * mediatek MT7922: update bluetooth firmware to 20260724143815 ==== kernel-firmware-network ==== Version update (20260610 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * morsemicro: add firmware for mm8108 support - Update to version 20260806 (git commit 16d815da3637): * linux-firmware: Update firmware for an8811hb 2.5G ethernet phy - Update to version 20260805 (git commit 31883adc3365): * airoha: update AN7583 NPU firmwares to version 0.5 ==== kernel-firmware-qcom ==== Version update (20260717 -> 20260828) - Update to version 20260828 (git commit b6bdea3726dc): * qcom: update CDSP firmware for x1e80100 platform * qcom: add QUPv3 firmware for nord * qcom: add HPASS firmware for nord platform * qcom/sa8775p: update signature on cdsp1 firmware - Update to version 20260820 (git commit f2ab551dea14): * qcom: add NSP firmware for nord platform * WHENCE: Move qcom qcdxkmsuc8[23]80.mbn firmwares to Adreno section - Update to version 20260813 (git commit 984503d80fd6): * qcom: add CDSP firmware for eliza platform - Update to version 20260803 (git commit 73b4d58aba76): * qcom: Add gpu firmwares for Eliza chipset - Update to version 20260728 (git commit 543b8f5f987c): * qcom: Update qdsp6sw firmware for shikra platform * qcom: Update DSP firmware for qcs8300 platform ==== kernel-firmware-qlogic ==== Version update (20260610 -> 20260731) - Update to version 20260731 (git commit a968c5c2962e): * qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters ==== kernel-firmware-realtek ==== Version update (20260629 -> 20260731) - Update to version 20260731 (git commit a968c5c2962e): * rtw89: 8922d: add fw 0.35.113.2 - Update to version 20260728 (git commit 543b8f5f987c): * rtw88: add firmware v41.0.0 for RTL8723B ==== kernel-firmware-sound ==== Version update (20260706 -> 20260825) - Update to version 20260825 (git commit 0305399a8783): * cirrus: cs35l54: Add Cirrus CS35L54 firmware mappings for an HP laptop * linux-firmware: Upload firmware for tas2573 stereo * intel: avs: Add AudioDSP base firmware for LKF platforms * intel: avs: Update AudioDSP firmware for APL-based platforms * intel: avs: Update AudioDSP firmware for SKL-based platforms * intel: catpt: Update AudioDSP firmware for BDW platforms - Update to version 20260820 (git commit f2ab551dea14): * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Samsung laptops * cirrus: cs42l45: Add new SSIDs for Dell laptops * cirrus: cs35l56: Add firmware for Cirrus Amps for an ASUS laptop * cirrus: cs35l56: Add Cirrus CS35L56 firmware mappings for some Dell laptops - Update to version 20260813 (git commit 984503d80fd6): * cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for some Dell laptops - Update to version 20260803 (git commit 73b4d58aba76): * linux-firmware: Add firmware for new project - Update to version 20260731 (git commit a968c5c2962e): * cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops - Update to version 20260728 (git commit 543b8f5f987c): * linux-firmware: Add firmware for new soundwire projects ==== kernel-firmware-ueagle ==== Version update (20260610 -> 20260703) - Update to version 20260703 (git commit c95059a3774b): * ueagle-atm: sadly drop unlicensed files ==== kernel-source ==== Version update (7.2.2 -> 7.2.4) Subpackages: kernel-64kb kernel-default - Linux 7.2.4 (bsc#1012628). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (bsc#1012628). - ACPI: scan: Do not combine resources that overlap completely (bsc#1012628). - selftests/mm: fix on-fault-limit false failure under sudo-rs (bsc#1012628). - udf: Fix i_lenExtents truncation on 32-bit kernels (bsc#1012628). - timer: Keep debugobjects state consistent in migrate_timer_list() (bsc#1012628). - timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() (bsc#1012628). - taskstats: fix cpumask parsing cutting off the last character (bsc#1012628). - smack: fix cred UAF in smack_file_send_sigiotask() (bsc#1012628). - signal: avoid shared siginfo namespace rewrites (bsc#1012628). - sticon/parisc: Detect default STI graphics card for console output (bsc#1012628). - sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] (bsc#1012628). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (bsc#1012628). - zloop: truncate finished zones to zone capacity (bsc#1012628). - xarray: honor XA_FLAGS_ACCOUNT in xas_split_alloc() (bsc#1012628). - w1: ds28e17: reject an oversize length on an I2C block read (bsc#1012628). - vsock/virtio: flush works in dependency order (bsc#1012628). - wifi: mt76: mt7996: validate default EEPROM firmware size (bsc#1012628). - wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames (bsc#1012628). - wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy (bsc#1012628). - wifi: mt76: mt7925: cancel mlo_pm_work on stop (bsc#1012628). - wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy (bsc#1012628). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (bsc#1012628). - wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot (bsc#1012628). - wifi: rtw88: pci: fix resource leak on failed NAPI setup (bsc#1012628). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (bsc#1012628). - wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() (bsc#1012628). - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (bsc#1012628). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (bsc#1012628). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (bsc#1012628). - mm/kmemleak: report RCU-tasks quiescent states during the scan (bsc#1012628). - mm/kmemleak: stop the task stack scan early when interrupted (bsc#1012628). - crypto: atmel-ecc - avoid stale fallback key after set_secret failure (bsc#1012628). - crypto: atmel-ecc - clean up and improve ECDH comments (bsc#1012628). - crypto: iaa - unmap dst before software fallback on decompress (bsc#1012628). - fuse: copy request headers via a stack buffer for io-uring (bsc#1012628). - fuse: decouple fuse_ring creation from ent registration (bsc#1012628). - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (bsc#1012628). - wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (bsc#1012628). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (bsc#1012628). - i3c: renesas: Perform Dynamic Address Assignment on resume (bsc#1012628). - i3c: renesas: Restore STDBR and EXTBR registers on resume (bsc#1012628). - i3c: renesas: Reset the controller on resume (bsc#1012628). - i3c: renesas: Reconfigure the DATBAS register on re-attach (bsc#1012628). - i3c: renesas: Follow the reset deassert order used in probe (bsc#1012628). - i3c: renesas: Clean DATBAS register on detach (bsc#1012628). - i3c: renesas: Check that the transfer is valid before accessing it (bsc#1012628). - i3c: master: svc: bound IBI payload to the requested max_payload_len (bsc#1012628). - i3c: master: Fix info leak and UAF in device unregister path (bsc#1012628). - i3c: master: adi: initialize the lock before enabling interrupts (bsc#1012628). - i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() (bsc#1012628). - dm-pcache: fix use-after-free and invalid seg operations in kset_replay() (bsc#1012628). - dm-pcache: fix implicit u8 truncation of gc_percent in message handler (bsc#1012628). - dm-pcache: only hand out initialized cache segments ... changelog too long, skipping 1384 lines ... - commit dcfc956 ==== kf6-attica ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Attica6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-baloo ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-baloo-file kf6-baloo-imports kf6-baloo-kioslaves libKF6Baloo6 libKF6BalooEngine6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Apply clang-format on fileexcludefilters.cpp. * Exclude .snapshots folders from indexing. * [app] Skip content indexing in the extractor if onlyBasicIndexing is set. * Update version to 6.30.0 ==== kf6-bluez-qt ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-bluez-qt-imports libKF6BluezQt6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Port away from ecm_add_qml_module's deprecated CLASSNAME arg * Update version to 6.30.0 ==== kf6-breeze-icons ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6BreezeIcons6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Set missing fill="currentColor" for update-busy * Add "tv" symlink to "video-television" * Add symlinks for `text-x-shellscript` * Add symbolic mastodon icon * Update version to 6.30.0 ==== kf6-frameworkintegration ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-frameworkintegration-plugin libKF6Style6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-karchive ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Archive6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kauth ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6AuthCore6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kbookmarks ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Bookmarks6 libKF6BookmarksWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kcmutils ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kcmutils-imports libKF6KCMUtils6 libKF6KCMUtilsCore6 libKF6KCMUtilsQuick6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Documentation fixes * Fix documentation for SettingsStateBinding * Fix docs for KQuickManagedConfigModule * kcmutils_generate_module_data: add missing var init, for safer usage * Add missing EXCLUDE_DEPRECATED_BEFORE_AND_AT default variable declaration * No longer explicitly include CMakeParseArguments * Fix types in QML documentation * Update version to 6.30.0 ==== kf6-kcodecs ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Codecs6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * [KEncodingProber] Fix signedness issues for mBestGuess index * [KEncodingProber] Return 0.0 confidence if encoding signals wrong syntax * [KEncodingProber] Clean up float constants and C-style static casts * [KEncodingProber] Drop charlen tables from state machine models * [KEncodingProber] Remove need for charlen table from MBCS probers * [KEncodingProber] Remove some erroneously copied comment * [KEncodingProber] Remove no longer used method * [KEncodingProber] SBCS: Replace model pointer with reference * [KEncodingProber] SBCS: Replace unbounded array pointer with span * [KEncodingProber] Move sequence counter sum out of loop * [KEncodingProber] Test for Cyrillic encodings (and Unicode reencodings) * [KEncodingProber] Test for ASCII only UTF-16 encoded texts * Update version to 6.30.0 ==== kf6-kcolorscheme ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6ColorScheme6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * kcolorschemetest: explicitly cast enum values to int for arithmetic ops * Update version to 6.30.0 ==== kf6-kcompletion ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Completion6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kconfig ==== Version update (6.29.0 -> 6.30.0) Subpackages: kconf_update6 kf6-kconfig-imports libKF6ConfigCore6 libKF6ConfigGui6 libKF6ConfigQml6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add some missing CMake var initialization, for safer usage * kconfigcore: minor cleanups * fix tabNext() and tabPrev() default documentation * Update version to 6.30.0 ==== kf6-kconfigwidgets ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6ConfigWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kcontacts ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Contacts6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add Matrix icon * Update version to 6.30.0 ==== kf6-kcoreaddons ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kcoreaddons-imports libKF6CoreAddons6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * KFormat: Get current time in UTC * kfilesystemtype: identify a fuse mount by its name when the table cannot * kfilesystemtype: tell a fuse mount with a disk behind it from one without * Update version to 6.30.0 ==== kf6-kcrash ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Crash6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kdbusaddons ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kdbusaddons-tools libKF6DBusAddons6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kdeclarative ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kdeclarative-imports libKF6CalendarEvents6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kded ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kdesu ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Su6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kdnssd ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kdoctools ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6DocTools6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kfilemetadata ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6FileMetaData3 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * [PostscriptDscExtractor] Fix time offset parsing for Qt 6.12 * [PostscriptDscExtractor] Modernize QString usage * [SimpleExtractionResult] Fix copy constructor * [EmbeddedImageData] Remove some dead, unreachable code and data * Fix a few nodiscard warnings for QFile::open * [ExtractorPlugin] Allow alias names when matching extractor mimetypes (kde#522678) * [kfilemetadata_dump] Provide information about cover images etc * [FFmpegExtractor] Extract cover image from Matroska streams * [FFmpegExtractorTest] Move test class declaration to implementation file * Update version to 6.30.0 ==== kf6-kglobalaccel ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6GlobalAccel6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Parse QKeySequence from QDBusArgument more carefully (kde#524700) * Update version to 6.30.0 ==== kf6-kguiaddons ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kguiaddons-imports libKF6GuiAddons6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add geo: URI handler for Cartes * Add support to pass along the unmodified geo: URI in an URL template * Fix geo: URI query string encoding * Reuse explicitly provided image data (kde#519651) * waylandclipboard: Check isInterruptionRequested in prepare read loop (kde#517743) * Update version to 6.30.0 ==== kf6-kholidays ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kholidays-imports libKF6Holidays6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * fix dates for 2083 (2026/27 A.D.) * Update Norwegian holidays based on official sources * Update event date for Urs Aala-Hazrat * Update version to 6.30.0 ==== kf6-ki18n ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-ki18n-imports libKF6I18n6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add another test case for 0 * Update version to 6.30.0 ==== kf6-kiconthemes ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kiconthemes-imports libKF6IconThemes6 libKF6IconWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kidletime ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kidletime-plugins libKF6IdleTime6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Include CMakeFindFrameworks only with APPLE * Drop no longer used CMake variable * Update version to 6.30.0 ==== kf6-kimageformats ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * jp2: Fix new[] vs delete by not doing new[] (kde#525120) * qRoundOrZero_T: fix possible assert in qRound (kde#524678) * autotests: Add non-standard HEIF image * heif: re-enable decoding of non-standard images (kde#495686) * Add HEIC test files with crop transformation * heif: check crop values * jxl: Do not rewind after reading final frame * rgb: reject RLE start offsets that underflow the raster data * avif: Do not rewind in jumpToNextImage() * ossfuzz: call functions used in animations * Update version to 6.30.0 ==== kf6-kio ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6KIO6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Too many changes since 6.29.0, only listing bugfixes: * [ftp] Send commands in upper case consistently (kde#523927) * KOpenWithDialog: fix pattern matching in filterAcceptsRow() (kde#524085) * kfileitemactions: fix submenu lifetime using main menu as the parent (kde#524239) * http: Report how far an upload has got, not what the answer weighs (kde#518511) * Don't show percent-encoded strings for items of desktop:/ IO worker (kde#522470) * properties: show how much room a folder takes up, not only its data (kde#457363) * file: let a folder with the setgid bit give a copied file its group (kde#399270) * openurljob: open a shell script rather than refuse it as a program (kde#522948) * knewfilemenu: allow overriding system templates with local templates (kde#473991) * knewfilemenu: set application link title to not be misleading (kde#520949) * knewfilemenu: fix relative symlinks (kde#508444) * RenameFileDialog: offer the rename operation of the last rename (kde#523932) - Drop patch, merged upstream: * 0001-kfileitemactions-fix-submenu-lifetime-using-main-men.patch ==== kf6-kirigami ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kirigami-imports libKirigamiPlatform6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Too many changes since 6.29.0, only listing bugfixes: * ListItemDragHandle: stop the dropAnimation if one is still running (kde#517233) * SwipeListItem: Don't make the content item overlap the icons (kde#518436) * OverlaySheet: make the scrim darker (kde#447965) ==== kf6-kitemmodels ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kitemmodels-imports libKF6ItemModels6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kitemviews ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6ItemViews6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kjobwidgets ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6JobWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * kjobcreator: Fix tab order * Update version to 6.30.0 ==== kf6-knewstuff ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-knewstuff-imports libKF6NewStuffCore6 libKF6NewStuffWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-knotifications ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-knotifications-imports libKF6Notifications6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * notificationtester: Add URL text field * Update version to 6.30.0 ==== kf6-knotifyconfig ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6NotifyConfig6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kpackage ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Package6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kparts ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Parts6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Remove some unused includes * Update version to 6.30.0 ==== kf6-kpty ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Pty6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kquickcharts ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * add_qml_tests: initialize _extra_args variable in all cases * Fix usage of misnamed KDE_INSTALL_DEFAULT_ARGUMENTS * controls/LegendDelegate: use tabular numerals for value * Update version to 6.30.0 ==== kf6-krunner ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Runner6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Remove left-overs of dropped ecm_setup_qtplugin_macro_names usage * Update version to 6.30.0 ==== kf6-kservice ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Service6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Fix documentation syntax * Update version to 6.30.0 ==== kf6-kstatusnotifieritem ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6StatusNotifierItem6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-ksvg ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-ksvg-imports libKF6Svg6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add missing EXCLUDE_DEPRECATED_BEFORE_AND_AT default variable declaration * SvgItem: hold one texture for one picture, like FrameSvgItem does * Update version to 6.30.0 ==== kf6-ktexteditor ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6TextEditor6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * only show bracket match preview if the view is visible * vi-mode: Fix append to block for tabs * vi-mode: Fix cursor column swap with tabs * vi-mode: Fix operations in selection ranges with tabs * vi-mode: Fix success message for non-successful save commands (kde#473077) * vi-mode: Fix "save all" command for unnamed files * Fix resolution for KateVi::Range debug operator * vi-mode: Implement filename registers * vi-mode: Fix yank highlight for blocks with tabs * vi-mode: Simplify method to detect waiting for characters * vi-mode: Refactor the method for leaving insert mode * vi-mode: Fix checks for setting user marks (kde#520734) * Update version to 6.30.0 ==== kf6-ktextwidgets ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-kunitconversion ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6UnitConversion6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Fix inconsistencies in exponentiated units * Check if toUnit is in this category before trying to convert * Update version to 6.30.0 ==== kf6-kuserfeedback ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kuserfeedback-imports libKF6UserFeedbackCore6 libKF6UserFeedbackWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * user-feedback-manual.qdocconf template: fix outdated version variable use * user-feedback-manual.qdocconf template: fix outdated URL * Update version to 6.30.0 ==== kf6-kwallet ==== Version