Packages changed: aws-lc (1.56.0 -> 1.57.1) dracut (059+suse.746.g8a13fbd8 -> 059+suse.749.g280c842e) flatpak grub2 gsettings-desktop-schemas iio-sensor-proxy (3.7 -> 3.8) iproute2 (6.15 -> 6.16) kernel-source (6.15.8 -> 6.16.0) librest (0.9.1 -> 0.10.2) libzypp (17.37.16 -> 17.37.17) linux-glibc-devel (6.15 -> 6.16) ncurses (6.5.20250726 -> 6.5.20250809) openSUSE-release (20250811 -> 20250812) openvpn patterns-media python-Automat python-argcomplete python-argparse-manpage salt unbound (1.23.0 -> 1.23.1) yast2-samba-client (5.0.2 -> 5.0.3) yast2-trans (84.87.20250730.0e8917982d -> 84.87.20250810.a14658bac6) === Details === ==== aws-lc ==== Version update (1.56.0 -> 1.57.1) - update to version 1.57.1: * Resolve issue with conflicting pkg-config variables - update to version 1.57.0: * Preparation for Adopting SONAME and ABI Versioning * Offer P521 for signature_algorithms in client Hello * ML-KEM: Import AArch64 backend from mlkem-native * Add back X509_STORE_get_verify_cb and X509_STORE_set_lookup_crls_cb * Explicitly test that input length is as expected for ed25519ph * Fix Libwebsocket Build * Return NULL when a NULL or empty string is passed to NETSCAPE_SPKI_b64_decode * Reimplement SSL_clear_num_renegotiations * ABI monitoring GitHub workflow improvements * Migrate Openssl-tool parameter parsing * Add HMAC SHA3 benchmarks * Re-import s2n-bignum after merge of ML-KEM/Keccak functionality * Integrate formally verified AArch64 Keccak-x1 assembly * Add a couple more no-ops for legacy builds - remove soname.patch, as upstream formally introduced a soname - adjust the lib names - add the crypto lib as a requires to the devel package ==== dracut ==== Version update (059+suse.746.g8a13fbd8 -> 059+suse.749.g280c842e) - Update to version 059+suse.749.g280c842e: * fix(dracut-util): crash if CMDLINE ends with quotation mark (bsc#1247819) ==== flatpak ==== Subpackages: flatpak-remote-flathub flatpak-selinux libflatpak0 system-user-flatpak - Add cd80e843435df5ce70d9a2b6710098135ceb9085.patch: session-helper: Avoid a memory leak. - Switch to source service for tarball. ==== grub2 ==== Subpackages: grub2-common grub2-i386-pc grub2-snapper-plugin grub2-systemd-sleep-plugin grub2-x86_64-efi grub2-x86_64-efi-bls - Fix timeout when loading initrd via http after PPC CAS reboot (bsc#1245953) * 0001-tcp-Fix-TCP-port-number-reused-on-reboot.patch ==== gsettings-desktop-schemas ==== Subpackages: gsettings-desktop-schemas-lang - Add gsettings-desktop-schemas-meson-1.9.patch: Fix build against meson 1.9.0rc2 (glgo#gsettings-desktop-schemas!113) ==== iio-sensor-proxy ==== Version update (3.7 -> 3.8) - Update to version 3.8: * Require 2.76 or newer for the Gio dependency. * Improve handling of buffer sensors which caused a regression in 3.7 for some corner cases. ==== iproute2 ==== Version update (6.15 -> 6.16) Subpackages: iproute2-bash-completion - Update to release 6.16 https://lore.kernel.org/netdev/20250803143154.2d700ad4@hermes.local/ * bond: fix stack smash in xstats * tc: Parse FQ band weights correctly ==== kernel-source ==== Version update (6.15.8 -> 6.16.0) - crypto: hkdf - skip TVs with unapproved salt lengths in FIPS mode (bsc#1241200 bsc#1246134 bsc#1245608). - commit 1ae9298 - btrfs: fix log tree replay failure due to file with 0 links and extents (bsc#1247726). - commit f83c8f3 - Delete patches.rpmify/libbpf-do-not-compile-with-Werror.patch. Gcc 15 was fixed in sr#1297061 (bsc#1245584). - commit 5e7fcd4 - series.conf: refresh - update upstream references and resort - patches.suse/dt-bindings-pinctrl-Add-RaspberryPi-RP1-gpio-pinctrl-pinmux-bindings.patch - patches.suse/dt-bindings-misc-Add-device-specific-bindings-for-RaspberryPi-RP1.patch - patches.suse/arm64-dts-rp1-Add-support-for-RaspberryPi-s-RP1-device.patch - patches.suse/arm64-dts-bcm2712-Add-external-clock-for-RP1-chipset-on-Rpi5.patch - patches.suse/arm64-dts-broadcom-Add-board-DTS-for-Rpi5-which-includes-RP1-node.patch - patches.suse/arm64-dts-broadcom-Add-overlay-for-RP1-device.patch - patches.suse/MAINTAINERS-add-Raspberry-Pi-RP1-section.patch - patches.suse/dt-bindings-clock-Add-RaspberryPi-RP1-clock-bindings.patch - patches.suse/clk-rp1-Add-support-for-clocks-provided-by-RP1.patch - patches.suse/pinctrl-rp1-Implement-RaspberryPi-RP1-gpio-support.patch - patches.suse/misc-rp1-RaspberryPi-RP1-misc-driver.patch - patches.suse/pinctrl-rp1-Implement-RaspberryPi-RP1-pinmux-pinconf-support.patch - commit 7de39ef - kernel-syms.spec: Drop old rpm release number hack (bsc#1247172). - commit b4fa2d1 - config: update arm config files - DRM_MSM_VALIDATE_XML=n (arm64 and armv7hl) - commit 254d580 - Update config files: CONFIG_IIO_SYSFS_TRIGGER=m for x86 and arm (bsc#1245167) - commit 4f3037c - spi: cs42l43: Property entry should be a null-terminated array (bsc#1246979). - commit 98dd62a - config: arm64: default: Added RP1 related CONFIG options RaspberryPi5 relies on RP1 southbridge to work. Enable new options to make it work (jsc#PED-7144): - CONFIG_MISC_RP1 - CONFIG_PINCTRL_RP1 - CONFIG_PCI_DYNAMIC_OF_NODES - CONFIG_COMMON_CLK_RP1 - commit c1174ff - clk: rp1: Implement remaining clock tree (jsc#PED-7144). - dt-bindings: clock: rp1: Add missing MIPI DSI defines (jsc#PED-7144). - pinctrl: rp1: Implement RaspberryPi RP1 pinmux/pinconf support (jsc#PED-7144). - MAINTAINERS: add Raspberry Pi RP1 section (jsc#PED-7144). - misc: rp1: RaspberryPi RP1 misc driver (jsc#PED-7144). - pinctrl: rp1: Implement RaspberryPi RP1 gpio support (jsc#PED-7144). - clk: rp1: Add support for clocks provided by RP1 (jsc#PED-7144). - dt-bindings: clock: Add RaspberryPi RP1 clock bindings (jsc#PED-7144). - arm64: dts: broadcom: Add overlay for RP1 device (jsc#PED-7144). - arm64: dts: broadcom: Add board DTS for Rpi5 which includes RP1 node (jsc#PED-7144). - arm64: dts: bcm2712: Add external clock for RP1 chipset on Rpi5 (jsc#PED-7144). - arm64: dts: rp1: Add support for RaspberryPi's RP1 device (jsc#PED-7144). - dt-bindings: misc: Add device specific bindings for RaspberryPi RP1 (jsc#PED-7144). - dt-bindings: pinctrl: Add RaspberryPi RP1 gpio/pinctrl/pinmux bindings (jsc#PED-7144). - commit 2e6c9cf - Update to 6.16 final - refresh configs - commit 15477ca - update to 6.16 final - refresh configs (headers only) - commit 05371c8 ==== librest ==== Version update (0.9.1 -> 0.10.2) Subpackages: librest-1_0-0 typelib-1_0-Rest-1_0 - Update to version 0.10.2: + Rename Meson project to librest - Changes from version 0.10.1: + Allow to use the CI to publish the release + Use G_DEFINE_QUARK when possible - Changes from version 0.10.0: + Handle some potential problems in parsing oauth2 access tokens + Allow to use rest and rest-extras from a single header + Fix the declaration of the RestOAuth2Error quark function + Name the RestOAuth2Error enum + Fixes several annotation issues - Drop patches merged upstream: + 0001-rest_proxy_call_sync-bail-out-if-no-payload.patch + 0002-Handle-some-potential-problems-in-parsing-oauth2-acc.patch - Update URL and Source following upstream name changes. ==== libzypp ==== Version update (17.37.16 -> 17.37.17) - Make ld.so ignore the subarch packages during install (bsc#1246912) - version 17.37.17 (35) ==== linux-glibc-devel ==== Version update (6.15 -> 6.16) - Update to kernel headers 6.16 - Rewrite preinstall scriptlet in lua ==== ncurses ==== Version update (6.5.20250726 -> 6.5.20250809) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20250809 + add configure check for Win32 named pipes feature, using that to make nc_mingw.h obsolete in favor of nc_win32.h + amend limit used in alloc_pair, by applying an adjustment for default colors only when the maximum number of color pairs is greater than the maximum number of colors (report by "Ingvix"). - Add ncurses patch 20250802 + fixes for reading Unicode characters in MinGW/Windows port (report by Axel Reinhold). ==== openSUSE-release ==== Version update (20250811 -> 