update (6.29.0 -> 6.30.0) Subpackages: kwalletd6 libKF6Wallet6 libKF6WalletBackend6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Too many changes since 6.29.0, only listing bugfixes: * Drop Close When Idle handling from kwalletd (kde#524500) * Fix logic errors in internalOpen (kde#524373) ==== kf6-kwidgetsaddons ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6WidgetsAddons6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * KColorMimeData: guard against a null QMimeData pointer * KMessageDialog: clean-up left-over KF5 times show event handling * Update version to 6.30.0 ==== kf6-kwindowsystem ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-kwindowsystem-imports libKF6WindowSystem6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Remove outdated & unused CMakeFindFrameworks include * Update version to 6.30.0 ==== kf6-kxmlgui ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6XmlGui6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * aboutkde: use better shadow for Konqi * Fix broken toolbars after second edit w/ multiple KXMLGUIClients (kde#442179) * Mark more pimpl parent pointers as const, consistently be first member * Update version to 6.30.0 ==== kf6-modemmanager-qt ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6ModemManagerQt6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Do not use CMAKE_MODULE_PATH variable before it is created * Remove usage of no longer existing QT_DEFINITIONS CMake variable * Remove Qt4-times unused subdir CMakeLists.txt file for D-Bus support * Update version to 6.30.0 ==== kf6-networkmanager-qt ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-networkmanager-qt-imports libKF6NetworkManagerQt6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Drop Q_FLAGS/Q_ENUMS on non-QObject/gadget types * Port away from deprecated Q_FLAGS * Update version to 6.30.0 ==== kf6-prison ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-prison-imports libKF6Prison6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-purpose ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-purpose-services libKF6Purpose6 libKF6PurposeWidgets6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Remove no longer used cmake variable * Removal of pastebin pulgin * Update version to 6.30.0 ==== kf6-qqc2-desktop-style ==== Version update (6.29.0 -> 6.30.0) - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * SwipeDelegate: remove workarounds for inset * TableHeaderViews: account for the margins of the root control * Update version to 6.30.0 ==== kf6-solid ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Solid6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * upower: Return -1 for unknown battery percentages * autotests: drop usage of not existing LIBS variable * Update version to 6.30.0 ==== kf6-sonnet ==== Version update (6.29.0 -> 6.30.0) Subpackages: kf6-sonnet-imports libKF6SonnetCore6 libKF6SonnetUi6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Fix typo in function name * Update version to 6.30.0 ==== kf6-syndication ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6Syndication6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Update version to 6.30.0 ==== kf6-syntax-highlighting ==== Version update (6.29.0 -> 6.30.0) Subpackages: libKF6SyntaxHighlighting6 - Update to 6.30.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.30.0 - Changes since 6.29.0: * Update dependency version to 6.30.0 * Add DotEnv syntax highlighting * repository.h: Make Repository::eventFilter() protected * syntax/yaml.xml: Have BuildStream files use the yaml highlighter * Associate .envrc files with Bash * Add KDL syntax highlighting * Add Just syntax highlighting * Initialize more cmake variables explicitly * Update version to 6.30.0 ==== kgamma6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kglobalacceld6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libKGlobalAccelD6-0 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kinfocenter6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kio-extras ==== Version update (26.08.0 -> 26.08.1) Subpackages: libkioarchive6-6 trash_kcm - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kio-gdrive ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kmenuedit6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== knighttime6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libKNightTime0 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== konsole ==== Version update (26.08.0 -> 26.08.1) Subpackages: konsole-part - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - Changes since 26.08.0: * Fix OSC22 mouse cursor shapes for splits * ViewSplitter: Fix focus shortcut issue (kde#524598) ==== kpipewire6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: kpipewire6-imports libKPipeWire6 libKPipeWireDmaBuf6 libKPipeWireRecord6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kpmcore ==== Version update (26.08.0 -> 26.08.1) Subpackages: libkpmcore13 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kquickimageeditor6 ==== Version update (0.6.2.1 -> 0.7.0.1) Subpackages: kquickimageeditor6-imports libKQuickImageEditor1 - Update to 0.7.0.1: * Fix build on ARM with SVE - Update to 0.7.0: * Removed OpenCV dependency by replacing the stack blur with a Qt Concurrency and Highway SIMD library based implementation. * Added color adjustment API. * Added repainted signal to AnnotationDocument. AnnotationDocument periodically repaints annotationsImage and canvasBaseImage. * AnnotationDocument::renderToImage always returns the latest image. If necessary, it will wait for repaints to finish before returning. * Annotation shadows don't jitter as much while being drawn or resized. * Added hasSelectionChanged and optionsChanged signals to SelectedItemWrapper. * For more details see https://mail.kde.org/pipermail/kde-announce/2026-August/000524.html - Add %check ==== kscreen6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * kcm: fix the check for showing the calibration button (kde#524507) * Update version for new release 6.7.5 ==== kscreenlocker6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libKScreenLocker6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== ksshaskpass6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== ksystemstats6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Fix i915 PMU path for discrete Intel GPUs (kde#517334) * osinfo: Provide some fallbacks for the version property (kde#523727) * Update version for new release 6.7.5 ==== kwalletmanager ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== kwayland-integration6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kwayland6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libKWaylandClient6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== kwin6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libkwin6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Too many changes to list here - Drop patches, now upstream: * 0001-wayland-Increase-global-removal-timer-timeout-to-1-d.patch ==== layer-shell-qt6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libLayerShellQtInterface6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== libarchive ==== Version update (3.8.7 -> 3.8.9) - Update to 3.8.9: * unzip: Windows port (#3167) * various further bugfixes: https://github.com/libarchive/libarchive/compare/v3.8.8...v3.8.9 - 3.8.8: * zip: support for reading encrypted zipx formats (bzip2, lzma, ppmd, xz, zstd) (#2685) * build: fix build with glibc 2.43 (#2969) * libarchive core: various NULL pointer, double-free, buffer overrun and integer overflow fixes (#2905, #2927, #2928, #2942, #2957, #2971, #2973, #2988, #2998, #3009, #3010, #3011, #3012, #3019, #3036, #3037, #3040, #3064, #3083, #3114, #3146) * windows: remove support for WinCrypt, fix GetTempPathW TOCTOU race condition (#2739, #3044) * filters (bzip2, gzip, lz4, uu, zstd): fixes for large archives, truncated input handling and out-of-bounds access (#2526, #3033, #3050, #3054, #3073, #3085, #3093, #3100, #3103, #3115, #3132) * 7-zip: multiple heap overflow, hardening and streamable reading fixes (#2923, #2929, #2980, #2985, #3002, #3006, #3062, #3067, #3074, #3099, #3102, #3119) * cab: multi-volume parser fixes and hardening against invalid/truncated headers (#2979, #3000, #3144, #3145, #3153) * cpio: pathname validation and out-of-bounds read fixes (#2984, #3043, #3055, #3095, #3158, #3168) * iso9660: fix path normalization, Joliet overflow/infinite loop and memory leaks (#2968, #2974, #2978, #2983, #3017, #3021, #3029, #3045, #3117) * mtree: fix hex/time value parsers and NULL dereferences (#2930, #2982, #3007, #3008, #3018, #3032, #3057) * RAR/RAR5: fix bound checks, dangling pointers and integer underflow (#3004, #3015, #3047, #3048, #3081, #3087, #3091, #3105, #3121) * tar: harden timestamp parsing, fix OOB with empty wide character directory names (#2991, #3038, #3052) * warc: fix header allocation leak on overflow (#3061) * xar: fix integer overflows, memory leaks and OOB writer accesses (#3013, #3028, #3030, #3032, #3041, #3060) * zip: reject overlong/empty pathnames, limit LZMA memory usage (#2981, #2993, #2996) - Removed add-missing-tests.patch: upstream 3.8.9 tarball now ships test_read_format_cab_skip_malformed.c and .cab.uu again, the patch no longer applies and is no longer needed ==== libbpf ==== - Use make macros with -C ==== libcupsfilters ==== Subpackages: libcupsfilters2 - libcupsfilters-2.1.1-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to libcupsfilters 2.1.1 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - libcupsfilters-2.1.1-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to libcupsfilters 2.1.1 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== libfido2 ==== - Drop USE_HIDAPI, as it produces a race condition (bsc#1234010) ==== libgcrypt ==== Version update (1.12.2 -> 1.12.3) - Update to 1.12.3: * Validate hash algorithm for use with RSA modulus * Validate parameters of Balloon KDF * Validate parallelism of Argon2 KDF * Fix parsing quoted parts and CRLF/LFCR in s-expression * Support BUFLEN check for GCRYMPI_FMT_SSH * Fix RSA PSS verify message length checking * Avoid a NULL ptr deref due to a unsupported genkey flag for ECC * Assert 32 KiB input cap in gcm_ctr_encrypt * Fix assertion failure in OCB when a buffered block becomes block 65536 * Fix OOB read in IMIT MAC verify of GOST28147 * Fix CMAC block-count truncation for 64 GiB writes * Fix AEAD spurious byte-counter carry for 4 GiB adds * Validate all KEM input lengths * Add length check of DATALEN when parsing s-expression * Only accept canonical value for S with EdDSA * Only accept canonical signatures for RSA * Fix an assertion failure for invalid small-order Ed25519 public keys * Validate length of supplied receiver public-key length in DHKEM decapsulation * Use a more strict value for the PKCS#1 minimal frame length. * Use just strong random for the Dilithium signature nonce and the Kyber encapsulation coins * Allow internal users to skip fast random poll for ciphers and hashes * Speedup sntrup761 by defer reduction in polynomial multiplication, reading random with a single call, and reducing freeze helpers w/o division * Avoid byte-wise load/store on RISC-V with Zicclsm * Use unaligned vector memory access on RSIV-V when supported * Add Intel SM4 instructions accelerated AVX512 and AVX2 implementation * Add Intel SM3 extension implementation * Add Intel SHA512 extension implementation * kyber: Accept and return a seed using the gcry_pk_genkey API * Add curve "ietf25" as alternative to "Curve25519" with exact RFC-8410 semantics. The name "X25519" was already used as an alias, thus this new name. * Add straight-line speculation hardening for function ends * Fix constant time memequal check for SM2 * Add post-quantum algorithm benchmarking to bench-slope * Due to the minor API updates and but with no newer branch released the SO name has been updated. - update upstream signing key ==== libheif ==== Version update (1.23.1 -> 1.23.4) - Update to version 1.23.4: * CVE-2026-XXXXX: The max_items security limit was not enforced for the child boxes of iinf, so a file could declare an unbounded number of items. * CVE-2026-XXXXX: Unbounded recursion in the reference-cycle check crashed the parser on a long chain of derived items, without bound when the item-count limit is disabled. * CVE-2026-XXXXX: Permanent decoder deadlock through a lock-order inversion in parallel grid tile decoding (enabled by default). * CVE-2026-XXXXX: Heap out-of-bounds read in the encoder pluginsi for images whose luma and chroma bit depths differ. * CVE-2026-XXXXX: Unreclaimable memory leak in heif_track_get_next_raw_sequence_sample(). * CVE-2026-XXXXX: Heap out-of-bounds read in the WebCodecs decoder plugin - includes fixes from 1.23.3: * CVE-2026-XXXXX: Heap buffer overflow (write) in the uncompressed (unci) mixed-interleave decoder when the two chroma components declare different bit depths. * CVE-2026-XXXXX: Permanent decoder deadlock through a reference cycle between an image and its alpha auxiliary image. * CVE-2026-XXXXX: Heap out-of-bounds read in the YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma planes have a lower bit depth than luma * CVE-2026-XXXXX: Heap buffer overflow in the SVT-AV1 encoder plugin when encoding a high-bit-depth alpha channel, and a double free on its send-picture error path. * CVE-2026-84451: Incomplete fix: the tile range check of the unci decoder (without icef) could still overflow, allowing an out-of-bounds read * CVE-2026-XXXXX: Heap out-of-bounds read when converting odd- height 4:2:0 frames of an uncompressed (uncv) image sequence to RGB. * CVE-2026-XXXXX: Out-of-bounds read in the RGB to YCbCr identity- matrix color conversion when the R, G, and B planes have different bit depths * CVE-2026-84450: A clap property combined with an oversized ispe reached an assert() in the Fraction arithmetic and aborted the process (incomplete fix). An error is returned instead. * Fix Several smaller findings * Fix Undefined behavior (negative shift) in the HDR bit-depth up-conversion for target bit depths above 16. Such conversions are now rejected. * A number of bug fixes - Update to version 1.23.2: * CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items. (boo#CVE-2026-84383) * Out-of-bounds read and write in derived-item and pixel-plane handling. Through iden and auxl item chains, a crafted file could attach pixel planes whose size differs from the image geometry; crop, scale, and plane-extraction code then indexed those planes with the wrong size. A working code-execution exploit was confirmed. Plane sizes are now validated wherever they are consumed. (boo#1279444) * CVE-2026-84384: brotli/zlib decompression of mime metadata and unci image data had no effective output-size limit, so a decompression bomb could exhaust memory. Decompressed output is now bounded by the security limits. (boo#1279445) * CVE-2026-84447: Chains of derived-image references (grid, iovl, iden) bypassed decode caching and memory limits, causing CPU and memory amplification. (boo#1279446) * CVE-2026-84446: Sequence sample-timing initialization could produce non-terminating decode loops and unbounded memory, bypassing max_sequence_frames. (boo#1279447) * CVE-2026-84444: Out-of-bounds write in the unci encoder when heif_context_add_image_tile() is given a tile whose planes do not match its declared size. (boo#1279448) * CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API when mask_data_len does not match the region geometry. (boo#1279449) * C++ exceptions such as std::bad_alloc can no longer escape the C API read/decode entry points; they are returned as a heif_error instead of aborting the process * assert()s in the pixel-image plane allocation were replaced by runtime errors * stts/ctts tables describing more samples than the track can have are rejected * pclr (JPEG 2000 palette) box: the number of palette entries is bounded by the box size * BitReader::skip_bytes() is now constant time (fixes a fuzzer timeout on bogus alignment values) * iden items now validate the decoded image size like all other items * The uncompressed (unci) encoder rejects images without pixel planes * meta, mini, and moov boxes with size 0 (extending to the end of the file) are now parsed correctly * Fixed an integer overflow when probing the file size * Fixed undefined behavior (signed shift) when reading the NAL unit length in the OpenH264 decoder * heif_region_item_add_region_inline_mask_data() now requires non-zero width and height and the mask_data_len must equal the expected (width * height + 7) / 8; otherwise it returns an error instead of storing the mask * heif_image_add_plane() returns an error instead of aborting for bit depths outside 1..128 or interleaved component counts outside 1..255 ==== libjpeg-turbo ==== - do not skip djpeg12-shared-3x2-float-prog-cmp, use correct parameters instead ==== libkdcraw ==== Version update (26.08.0 -> 26.08.1) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== libkexiv2-qt6 ==== Version update (26.08.0 -> 26.08.1) Subpackages: libKExiv2Qt6-0 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== libkgapi6 ==== Version update (26.08.0 -> 26.08.1) Subpackages: libKPim6GAPICore6 libKPim6GAPIDrive6 libkgapi6-sasl2-kdexoauth2 - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== libksba ==== Version update (1.8.0 -> 1.8.1) - Update to 1.8.1: * Fix CMS parser to avoid possible infinite loop - drop libksba-nobetasuffix.patch, not needed when autoreconf is not run. Also don't run it. - Fix fgrep deprecation warnings in ksba-config --libs output boo#1203092 add libksba-1.8.1-fgrep-warning.patch, sent upstream ==== libkscreen6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libKF6Screen8 libKF6ScreenDpms8 libkscreen6-plugin - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== libksysguard6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: ksysguardsystemstats6-data libKSysGuardSystemStats2 libksysguard6-imports - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== libnftnl ==== Version update (1.3.1 -> 1.3.2) - Update to release 1.3.2 * Support for connlimit stateful objects * Now validates geneve class and type attribute size in setter and validates that the kernel does not provide too long geneve data attributes. * Do not print userdata content through snprintf API. * Enhancements for the snprint API to display data according to size and byteorder, this includes new functions nftnl_{expr,set_elem}_set_imm() to decorate the data. * More improvements for the snprintf() API for set elements: no colon is printed if data is not provided, print object names in maps and print flags only if non-zero. ==== libpisp ==== Version update (1.6.0 -> 1.7.0) - Update to version 1.7.0 * gst: Add BGR output format support. * gst: Honour GstVideoMeta strides on input buffers. * gst: Fix R/B channel ordering for RGB output formats. * tests: Add strided input and BGR test cases. * tests: Drop BGR compensation for GStreamer RGB output. ==== libplasma6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libPlasma7 libplasma6-components libplasma6-desktoptheme - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== libupnp ==== Version update (22.0.6 -> 22.1.0) Subpackages: libixml22 libupnp22 - Update to release 22.1.0 * OSS-Fuzz: Add new fuzzer targets service table processing ==== libxml2 ==== Version update (2.15.3 -> 2.15.4) Subpackages: libxml2-16 libxml2-tools - Update to version 2.15.4: + Security: - xmlregexp: Prevent out-of-bounds read in NXT macro - fix: add missing overflow checks in dict.c, uri.c, and valid.c - xmlregexp: Calc string length after null checking - xpointer: Check overflow in xmlXPtrEvalXPtrPart - xmlIO: Check for int overflow before calling writecallback - fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree + Improvements: - Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound) - Fix memory leak in static Windows library (memory-leak) - xmlreader: Copy DTD in xmlTextReaderDumpCopy - parser: Fix double free in xmlIOParseDTD (double-free) - parser: fix division-by-zero when maxAmpl is set to 0 - parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak) - catalog: Make sure to reset catalog resolve cache - xmlAddChild: unlink node before free for text nodes (memory-leak) - Normalize entity values in attr in xmlNodeGetContent - Handle whitespace for date/time/duration types - catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref) - Drop libxml2-CVE-2026-11979.patch: Fixed upstream. ==== libzypp ==== Version update (17.38.14 -> 17.38.15) - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - version 17.38.15 (35) ==== live555 ==== Version update (2026.08.14 -> 2026.08.25) Subpackages: libBasicUsageEnvironment2 libUsageEnvironment3 libgroupsock33 libliveMedia120 - Update to version 2026.08.25: + Fixed a bug in "VorbisAudioRTPSource" that could have caused a malicious SDP description to crash a RTP client. ==== milou6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== mozilla-nspr ==== Version update (4.39 -> 4.40) - update to version 4.40 * no upstream release notes found ==== mozilla-nss ==== Version update (3.126.1 -> 3.127) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.127 * bmo#2060720 - Round ECH ClientHelloInner padding up to