20250812) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openvpn ==== - add (bsc#1239783) -- fix build against 6.16 * 0001-dco-linux-avoid-redefining-ovpn-enums.patch - Don't recommend ovpn-dco-kmp if it is in the kernel already (newer and safer version): https://build.opensuse.org/requests/1255536 - add (bsc#1239783) * 0001-dco-better-naming-for-function-parameters.patch * 0001-dco_linux-extend-netlink-error-cb-with-extra-info.patch * 0001-Handle-missing-DCO-peer-by-restarting-the-session.patch * 0001-dco_linux-Introduce-new-uAPIs.patch * 0001-Implement-ovpn-version-detection.patch * 0001-dco_linux-fix-peer-stats-parsing-with-new-ovpn-kerne.patch * 0001-dco_linux-avoid-bogus-text-when-netlink-message-is-n.patch ==== patterns-media ==== Subpackages: patterns-media-rest_cd_core patterns-media-rest_dvd - Do not require kernel-firmware-all, but rather expand the list, which allows to drop some larger, less commonly used candiates like mellanox. ==== python-Automat ==== - Make the libalternatives transition conditional ==== python-argcomplete ==== - Make the libalternatives transition conditional ==== python-argparse-manpage ==== - Make the libalternatives transition conditional ==== salt ==== Subpackages: python311-salt salt-master salt-minion - Revert require M2Crypto >= 0.44.0 for SUSE Family distros - Improve SL Micro 6.2 detection with grains - Fix functional.states.test_user for SLES 16 and Micro systems - Fix the tests failing on AlmaLinux 10 and other clones - Added: * improve-sl-micro-6.2-detection-with-grains.patch * fix-functional.states.test_user-for-sles-16-and-micr.patch * fix-the-tests-failing-on-almalinux-10-and-other-clon.patch ==== unbound ==== Version update (1.23.0 -> 1.23.1) Subpackages: libunbound8 unbound-anchor - simplify python handling. python2 support is dropped and python3 is built by default. Conditionals for the latter are removed. - enable EDNS subnet handling - Update to 1.23.1: (boo#1246625) Bug Fixes: * Fix RebirthDay Attack CVE-2025-5994, reported by Xiang Li from AOSP Lab Nankai University. - our package was not built with EDNS subnet support up to this point and therefor was not affected. - prepare enabling quic support: currently fails on missing quic support in openssl. aws-lc is sadly not a drop in replacement for unbound. - enable TCP Fast Open for the server and client - remove unused --with-ldns option - enable cachedb including hiredis support on Tumbleweed new BuildRequires pkgconfig(libhiredis) ==== yast2-samba-client ==== Version update (5.0.2 -> 5.0.3) - Avoid bsc#1222564 which breaks nsswitch.conf by instead adjusting nsswitch.conf using sed rather than yast Nsswitch module using augeas; (bsc#1222564. - 5.0.3 ==== yast2-trans ==== Version update (84.87.20250730.0e8917982d -> 84.87.20250810.a14658bac6) Subpackages: yast2-trans-af yast2-trans-ar yast2-trans-bg yast2-trans-bn yast2-trans-bs yast2-trans-ca yast2-trans-cs yast2-trans-cy yast2-trans-da yast2-trans-de yast2-trans-el yast2-trans-en_GB yast2-trans-es yast2-trans-et yast2-trans-fa yast2-trans-fi yast2-trans-fr yast2-trans-gl yast2-trans-gu yast2-trans-hi yast2-trans-hr yast2-trans-hu yast2-trans-id yast2-trans-it yast2-trans-ja yast2-trans-jv yast2-trans-ka yast2-trans-km yast2-trans-ko yast2-trans-lo yast2-trans-lt yast2-trans-mk yast2-trans-mr yast2-trans-nb yast2-trans-nl yast2-trans-pa yast2-trans-pl yast2-trans-pt yast2-trans-pt_BR yast2-trans-ro yast2-trans-ru yast2-trans-si yast2-trans-sk yast2-trans-sl yast2-trans-sr yast2-trans-sv yast2-trans-ta yast2-trans-th yast2-trans-tr yast2-trans-uk yast2-trans-vi yast2-trans-wa yast2-trans-xh yast2-trans-zh_CN yast2-trans-zh_TW yast2-trans-zu - Update to version 84.87.20250810.a14658bac6: * Translated using Weblate (Slovak) * Translated using Weblate (Dutch) * Translated using Weblate (Japanese) * Translated using Weblate (Spanish) * Translated using Weblate (Spanish) * Update translation files * New POT for text domain 'storage'. * Translated using Weblate (Spanish)