a multiple of 32 * bmo#2063071 - make selfserv listen on IPv6 wildcard on dual-stack hosts * bmo#2059176 - EC_DerivePublicKey() failure is not propagated in sftk_mkPrivKey() * bmo#2052210 - Generate additional test message for Thunderbird (HTML with remote image) * bmo#1869493 - Heap-buffer overflow in AES Keywrap * bmo#2054609 - remove cipher suite order exception from bug 946147 * bmo#2061107 - restore pkcs12.h for source compatibility * bmo#2056291 - remove support for pre-v1.0 PKCS#12 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext * bmo#2060118 - remove DH_GenParam support * bmo#2053831 - clang format * bmo#2054714 - avoid leaking stale ECH outer extensions across HRR * bmo#2053831 - Drop CKF_VERIFY flag from CKM_HKDF_DATA derivation in ECH GREASE * bmo#2053831 - Adjust PK11_Derive and TLS 1.3 derivation templates for CKM_HKDF_DATA and CKO_DATA compliance * bmo#2053831 - Use CKF_HKDF_SALT_DATA in tls13_HkdfExtract for CKO_DATA keys per PKCS#11 v3.2 * bmo#2057184 - Enable -Wunused-but-set-variable/-global in werror.py * bmo#2056846 - Remove unused policy string callback to fix - Wunused-but-set-global * bmo#2052709 - Convert NSS 3.126 release notes to Markdown * bmo#2052709 - Rename doc/rst to doc/src and update references * bmo#2052709 - Apply markdownlint to the converted Markdown docs * bmo#2052709 - Fix Markdown documentation build warnings * bmo#2052709 - Convert documentation from reStructuredText to Markdown (automated) ==== multipath-tools ==== Version update (0.15.1+227+suse.6644513 -> 0.15.1+229+suse.6c6f63e) Subpackages: kpartx libmpath0 - Update to version 0.15.1+229+suse.6c6f63e: * Fix hang in initrd during installation (bsc#1274053) ==== nftables ==== Version update (1.1.6 -> 1.1.7) Subpackages: libnftables1 python313-nftables - Update to release 1.1.7 * Fix spurious EEXIST error when using the create element command with large batches. * Improve error reporting for syntax errors by printing expected tokens. * Set element support for multi-statements, e.g. counter + quota. * Connlimit support with maps. * Support for using bitmask datatypes as set key, e.g. tcp flags. - Delete support-reproducible-build.patch (merged) ==== nvme-cli ==== Version update (3.0~b.4 -> 3.0+6.g1ac60ca4b) Subpackages: libnvme3-1 - drop the 'v' from the version string - Update to version v3.0+6.g1ac60ca4b: * tests: make the fabrics mock IPC wire format explicit little-endian * tests: make the fabrics mock work on 32-bit time64 architectures * tests: fix native-endian struct.pack in fabrics discovery mock * build: show CFLAGS/LDFLAGS in the meson configuration summary * build: cross-test on i386 to catch 32-bit time_t truncation bugs - Update to version v3.0+1.g56361dc25: * shared: fix time_t truncation in shr_format_ts() on 32-bit archs - Update to version 3.0: * Release v3.0 * doc: Regenerate all docs for v3.0 * scripts: handle NEWS.md update on release * completions: update the shell completions * libnvme: return an empty string for missing namespace attributes * nvme-types-base: fix kernel-doc-check warnings * log: check if etdas setting supported or not * log: add force option to report data area 4 * ioctl-win: add support for dsm command with deallocate attribute * ocp: add missing case 6 fields to ocp smart log v2 json output * completions: move completion install rules into completions/meson.build * completions: regenerate from a full build * completions: wire generation and drift-check into the build * ioctl-win: extend data out buffer fix to all write commands with no data * ioctl-win: differentiate between io and admin storage protocol commands * ioctl-win: fix ns delete handling * ctrl-map: make Windows pci address detection locale-independent * libnvme: use the shared validators in the config parser * shared: check the month and character set in an NQN * tests: use valid NQNs in test fixtures * libnvme: validate the host NQN and host identifier on read * shared: add NQN and UUID string validators * libnvme: do not scan the topology when creating a GlobalCtx * libnvme: expose scan_topology() in the Python bindings * libnvme: let GlobalCtx() take the host identity * libnvme/fabrics: fix to check dctype string NULL pointer * doc: fix ocp documentations asciidoc failures * doc: add feat and ocp commands to meson.build * doc: add feat commands remainted * nvme-print: fix null pointer dereference in strset_iterate_sorted_ * libnvme: flag read=none members in the generated SWIG interface * libnvme: build the host identity Python objects with Py_BuildValue() * libnvme: document the ctx default in the host identity docs * nvme-discoverd: take a time span for the give-up horizon * shared: add shr_parse_time() * ocp: remove logically dead code in parse_event_fifo() * libnvme: simplify file existence check in test_creates_missing_directory() * tests: use pathlib in the e2e test cases * tests: use pathlib in the e2e runner * registry: fix unchecked return value from libnvmf_registry_attr_for_each * exclusion: fix insecure temporary file creation in excl_edit() * libnvme: fix unchecked return value of sscanf in ctrl_instance() * libnvme: check return value of sscanf in libnvme_ns_generic_to_blkdev() * keys: print check command results only with --verbose * shared: fix resource leaks on early return in table tests * mem: remove unnecessary type cast * mem: fix integer overflow in allocation rounding * plugins/solidigm: Improve Telemetry debug info parsing * doc: fix to add copy command namespace-id option description * tests: probe both stdout and stderr for _probe_command * completions: regenerate from the alphabetized generator * completions: update test for alphabetical output * completions: alphabetize bash and zsh command and option lists * doc: add power mgmt command * feat: fix to add err-recovery command nsid option checking * doc: add err-recovery command * doc: add num-queues command * doc: add host-behavior-support command * doc: add lba-range-type command * feat: add lba-range-type command * utils: fix resource leak in copy_opt_val on strdup failure * ocp: print physical media units written/read as 128-bit decimal value * libnvme: python: decode discovery log page fields the way C does * tests: add CLI tests for samsung vs-internal-log * plugins/samsung: add Samsung vendor specific extensions plugin * shared: add shr_dir_prefix_len() * shared: handle a path with no file name in shr_mkdir_from_fname() * shared: fix tautological range check in DEFINE_SHR_PARSE_CSV_FUNC * libnvme: expose the top-level host identity * libnvme: python: expose the top-level connection defaults * Release v3.0-rc3 * completions: regenerate bash, zsh, and PowerShell completions for v3.0-rc3 * doc: Regenerate all docs for v3.0-rc3 * nvme: fix improper value passed to libnvme_strerror in identify_ctrl * libnvme: leave registry ownership alone on a reused connection * nvme: make --quiet suppress informational output * libnvme: carry the fabrics context credentials into the controller * doc: nvme-fabrics.conf is shared by the nvme-cli tools, not by everyone * fw: fix improper value passed to libnvme_strerror in fw_commit_support_mud * shared: fix improper use of negative row id in test_multi_type_and_centered * tests: fix improper use of negative return value in test_shr_table_print() * shared: fix missing negative-return check in test_invalid_format_type * shared/tests: fix improper use of negative row id in test_basic_table * libnvme: python: stop freeing tree-owned objects in destructors * nvme-cmds: fix status code type check for get log dynamic chunk retry * ioctl-win: use generic passthru for get log with non-NVM CSI values * ioctl-win: retry skipped log pages with generic passthrough * libnvme: pass the global context to the host ID generators * nvme: list every exclusion list and flag invalid entries ... changelog too long, skipping 414 lines ... - undone the missing man pages change from b4 in the spec file ==== openssl-3 ==== Subpackages: libopenssl3 - Security fix: * CVE-2026-75803: openssl: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837) * Add openssl-CVE-2026-75803.patch - Security fixes in August 2026 release: (bsc#1274774) * CVE-2026-14456: Unbounded Memory Growth in QUIC Server Incoming Channel Queue (bsc#1274791) * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792) * CVE-2026-18798: QUIC Server May Trigger Double Free When Processing INITIAL Packet (bsc#1274777) * CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343) * CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795) * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788) * CVE-2026-63073: Untrusted Sender DN Used as Format String in CMP Response Validation (bsc#1274796) * CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797) * CVE-2026-63075: QUIC ACK-only Packet Retention Can Cause Memory Exhaustion (bsc#1274798) * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790) * Add patches: openssl-CVE-2026-14456.patch openssl-CVE-2026-14457.patch openssl-CVE-2026-18798.patch openssl-CVE-2026-34181.patch openssl-CVE-2026-54874.patch openssl-CVE-2026-63072.patch openssl-CVE-2026-63073.patch openssl-CVE-2026-63074.patch openssl-CVE-2026-63075.patch openssl-CVE-2026-63076.patch ==== orc ==== Version update (0.4.43 -> 0.4.44) - Update to version 0.4.44: + Fix various i386-related regressions + avx512: - Disable target on x86 - Implement the missing memoff-reg moves + Fix Debian gcc miscompiling the backup float conversion functions ==== partitionmanager ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== patterns-kde ==== Version update (20260428 -> 20260830) - Drop Leap 15 recommends from spec file - Recommend libreoffice-qt6 when installing the KDE Office pattern rather than libreoffice-qt5 (boo#1277445) ==== patterns-microos ==== Subpackages: patterns-microos-alt_onlyDVD patterns-microos-base patterns-microos-base-packagekit patterns-microos-base-zypper patterns-microos-basesystem patterns-microos-cloud patterns-microos-cockpit patterns-microos-defaults patterns-microos-desktop-common patterns-microos-desktop-kde patterns-microos-ima_evm patterns-microos-onlyDVD patterns-microos-ra_agent patterns-microos-ra_verifier patterns-microos-selinux patterns-microos-sssd_ldap - Make account-utils the default ==== pcre2 ==== Version update (10.47 -> 10.48) Subpackages: libpcre2-16-0 libpcre2-8-0 - Update to 10.48: * GHSA-2p8c-ff85-vh9x: If pcre2_jit_compile() is called with options for some match modes, and then pcre2_match() is used to perform a match for a different match mode, an out-of-bounds read can occur if the match is attempted against invalid UTF input. (boo#1277708) * GHSA-q8g2-wprr-34m9: If pcre2_convert() is called on untrusted input on platforms with 32-bit size_t, an out-of-bounds heap write can occur (boo#1277707) * GHSA-3r4p-g7gg-ppmf: Fixed an out-of-bounds write in DFA matching when using a heap limit; also fixed possible integer overflows which could cause under-allocation of the workspace. (boo#1277713) * GHSA-fmgr-6ggq-9859: Added bounds checks for several integer overflows while compiling patterns on 32-bit CPUs, which could cause under-allocation followed by out-of-bounds writes. (boo#1277709) * GHSA-9qww-pwc4-77qq: Applied lower buffer bound to prevent two out-of-bounds reads while scanning backwards through invalid UTF data with PCRE2_MATCH_INVALID_UTF. (boo#1277710) * Fix a JIT-specific matching bug affecting prefix scanning on patterns with repeats * Fix a JIT-specific matching bug in variable-length lookbehinds * Miscompiled Unicode character classes combining characters at or below U+00FF with characters at U+0100 and U+8000 or above * Incorrect JIT character advancement with PCRE2_MATCH_INVALID_UTF in UTF-8 and UTF-16 modes, which could skip adjacent characters * Update Unicode support to Unicode 17.0 * Fix a leak and later invalid free when calling the fast-path pcre2_jit_match() function with a match data object previously used with pcre2_match() and PCRE2_COPY_MATCHED_SUBJECT. (boo#1277711) * GHSA-q7rw-r7qq-2hx6: Fix exposure of two uninitialised bytes from malloc() via pcre2_serialize_encode() (boo#1277712) - Fix (all) rpmlint warnings ==== plasma5support6 ==== Version update (6.7.4 -> 6.7.5) Subpackages: libPlasma5Support6 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-activities ==== Version update (6.7.4 -> 6.7.5) Subpackages: libPlasmaActivities7 plasma6-activities-imports - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-activities-stats ==== Version update (6.7.4 -> 6.7.5) Subpackages: libPlasmaActivitiesStats1 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-browser-integration ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-desktop ==== Version update (6.7.4 -> 6.7.5) Subpackages: plasma6-desktop-emojier - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 * applets/kicker: don't launch favorites twice on Space * emojier: go back to search field on Arrow Up * Add missing Qt::Qml link * containments/desktop: respect type-ahead setting in widget (kde#523053) * applets/kickoff: disable reusing items in KickoffGridView (kde#515229) * applets/taskmanager: correct for initial spacer in RtL (kde#504898) * applets/taskmanager: make task progress bar follow rtl (kde#524112) * applets/kicker: don't allow dragging categories * applets/kicker: fix highlight while dragging * emojier: make window large enough for sidebar (kde#523090) * containments/panel: strip mnemonics from tooltip (kde#488578) * applets/taskmanager: Fix "cannot read property width of undefined" warnings * Only link discover to deb files on deb-based distros * applets/taskmanager: Ask for a thumbnail when window is ready for painting * Panel: expose reorderApplets() function for scripting * desktop: Do not overwrite wallpaper-provided accent color (kde#514656) * minimizeall, showdesktop, folder: update BugReportUrl * kcms/landingpage: Fix color bleed through at the corners (kde#522042) * spellchecking: do not ask to apply settings if no backend or dictionary exists (kde#521712) * Update version for new release 6.7.5 ==== plasma6-integration ==== Version update (6.7.4 -> 6.7.5) Subpackages: plasma6-integration-plugin plasma6-integration-plugin-qt5 - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * MessageDialogHelper: don't set WA_DeleteOnClose (kde#523039) * Remove linux (Qt5) CI * Update version for new release 6.7.5 ==== plasma6-nm ==== Version update (6.7.4 -> 6.7.5) Subpackages: plasma6-nm-openconnect plasma6-nm-openvpn - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * secretagent: fix duplicate delete/update jobs * Use dynamically allocated DeletePasswordJob * secretagent: fix missing secrets returned * secretagent: fix crash with multiple requests (kde#521935) * Update version for new release 6.7.5 ==== plasma6-openSUSE ==== - Update to 6.7.5 ==== plasma6-pa ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-print-manager ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== plasma6-systemmonitor ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 * Fix process termination when used in RtL language (kde#522233) * Update version for new release 6.7.5 ==== plasma6-workspace ==== Version update (6.7.4 -> 6.7.5) Subpackages: plasma6-session plasma6-workspace-libs - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Add missing Qt::Qml link * applets/notifications: Don't invoke default action when a link is hovered * Klipper: Make the Help button in Klipper's config work * Klipper: Make apply work in keyboard shortcuts configuration tab (kde#485460) * InfiniteList: fix current day view * applets/digital-clock: fix tooltip overflow and center time zones (kde#524390,kde#501555) * InfiniteList: fix calendar changing views when dragging it between displays (kde#472360) * 🍒 shell/scripting: fix setOpacity calling wrong method * klipper: Preserve encoded PNG when restoring history entries * Scripting: restore Applet::index property (kde#523675) * applets/digital-clock: Compare agenda dates across time zones (kde#442100) * margins-separator: update BugReportUrl * kcms/nightlight: Add missing non-default highlight (kde#521974) * Update version for new release 6.7.5 ==== polkit-kde-agent-6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== powerdevil6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * powerdevil: Clear stale battery warnings after charging * applets/batterymonitor: omit PPD message when there's no PPD * kcm: Fix non-default highlight * Update version for new release 6.7.5 ==== python-dbus-python ==== Version update (1.3.2 -> 1.4.0) - update to 1.4.0: * Automatically set the NO_REPLY message flag in call_async if there is no reply handler and no error handler * Add arg0namespace match rule support Hofstee) * Add argNpath match rules support * Generate a valid sdist from `meson dist` * Mention more alternatives to this package in the README * Don't require tomllib when generating dist tarball on Python ≥ 3.11 * Fix compilation with Python ≥ 3.13 in some situations * Avoid using distutils in setup.py (Simon McVittie) * Fix a typo in example code (dbus-python!25, Robert Ancell) * Safer handling of weak references (Simon McVittie) - add missing keyring - add Revert-using-Py_TPFLAGS_MANAGED_WEAKREF.patch from fedora, fixes testsuite failures on newer python versions ==== python-idna ==== Version update (3.18 -> 3.19) - update to 3.19: * Restore the `std3_rules` option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that `uts46_remap()` defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again. * Performance improvements to UTS #46 mapping, particularly for ASCII-only domains. * Test on free-threaded CPython with the GIL disabled and document thread safety. * Expose the Unicode version of the generated tables as `idna.unicode_version`, and show it in `idna --version`. * Add `code`, `text`, `codepoint` and `position` attributes to `IDNAError` so that the failed rule and the offending character can be identified without parsing the exception message. * The deprecated `transitional` argument to `encode()` and `uts46_remap()` is now completely ignored, and gives a deprecation warning for the latter. * Reject A-labels that are not the canonical Punycode encoding of their U-label. * Fix CONTEXTJ violations raising `IDNAError` instead of `InvalidCodepointContext`. * Consistently raise `IDNAError` for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec. * Add property-based tests, extended fuzzing targets, coverage * measurement, and CI checks that the data tables match the generator output. * Various code quality and tooling improvements. ==== python-maturin ==== Version update (1.14.1 -> 1.15.0) - Update to 1.15.0 * set UV_PYTHON when running maturin develop with uv gh#PyO3/maturin#3236 * Set UID and GID headers in pax gh#PyO3/maturin#3241 * Replace unguarded panics with explicit errors on fallible input gh#PyO3/maturin#3242 * Harden PEP 517 build-wheel and fix unreachable OIDC 404 fallback gh#PyO3/maturin#3244 * docs: add pdfcrate and quebec to examples gh#PyO3/maturin#3245 * Fix abi3t PyModExport entrypoint check gh#PyO3/maturin#3246 * fix maturin build --pgo -i with uv install gh#PyO3/maturin#3237 * Don’t specify generate-import-lib for PyO3 0.29 gh#PyO3/maturin#3258 * refactor build so that pgo is part of normal pathway gh#PyO3/maturin#3257 * fix: verify bindings detection with cargo tree in workspaces gh#PyO3/maturin#3264 * fix: harden cargo tree verification of bindings detection gh#PyO3/maturin#3266 * feat: support --pgo for maturin develop gh#PyO3/maturin#3270 * feat: support MATURIN_PGO env var to activate --pgo gh#PyO3/maturin#3271 * feat: type the bindings input with a single-source-of-truth enum gh#PyO3/maturin#3273 * Don't force export of the PyInit_{module_name} in UniFfi mode gh#PyO3/maturin#3275 * fix(generate-stubs): write stubs into the module's package directory gh#PyO3/maturin#3282 * Fix group not cwd gh#PyO3/maturin#3284 * docs: document missing [tool.maturin] config fields gh#PyO3/maturin#3287 * docs: fix cross compiling heading level gh#PyO3/maturin#3290 ==== python313-packaging ==== Version update (26.2 -> 26.3) - update to 26.3: * Add a public :class:`~packaging.ranges.VersionRange` API and :meth:`SpecifierSet.to_range() `, representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. :meth:`~packaging.ranges.VersionRange.to_specifier_set` converts a range back to a :class:`~packaging.specifiers.SpecifierSet` where a PEP 440 form exists. (:pull:`1267`, :pull:`1270`, :pull:`1298`) * PEP 808: accept Metadata-Version: 2.6. (:pull:`1194`) * Add a limit argument to parse_tag() for compressed tag sets. (:issue:`1220`) * Add a prefer_sdist_predicate argument to Pylock.select() to prefer source distributions over wheels for selected packages. (:pull:`1334`) * Add :func:`~packaging.tags.pure_python_tags` to generate the pure-Python tags for a Python version without touching the running platform. (:pull:`1346`) * Add :meth:`SpecifierSet.is_subset() `, :meth:`~packaging.specifiers.SpecifierSet.is_superset`, and :meth:`~packaging.specifiers.SpecifierSet.is_disjoint`, which compare the versions two specifier sets accept. (:pull:`1313`) * Drop support for Python 3.8; packaging now requires Python 3.9 or later. (:pull:`1157`) * Prefer native linux_* platform tags over manylinux and musllinux tags on Linux. (:issue:`160`) * Raise InvalidVersion instead of TypeError when Version is given a non-string. (:pull:`1319`) * Raise InvalidVersion for non-string pre-release letters passed to Version.from_parts. (:pull:`1241`) * Fix an AttributeError when hashing internally trimmed versions. (:pull:`1242`) * Fix SpecifierSet.is_unsatisfiable for post-release boundary intersections. (:pull:`1257`) * Make Requirement.__hash__ consistent with __eq__ for trailing-zero-equivalent specifiers (e.g. foo==1.0.0 and foo==1.0.0.0), so equal requirements hash equal and deduplicate in sets and dicts. (:pull:`1232`) * Normalize requested extra names before comparing or hashing requirements. (:issue:`644`) * Preserve a Requirement's specifier prereleases override across a pickle round trip. (:issue:`1204`) * Raise InvalidRequirement instead of InvalidSpecifier when a requirement contains an invalid specifier. (:pull:`1332`) * Clarify the error for post-release prefix wildcards like ==1.0.post1.*. (:pull:`1299`) * Preserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (:pull:`1213`) * Keep the parentheses of a nested group when serializing markers. (:pull:`1316`) * Normalize extra and dependency_groups values in nested markers at parse time. (:pull:`1246`, :pull:`1310`) * Raise UndefinedComparison when a set-valued variable like extras is used outside the membership form. (:pull:`1265`) * Raise UndefinedEnvironmentName (a KeyError subclass) for missing environment keys during marker evaluation. (:pull:`1276`) * Wrap malformed string literal errors in InvalidMarker / InvalidRequirement instead of leaking a low-level error. (:pull:`1249`) * Reject requirements and markers with a trailing line break. (:pull:`1345`) * Collect all from_email validation errors into one ExceptionGroup instead of raising the first. (:pull:`1268`) * Accept the UTF-8 charset case-insensitively in email payloads. (:pull:`1330`) * Reject malformed Description-Content-Type values. (:pull:`1329`) * Don't rewrite user values that contain {field} placeholders in error messages. (:pull:`1327`) * Route multipart email payloads to unparsed instead of asserting. (:pull:`1247`) * Make InvalidMetadata and CyclicDependencyGroup picklable. (:pull:`1328`) * Fold every line boundary str.splitlines recognizes when writing a header with :class:`~packaging.metadata.RFC822Message`. (:pull:`1356`) * Raise InvalidLicenseExpression for misplaced WITH clauses and empty LicenseRef- names. (:pull:`1266`) * Raise InvalidLicenseExpression instead of KeyError for a LicenseRef- with a + suffix. (:pull:`1219`) * Raise InvalidTag from parse_tag() for tags with the wrong number of components. (:pull:`1238`) * Reject empty tag components in parse_wheel_filename() and parse_tag(). (:pull:`1234`) * Reject an empty project name in the wheel and sdist filename parsers. (:pull:`1305`) * Reject wheel filenames with a trailing newline. (:pull:`1341`) * Reject wheel tags whose interpreter component is not an identifier. (:issue:`577`) * is_normalized_name now rejects names with collapsed double hyphens like a--b. (:pull:`1230`) * Fix duplicate explicit abi3t tags. (:pull:`1245`) ... changelog too long, skipping 58 lines ... * Use nox's uv integration. (:pull:`1057`) ==== qca-qt6 ==== Version update (2.3.10 -> 2.3.12) Subpackages: libqca-qt6-2 - Update to version 2.3.12: * Update rootcerts.pem * Increase version number * CI: gitlab-templates/linux.yml is gone * qca-ossl: do not dereference a DH key that failed to generate * qca-ossl: load the default OpenSSL provider explicitly (kde#482819) * CI: Add build with openssl4 * Update rootcerts.pem * CI: A bit of janitoring * Increase version number * Define QCA_FULL_INCLUDE_INSTALL_DIR after USE_RELATIVE_PATHS has been processed * Compile with openssl4 * CI: Remove fedora 34 build * Remove FreeBSD Qt5 build ==== qemu ==== Version update (11.0.3 -> 11.1.1) - Bugfixes (bsc#1277435, bsc#1263864): * file-posix: Tolerate unaligned hole at middle (bsc#1277435) * target/ppc/kvm: Use host compatibility mode for nested guests (bsc#1263864) * target/ppc/kvm: Add support for querying host compatibility mode (bsc#1263864) * linux-headers: Update to include KVM_CAP_PPC_COMPAT_CAPS (bsc#1263864) - Improve riscv64 handling: * [openSUSE][RPM] build all firmware on riscv64 and fix user tests * [openSUSE][RPM] spec: stub out all iotests when running under user emulation (e.g., for riscv64) - Fix broken build on aarch64: * [openSUSE][RPM] spec: disable GCS linker validation on aarch64 - Update to latest stable release (11.1.1) Full backport list here: https://lore.kernel.org/qemu-devel/20260827155607.639070-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/riscv/tcg: sret in virtual user mode raises virtual instruction exception target/riscv: Allow UXL to be 3 in mstatus on rv128 target/riscv: Restore register dump zero padding tests/qtest: remove trace output from k230 watchdog test target/riscv: enforce even register constraints for Zdinx fcvt pairs target/riscv: reject FMV.X.W/FMV.W.X under Zfinx target/riscv: honor zicbo* envcfg gating in linux-user mode disas/riscv: Fix typo in th.lbib format disas/riscv: Fix isa decoding of rev8 disas/riscv: Fix rv32 encoding of zext.h target/riscv: allow menvcfg/henvcfg LPE and SSE bits on RV32 hw/riscv/riscv-iommu: preserve requested perm in spa_fetch() hw/riscv/riscv-iommu: fix U-bit check to apply only to leaf S/VS-stage PTEs disas/riscv: Decode unsigned vector immediates as unsigned disas/riscv: Use signed type for vector immediates disas/riscv: Fix 6-bit immediate extraction disas/riscv: Fix th.srri decoding tests/qtest: Add seed CSR zero extension test target/riscv: Fix seed CSR sign extension target/riscv: do not count ECALL in minstret target/riscv: Fix memory leak in riscv_trigger_unrealize() target/riscv: use SXL instead of MXL for read_sstatus target/riscv: Fix PC sync in trans_sspopchk for CFI exception handling whpx: i386: inject back db whpx: i386: work around Hyper-V FP state oddities whpx: i386: synchronise PAT too whpx: i386: enable fast hypercall output hw/i386: fw_cfg: do not set VMX feature control on WHPX whpx: i386: fix xsaves enablement in legacy probing path hw/watchdog: Add lower bound check for watchdogNumber tests/tcg/aarch64: Add regression test for whilewr/whilerw target/arm: Fix SVE2 WHILEWR/WHILERW zero diff boundary case tcg: Export tcg_gen_ussub_i{32,64,tl} hw/intc/arm_gicv3: Have GIC kconfig select GICv3 for HVF and WHPX hw/intc: Fix arm kvm gicv3 selection tcg: Defer tb_flush when initial thread region alloc fails tcg: Return success from tcg_region_alloc tcg: Return success from tcg_region_alloc__locked target/loongarch: check FPE before reading fcc in bceqz/bcnez meson: make linker warnings non-fatal on Linux serial: clear transmit retry callback on unrealize ... - Revisit the fix for bsc#1232712: * hw/display/xenfb: always register vfb and allocate console early (bsc#1232712) - Switch to ipxe-qemu: * [openSUSE][RPM] spec: stop building edk2-basetools and ipxe - Upgrade to version 11.1.0 The full list of changes are available at: https://wiki.qemu.org/ChangeLog/11.1 Highlights include: * Universal Flash Storage (UFS) emulation support for Write Booster (device-level caching) and Host-Initiated Defragmentation (HID) based on UFS 4.1 specification * vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc * GUI: improvements to virtual console handling/specifying of different character encoding and GTK/VNC improvements as well * ARM: support for new architectural CPU features (too many to list here, see full changelog) * ARM: support for new imx8mp-evk machine type (based on i.MX 8MM Evaluation kit) * ARM: 'virt' board support for specifying cache topology, 'hvf' accelerator now supports nested virtualization and vGIC * HPPA: updated to SeaBIOS-hppa v25 firmware, TLB insert fixes for HP-UX 9 * PowerPC: MPIPL support for PowerNV to preserve memory after an unexpected reset, as well as support for emulating a nest MMU * RISC-V: ISA exstention support for big-endian, Zbr/xbr0p93, Zvfbfa, fractional LMUL on vector SHA instructions, KVM support for Zicbop and BFloat16 extensions, and more * RISC-V: new board support for K230, support for Tenstorrent mvendorid, and other misc. fixes/features * s390x: KVM support for ASTFLE facility 2 (for nested) * and lots more... ==== qqc2-breeze-style6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 ==== qrca ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== qt6-tools ==== Subpackages: libQt6UiTools6 qt6-tools-qdbus - Add 0003-CMake-Add-LLVM-23-to-supported-QDoc-Clang-versions.patch. ==== raspberrypi-firmware ==== - Prevent -52 error message during wifi scan (bsc#1215134). ==== samba ==== Version update (4.24.5+git.481.dba78dbdea -> 4.24.6+git.488.e38f6c96c62) Subpackages: libldb2 samba-ad-dc-libs samba-client samba-client-libs samba-libs - Build and install pycache files; (bsc#1274812) - Update to 4.24.6 * leases torture test flappy (marked flappy); (bso#15978). * Memory leak in DRS when replication fails; (bso#16065). * vfs_ceph_snapshots: smbd panics on snapshot access for a share mounted at the CephFS root ("/"); (bso#16176). * race condition in pthreadpool when forking; (bso#16191). * witness test flappy needs to be fixed; (bso#16077). * temporary read of unrelated or non-existing memory in s3 dfs server; (bso#16093). * source4/dsdb/samdb/cracknames.c doesn't use ldb_binary_encode_string() consistently; (bso#16094). * dsgetdcname() may not detect an active directory domain if the netbios domain name is given and nmbd nor the nbt service is available; (bso#16153). * ndr_{push,pull,print}_{timeval,timespec} encode/decode the value twice; (bso#16199). * vfs_ceph_new: smbd crashes when mixing proxy and non-proxy CephFS shares; (bso#16186). * CTDB doesn't send tickle ACKs when taking over a released IP; (bso#15994). * CTDB can run nested elections, in rare circumstances; (bso#16152). - Update update-samba-security-profile for selinux Create and label /run/samba/nmbd and /run/samba/winbindd as this doesn't work properly in DC configurations (bsc#1268532) ==== sdbootutil ==== Version update (1+git20260825.c7a5a97 -> 1+git20260909.7cfa1f0) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20260909.7cfa1f0: * Drop PCR warning when is not part of the policy - Update to version 1+git20260908.c641fc2: * Update the shim when required * Warn when recovery PIN is different from recovery key * Improves extra boot entries support * Better report when the default snapshot diverges * Explain how to do re-enrolling if recovery PIN fails * Explain why update-prediction fails and how to solve it * Hide comparison output * Add bootctl default entry in the prediction - Update to version 1+git20260903.f91f636: * Include FIDO2 unlocked devices for ordering (bsc#1234010) * Test in parallel for speed up * Add --repair parameter to cleanup * Fix shellcheck complain * Report entries with missing files * Avoid duplicate entries in non-snapper systems * Add initial tests for sdbootutil * Report the error if bootctl clean fails - Update to version 1+git20260901.41540d5: * No warn if a component is not in the event log * Add status command * Select the new sdbootutil if available * Skip blank lines in measure-pcr-generator.sh * Do not change crypttab for unrelated entries * Report the bad PCR when update-prediction fail * Do not write the recovery PIN in the journal * Improves non snapshot system support * Update help message for --measure-pcr * Report when PCR 7 is dropped because shim update * Add --strict parameter for --pcr policy * Report dropped PCRs via a warn * Adjust the limits for PolicyOR issues * Avoid update predictions if the service is up * Keep the exit status of sdbootutil call - Update to version 1+git20260827.786f9a8: * Do not accept empty passwords * jeos-firstboot-enroll: report errors also in the journal * Restore old crypttab via the exit trap * Update CLAUDE data * Detect half created openssl keys * check_enrolled report when something was written in the LUKS2 header * Improve a bit the disk-encryption-tool keyslot detection * Avoid leak of env var secrets * Wipe the d-e-t key in the enroll service and jeos module * Remove the correct keyslot left by d-e-t * Differentiate tpm2 and tpm2+pin for unattended unlock * Use is_same_device in detect_tracked_device and drop greps * Refactor check to avoid shellcheck complain * Parse the entry file in a sigle place * Validate the entry with the new kernel name * Refactor enrollment interface and deprecate the old one * New kernels will have different hash * Warn If no crypttab entry found * Extend is_same_device * jeos-firstboot-enroll: validate the passwords * sdbootutil-enroll: report when no encryption method is provided * Write recovery pin after enrollment in jeos module * Write recovery pin after enrollment * Improve error detection in sdbootutil-enroll * Increase keyctl timeout * Merge require_unlock and set_unlock_method * Be sure that the terminal check works with snapper * Renerate initrd when new measure-pcr keys are created * Separate ask-* parameters * Fix reading credential and keyctl password * Get the device password for each enrolling mechanism * Drop elements from crypttab if the enrollment fails * Validate the enrollment for each method * Add warning when enrolling FIDO2 token ==== sddm-kcm6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Add missing Qt::Qml link * Update version for new release 6.7.5 ==== sdl2-compat ==== Version update (2.32.70 -> 2.32.72) - Update to release 2.32.72 * Fixed a crash during the menu transition in Super Mario War. * Fixed menu rendering in The Ur-Quan Masters. * Fixed loading screen flickering in Payday 2. * Fixed the pointer position in Augustus when screen scaling is enabled. * Fixed an out of bounds exception in the OBS plugin "input-overlay" when using the new Steam Controller. ==== selinux-policy ==== Version update (20260826 -> 20260910) Subpackages: selinux-policy-targeted - Update to version 20260910: * Allow polkit_auth_t dac_read_search/dac_override (bsc#1255503) * Allow pam_ssh_agent configure custom key location (bsc#1255503) - Update to version 20260908: * fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038) * Fix for (open)SUSE (bsc#1270243) * Fix for (open)SUSE (bsc#1277439) ==== sg3_utils ==== Version update (1.48+35.c49e7c08 -> 1.48+36.936c7ae) Subpackages: libsgutils2-1_48-2 - Update to version 1.48+36.936c7ae: * sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) ==== signon-kwallet-extension ==== Version update (26.08.0 -> 26.08.1) - Update to 26.08.1 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.1/ - No code change since 26.08.0 ==== spectacle ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 * Fix annotation options submenu overflowing off top of screen * Fix crash when window is destroyed during window-under-pointer detection * Update version for new release 6.7.5 ==== steam-devices ==== Version update (20251018+git.4d7e6c1 -> 20260625+git.22ec85e) - Update to version 20260625+git.22ec85e: * Fix Valve hidraw devices with no associated input node * steam-input.rules: Only enable wakeup if the attribute exists * Add other Switch 2 controllers over USB * Limit Valve bluetooth devices to VID-only, expose evdevs too * Update 60-steam-input.rules * allow wakeup from Valve devices - Update udev-joystick-blacklist to 20250414 - Changed to noarch ==== sudo ==== - Drop make -B workaround for parallel build race condition. The underlying issue (sudo Bug #842, libtool .o/.lo race) was fixed upstream in sudo 1.8.24 (July 2018). The -B flag was added in SR#622342 with the note that it could be reverted after the upstream fix landed. Also drop the sle_version < 150000 build conditional that was only needed for the non-B code path. - Add --with-devel to build the full upstream test suite including the testsudoers regression binary. Pre-generated parser files are removed before make to prevent a parallel build race where yacc overwrites gram.h while other sources are compiling against it. Add bison and flex as BuildRequires for the regeneration. - Add %check section to run the upstream test suite during build. Fedora, Debian and Arch Linux all run make check. ==== suse-module-tools ==== Version update (16.1.6 -> 16.1.7) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.7: * If no initrd is found rebuild it (gh#openSUSE/suse-module-tools#133) ==== systemsettings6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Update version for new release 6.7.5 * Fix loadModule not resetting subCategoryModel parent for modules w/o a submenu (kde#524340,kde#514006) * Update version for new release 6.7.5 ==== wireplumber ==== Version update (0.5.15 -> 0.5.17) Subpackages: libwireplumber-0_5-0 - Update to version 0.5.17: * Highlights: - This release fixes a significant regression introduced in version 0.5.16. Users are strongly encouraged to upgrade to this release and avoid using 0.5.16. * Fixes: - Fixed factory-created device, node and link objects to stop sharing ownership with their registry global, fixing a regression from the WpClientContext introduced in 0.5.16 that broke proper object destruction in the monitor scripts. - Improved default-nodes to also rank on the object.serial of a node's device and on the node's own object.serial, so that route priorities are only compared between nodes of the same card, and the election no longer changes for no apparent reason when all other keys are equal. - Fixed m-lua-scripting to include the offending Lua type name in POD build errors - Update to version 0.5.16: * Additions & Enhancements: - Added WpClientContext, a second PipeWire connection running on its own thread that hosts WirePlumber's in-process media objects (loopback and filter-chain modules, LocalNode(), SpaDevice()), so that slow Lua event hooks on the main thread no longer stall their control path; the export core is retired in favor of this new client context - Added new WpDynamicRules class for matching rules with conditions, and updated filter-graph.lua to use it, allowing filter-graphs to be loaded and unloaded dynamically depending on whether other objects exist or not - Added wp_impl_module_unload() and LocalModule:unload(), giving scripts control to unload implemented modules at any time - Added a volume-set action to module-mpris to allow adjusting the volume of a remote MPRIS2 player from Lua - Added --yes flag to wpctl reset to skip the confirmation prompt - Added device.form-factor ALSA node property for use in ALSA rules, and made HDMI node descriptions include the name of the connected display when available - Refactored the Bluetooth monitor to use event hooks for handling devices and nodes, matching the design already used by the v4l2 and libcamera monitors - Overhauled the documentation: filled in every stub and missing Lua API and C API page, added a getting started guide, new wireplumber(1) and wpexec(1) man pages, and removed stale pages describing features renamed or removed in the 0.4 to 0.5 transition * Fixes: - Fixed monitors to always activate all device and node features, and made monitors wait for successful device activation before storing the devices and nodes as a managed objects - Fixed find-preferred-profile to skip a configured preferred profile that is not available, instead of leaving no profile selected - Fixed permission-manager to not include destroyed globals when rebuilding the permissions array on objects-changed, fixing some pipewire warnings in the log - Fixed a memory leak in WpSpaDevice by only collecting params from our own requests - Fixed filter-graph to correctly apply graphs defined for the same node across multiple configuration files - Fixed several nil-related crashes and correctness issues in Lua scripts - Improved apply-access to directly attach an already-active permission manager to the client instead of wastefully re-running activation on it - Improved state-stream change detection to avoid spurious state writes from volume rounding and from unset or empty properties - Fixed default-nodes to ignore smart filters when selecting the best default node - Removed the node.filter.forward-format setting and its script, which only worked with 0.4 and never really worked with 0.5 ==== xdg-desktop-portal-kde6 ==== Version update (6.7.4 -> 6.7.5) - Update to 6.7.5: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.5 - Changes since 6.7.4: * Dont try to delete uninitialized DataControlManager * screencasting: Do not leak streams when creation fails * session: release all sessions when the portal frontend disappears (kde#523515) * Update version for new release 6.7.5 ==== zvbi ==== Version update (0.2.44 -> 0.2.45) - update to 0.2.45: * Update Swedish translations. * Update Cyrillic characters for Bulgarian/Russian/Ukranian. * Fix missing subtitles, revert C4_ERASE_PAGE patch from libzvbi 0.2.42. * Apply security updates. ==== zypper ==== Version update (1.14.98 -> 1.14.101) Subpackages: zypper-needs-restarting - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - version 1.14.101 - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - version 1.14.100 - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. - BuildRequires: libzypp-devel >= 17.38.0. Code uses some of the new libzypp log and string tools. - version 1.14.99