Packages changed: Mesa (26.1.5 -> 26.1.6) Mesa-drivers (26.1.5 -> 26.1.6) MicroOS-release (20260731 -> 20260802) NetworkManager apparmor (5.0.1 -> 5.0.2) chrony gcc16 (16.1.1+git9423 -> 16.1.1+git9481) glib2 (2.88.2 -> 2.88.3) grub2 hwinfo (25.4 -> 25.5) libapparmor (5.0.1 -> 5.0.2) libcontainers-common (20260429 -> 20260521) libheif (1.23.0 -> 1.23.1) librepo libxmlb (0.3.27 -> 0.3.29) microos-tools (4.0+git26 -> 4.0+git28) nghttp2 (1.69.0 -> 1.70.0) nghttp3 (1.15.0 -> 1.18.0) nvme-cli (3.0~b.3 -> 3.0~b.4) open-lldp (1.1.1+87.f16f944 -> 1.1+110.f16f944) pam (1.7.2+git12 -> 1.7.2+git48) pam-full-src (1.7.2+git12 -> 1.7.2+git48) permissions (1699_20260723 -> 1699_20260728) podman (5.8.3 -> 6.0.2) python-certifi (2026.5.20 -> 2026.7.22) qemu (11.0.2 -> 11.0.3) samba (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) shared-mime-info (2.4 -> 2.5.1) skopeo (1.22.2 -> 1.23.0) tar update-bootloader (1.27 -> 1.28) vim wpa_supplicant wtmpdb (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) === Details === ==== Mesa ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== Mesa-drivers ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== MicroOS-release ==== Version update (20260731 -> 20260802) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add 2462.patch: nm-initrd-generator: set parent for NBFT vlan connection (bsc#1259025, glfd#NetworkManager/NetworkManager!2462). - Add NetworkManager-initrd-generator-ip-hcn.patch: handle "ip=hcn" option in nm-initrd-generator, it generates an empty connection (PED-14534). ==== apparmor ==== Version update (5.0.1 -> 5.0.2) - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== chrony ==== Subpackages: chrony-pool-openSUSE - Potential incompatibility! Extend UsrEtc (/usr/etc) support to the main configuration: * Ship the vendor chrony.conf and the chrony.d pool defaults under /usr/etc instead of /etc. * chronyd.service now uses /etc/chrony.conf when it exists and falls back to /usr/etc/chrony.conf otherwise (chrony-usretc-service.patch) * Use the confdir directive for chrony.d so that files in /etc/chrony.d override same-named vendor files in /usr/etc/chrony.d * Preserve admin-modified /etc/chrony.conf and /etc/chrony.d/pool.conf across the upgrade via the standard .rpmsave migration scriptlets. * chrony.keys stays in /etc. * To add the new chrony.d overlay/fallback mechanism to existing configurations the "include" line at the end of /etc/chrony.conf needs to be replaced by the "confdir" line from the new /usr/etc/chrony.conf file. ==== gcc16 ==== Version update (16.1.1+git9423 -> 16.1.1+git9481) Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Update to gcc-16.1.1+git9481, GCC 16.2 RC1 ==== glib2 ==== Version update (2.88.2 -> 2.88.3) Subpackages: glib2-tools libgio-2_0-0 libgirepository-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0 typelib-1_0-GLib-2_0 typelib-1_0-GLibUnix-2_0 typelib-1_0-GModule-2_0 typelib-1_0-GObject-2_0 typelib-1_0-Gio-2_0 - Update to version 2.88.3 (CVE-2026-15588): + Fix potential miscompilation with GCC 17 with `G_GNUC_CONST` on `get_type()` functions + Bugs fixed: - G_GNUC_CONST vs get_type comes home to roost - (CVE-2026-15588) Security report: GDBusServer pre-authentication DoS via unbounded SASL line buffering - Drop G_GNUC_CONST for *_get_type - gdbusauth: Limit length of lines read from client - gdbusauth: Unmark a new string as translatable - Several Meson/gcc fixes ==== grub2 ==== Subpackages: grub2-common grub2-i386-efi grub2-i386-efi-bls grub2-i386-pc grub2-snapper-plugin grub2-x86_64-efi grub2-x86_64-efi-bls - Fix KVM and Xen VM images taking too long to boot (bsc#1266384) * 0001-cacheinfo-fix-hit-ratio-calculation-and-statistics-o.patch * 0002-disk-fix-cache-lock-and-hit-counter-for-invalidated-.patch * 0003-disk-reduce-cache-slot-thrashing.patch - Replace patch with upstreamed version * 0001-test-Fix-f-test-on-files-over-network.patch * 0002-http-Return-HTTP-status-code-in-http_establish.patch * 0003-docs-Clarify-test-for-files-on-TFTP-and-HTTP.patch * 0004-tftp-Fix-hang-when-file-is-a-directory.patch ==== hwinfo ==== Version update (25.4 -> 25.5) Subpackages: libhd25 - merge gh#openSUSE/hwinfo#187 - small adjustments to bash-completion, update spec file - 25.5 - merge gh#openSUSE/hwinfo#183 - add bash completion script for hwinfo - merge gh#openSUSE/hwinfo#186 - serial driver file name changed in /proc in current kernel, adjusting code (bsc#1271724) ==== libapparmor ==== Version update (5.0.1 -> 5.0.2) - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== libcontainers-common ==== Version update (20260429 -> 20260521) Subpackages: libcontainers-default-policy registries-conf-default - New release 20260521 * bump bundled c/common to 0.68.0: + containers.conf: - previously /usr/share/containers/containers.conf, /etc/containers/containers.conf, ~/.config/containers/containers.conf were read all in order; now only the file with the highest precedence is read - ~/.config/containers/containers.conf will be read before a drop-in file from /etc/containers/containers.conf.d/ + storage.conf: - support for drop-in configuration files - storage.rootless.conf.d/ storage.rootful.conf.d/ allow configuring options system wide for all users - rootless_storage_path field is deprecated, instead set graphroot to the same value in a drop-in file under storage.rootless.conf.d/ - graphroot, runroot options in the default storage.conf are now read by all users; if a specific root only graphroot was set, then this option must be moved to a new drop-in under storage.rootful.conf.d/ + registries.conf: - drop support for v1 syntax - support reading the default file under /usr/share/containers - correctly use XDG_CONFIG_HOME for the per user file lookup + registries.d: - support reading files under /usr/share/containers/registries.d/ + policy.json: - add /usr/share/containers/policy.json search location - Move all vendor config files from /etc/containers/ to /usr/share/containers * user-modified files in /etc/containers continue to work as overrides * preserve ownership of /etc/containers * ghost /etc/containers/{storage,containers}.conf - Add Conflicts: podman < 6, buildah < 1.44, skopeo < 1.23 ==== libheif ==== Version update (1.23.0 -> 1.23.1) - Update to version 1.23.1: + FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding + SVT-AV1 encoder: new tune=iq and ms-ssim tune parameters + C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes + Sequence decoder now scales the alpha auxiliary track to the main image size + Fixed pixi box writing for multi-channel images + Corrected the placement of the TAI clock_type field into the top 2 bits + Empty/unset plugin directory is no longer scanned + CVE-2026-62289 (GHSA-jc8f-p23p-5hjg) Integer underflow in Fraction constructor via double clap transform application + CVE-2026-62291 (GHSA-xpw3-9rhw-482x) Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions + CVE-2026-62292 (GHSA-73p7-m7gg-w2jv) Out-of-bounds read in uncompressed unci tile range slicing + CVE-2026-62377 (GHSA-9ww4-9v47-m7pj) Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file + (GHSA-46rp-pcq2-rpmr) Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth ≤ 8 ==== librepo ==== - Pull some fixes from upstream master to fix GPG check of repo metadata * 0001-gpgme-Improve-handling-of-expired-GPG-signatures-wit.patch * 0002-PGP-define-shared-error-message-constants-for-both.patch * 0003-gpgme-report-Signing-key-not-found-when-signing-key.patch * 0004-test-verify-missing-key-error-message-consistency.patch ==== libxmlb ==== Version update (0.3.27 -> 0.3.29) - Update to version 0.3.29: + Bugfixes: - Avoid stale query indexes when reloading the silo - Clear the query cache when reloading the silo - Correctly mark the silo as invalid when re-loading malformed data - Fix building the silo when shared-mime-info is installed - Changes from version 0.3.28: + New Features: - Automatically add system locales when using native-langs - Lower the Meson and GLib deps for RHEL-8 + Bugfixes: - Lazy clear opcode tokens for a ~2% speedup - Speed up negative queries by 11% by defer creating the results objects - Speed up predicates with no bindings by 9% - Speed up the no-results query by 2.5% by using a constant error ==== microos-tools ==== Version update (4.0+git26 -> 4.0+git28) Subpackages: selinux-autorelabel zypp-excludedocs zypp-no-multiversion zypp-no-recommends - Update to version 4.0+git28: * Use zypp.conf.d dropin for ZYPP_SINGLE_RPMTRANS=1 - Update to version 4.0+git27: * Remove obsolete stuff (locale-check, salt-tmpdir) ==== nghttp2 ==== Version update (1.69.0 -> 1.70.0) - Require the versions configure actually checks for: libnghttp3 >= 1.17.0 and libngtcp2 >= 1.23.0. Without them OBS starts the build and lets it fail in configure, instead of holding the package unresolvable until nghttp3 is in place - Update to 1.70.0: * nghttpx: add separate frontend and backend stream timeouts, plus an HTTP/2 stream write timeout * nghttpx: drop HTTP/2 and HTTP/3 connections whose frontend write rate is too low, so a peer can no longer hold a connection open by reading slowly * Rework HTTP header validation, and add the value check that was missing for the priority header field * Fix an out-of-bounds read in the base64 decoder * get_socket_error() now reports the errno of getsockopt() when that call itself fails, instead of a stale value * Update the bundled llhttp to 9.4.2 and mruby to 4.0.0, and refresh the bundled ngtcp2, neverbleed and sfparse * Large internal rework: nghttpx now carries its error paths in std::expected rather than out-parameters - Drop 0001-nghttpx-Tighten-up-CONNECT-and-HTTP-Upgrade-handling.patch, the fix is part of this release (CVE-2026-58055, bsc#1269489) - Mark the doc subpackage noarch, it ships documentation only and rpmlint rightly flagged it with no-binary - Run spec-cleaner: drop the Group tags and sort the build dependencies ==== nghttp3 ==== Version update (1.15.0 -> 1.18.0) - Update to 1.18.0: * Added nghttp3_conn_close_stream2 and the nghttp3_stream_close2 callback * Validate the header length against the estimated uncompressed length * Fix a build error with gcc-16 - Changes from 1.17.0: * Added nghttp3_conn_stream_flushed and public API to encode and decode variable-length integers * Fix header name validation - Changes from 1.16.0: * Added nghttp3_conn_get_stream_user_data * Call the nghttp3_stream_close callback for all streams * Fix a memory leak on the failure path * Ignore content-length for the extended CONNECT * Reject HTTP status codes with a leading zero * Optimize huffman decode length estimation - The library soname is unchanged at 9 ==== nvme-cli ==== Version update (3.0~b.3 -> 3.0~b.4) Subpackages: libnvme3-1 - Update to version 3.0~b.4: * Release v3.0-b.4 * doc: Regenerate all docs for v3.0-b.4 * libnvme/config: add epcsd supporting * libnvme/config: add support for persistent * libnvme/fabrics: remove pdc-enabled build time config * plugins/config: add create command * libnvme/config-emit: ensure config dir exists * shared/fs-util: add missing windows implementation * shared/fs-util: add sh_mkdir_from_fname and shr_dirname * shared: split platform parts into separate files * shared: update prefix for compiler attributes * doc: remove nvme-config.txt * plugins: invoke the arg parser for the remaining commands * discoverd: rename discoverd.conf to nvme-discoverd.conf * ocp: add NULL checks after memory allocation * ocp: fix __le64 usage in C9 log reading * ocp: fix use after free and memory leak related to C9 log page reads * ocp: use libnvme_alloc and libnvme_free for log buffer allocations * ocp: read telemetry log with maximum transfer size * innogrit: fix resource leak in innogrit_vsc_getcdump() * scaleflux: clamp code_type before array access in nvme_parse_evtlog() * wdc: fix out-of-bounds access in wdc_show_cloud_smart_log_normal() * micron: clean up and fix micron telemetry log reading * nbft: ensure transport buffer is null terminated in read_ssns() and read_hfi() * nvme-models: fix stream EOF state errors in __nvme_product_name and pull_class_info * ibm: fix missing break in show_ibm_smart_log() case 0x00f5 * nvme-rpmb: fix out-of-bounds allocation in read_rpmb_key() * tests: align config-convert expectation with preserved legacy json * plugins/ymtc: fix additional smart info display for YMTC PE511 * utils: check asprintf return value * util: fix memory leak in read_binary_file() * util: fix memory leak in read_binary_file() * utils: add crash handlers for option capture * nvme: avoid stale pointer in get_log_offset() * fabrics: avoid double free in build_options() * fabrics: avoid reduntant libnvmf_context_set_crypto() call * fabrics: avoid mem leak in libnvmf_context_set_crypto() * fabrics: accept fabrics arguments for disconnect * nvme: add arg parser to gen/show hostnqn * plugins/keys: report line number 1 based * plugins/keys: show error when missing trailing colon * plugins/keys: update help text for gen-tls * fabrics: add --kxchap-* arguments * nvme: add compat tls/chap key management commands * libnvme: rename DH-HMAC- prefix with KX-HMAC- * tests: add nvme keys tests cases * nvme: split keyring insert out of keys check-tls/check-dhchap * nvme: move key commands into new keys plugin * shared: add more test coverage * libnvme: return libnvmf_tid_parse{,_strict}() as int, not a pointer * libnvme/nbft: tests: Regenerate reference NBFT table dumps * nvme: preserve legacy json config for rollbacks * libnvme: reuse heap reader for NBFT security lists * libnvme: fix comments that still describe removed JSON config support * libnvme/nbft: Add sample synthetic NBFT tables * shared: move init unit test * shared: move compiler-attributes to common code * libnvme: return libnvmf_tid_from_fields() as int, not a pointer * nvme: fix to check sanitize status error * nbft-plugin: fix resource leak in show_nbft() * discoverd: parse discoverd.conf with the shared ini parser * libnvme: parse NBFT Security Profile descriptors * doc: add nvme-discoverd(8) and the design README * meson: make nvmf-autoconnect independently toggleable * discoverd: add the nvme-discoverd daemon * libnvme: harden NBFT interface references * libnvme: validate NBFT descriptor ranges * libnvme: drop test/ioctl's own freep(), use shared/cleanup.h * shared: add README * shared: add test coverage for array-util, base64, crc32 * shared: rename everything to the shr_ namespace * shared: add PTRARRAY_DEFINE() for type-checked ptrarray wrappers * shared: dedup cleanup.h boilerplate * shared: move base64, crc32, and misc utility functions * shared: fix mkdir_p() silently truncating long paths * shared: relicense to LGPL-2.1-or-later * sfx-nvme: fix resource leak in sfx_status() * nbft: fix resource leak of ssns->hfis in read_ssns() * sndk plugin: Fix vs-smart-add-log for NVMe OF * nvme: add utils dump-command-metadata command * memblaze: fix stack overflow in perf-stats-print-x * nvme: add global options config file * shared: move ini parser to common code * nvme: move args into separate header * nvme: do not include libnvme-mi on global level * nvme: change verbosity type * util/json: use stdint types * shared: add a small static utility library * wdc: free dssd_specific_ver when smart_log_ver < 3 * virtium: remove erroneous (float) cast in vt_save_smart_to_vtview_log() * nvme-print: print address instead of traddr * nvme: replace argconfig_parse with parse_args * nvme-cli: resolve hostnqn/hostid on ctx creation * libnvme/tree: free hnqn/hid in error path * sfx-nvme: fix dead assignment in sfx_dump_evtlog() * exclusion: fix uninitialized argument in libnvmf_exclusion_read() * nvme: Fix get-log xfer-len parameter handling * libnvme: generate the trivial libnvme_global_ctx bool accessors ... changelog too long, skipping 105 lines ... unpackaged files. ==== open-lldp ==== Version update (1.1.1+87.f16f944 -> 1.1+110.f16f944) Subpackages: liblldp_clif1 - Changed _services and spec file to recreate the tarball file based on version 1.1 instead of version 1.1.1, since the software that compares versions was having issues with using 1.1.1. (bsc#1268742) ==== pam ==== Version update (1.7.2+git12 -> 1.7.2+git48) - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== pam-full-src ==== Version update (1.7.2+git12 -> 1.7.2+git48) - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== permissions ==== Version update (1699_20260723 -> 1699_20260728) Subpackages: permctl permissions-config - Update to version 1699_20260728: * profiles: whitelist selinux-sandbox seunshare (bsc#1268256) * profiles: drop netcfg /etc/exports ==== podman ==== Version update (5.8.3 -> 6.0.2) - Update to version 6.0.2: * Bump to v6.0.2 * Release notes for v6.0.2 * podman-remote: do not check for cgroupv2 * [v6.0] Bump Buildah to v1.44.1 * docs: clarify network create isolate option * test system: increase nproc ulimit to avoid flake * fix broken kube play --wait behavior * test/system: fix broken port bound check logic * test/system: fix "podman rm running container, w/o and w/ force" flake * Fix Windows installer machine scope PATH update * Always unprovision if the WSL machine init fail * Bump Podman to v6.0.2-dev * Bump to v6.0.1 * Release notes for v6.0.1 * Mark pasta forwarder tests as non-parallel * Enable pasta forwarder tests after passt SELinux fix * vendor: bump go.podman.io/common to v0.68.1 and fix pasta API break * macos: Use latest vfkit release in installer * Bump bundled krunkit from 1.3.1 to 1.3.2 * Fix lookup of HyperV VMs with matching name * docs: update network create --route description * docs: fix network create no_default_route doc * Only suggest --replace for commands that have the flag * machine/wsl: fix config mount logic * Bump bundled krunkit from 1.2.1 to 1.3.1 * Restore caching of the default machine image * label machine issues automatically * fix podman machine os upgrade distro check * podman log-level debug must produce the same oci runtime errors * Fix release email * Fix lookup of WSL VMs with matching name * Fix WSL check: assume not installed when --status returns an error * Packit: Add cautionary note to ephemeral copr job * Windows installer tests: download v5.8.3 of the setup bundle * Bump Podman to v6.0.1-dev - Update to version 6.0.0: * Security * This release addresses CVE-2026-57231 (bsc#1269471), where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names (GHSA*4hq8-gpf5-8p68). * Breaking Changes * Due to breaking changes in this release, Podman v6.0.0 must be used with Buildah v1.44.0, Skopeo v1.23, Netavark and Aardvark v2.0.0, and configuration files from the container*libs repository's common/v0.68.0 release. * Support for BoltDB databases has been dropped. Starting Podman 6 when the BoltDB database is in use will have Podman attempt an automatic migration from BoltDB to SQLite. * Support for running on Intel Macs has been removed. * Support for running on Windows 10 has been removed. * Support for running on cgroups v1 systems has been removed. Please update your system to use cgroups v2. * Support for running on iptables has been removed. Please use nftables instead. * Support for CNI networking has been removed. Please use Netavark instead. * Support for the slirp4netns rootless network stack has been removed. Please use Pasta instead. As part of this, the *-network-cmd-path global option, only used with slirp4netns, has been removed. * Podman's configuration file parsing logic has seen a major rewrite. Please see this document for exact details. * Podman's import path has changed from github.com/containers/podman/v5 to go.podman.io/podman/v6 as part of our move into a CNCF*owned GitHub organization. * Network isolation now defaults to enabled, improving Docker compatibility and security. A special workaround for the Docker*compatible API related to isolation being disabled has been removed (#27349). * The way the podman quadlet suite of commands functions has been changed. Previously, Quadlets and their associated files were tracked using a .app file, ensuring that removing a Quadlet also removed all associated non*Quadlet files. Now, Quadlets and associated files are placed in subdirectories, which should reduce bugs and make manual management of Quadlets added by podman quadlet install much easier. * VMs made by podman machine on Linux now mount volumes from the host using systemd. Volume mounts on existing podman machine VMs on Linux have been broken by this change, and the VM will need to be recreated. * The podman volume prune command now matches Docker's behavior by only pruning unused anonymous volumes. Please use the newly*added --all option for the previous behavior (pruning all volumes). * The podman volume list command now combines multiple filters using logical AND instead of logical OR (meaning all filters must match for a container to be included in output) (#26786). * The label!= filter used in many commands now combines the output of multiple instances of the filter with logical AND instead of logical OR. * The --format='{{json .Labels}} option to the podman ps, podman pod ps, and podman volume ls commands now prints its output as comma*separated key=value pairs instead of as a JSON map, improving Docker compatibility (#21847). * The --all-providers option to podman machine list has been removed, as machines from all providers can now be accessed by all commands. * The MemorySwappiness field of podman inspect is now set to nil when not explicitly set by the user (instead of *1), improving Docker compatibility (#23824). * The podman commit command now pauses the container while committing changes, improving security by restricting concurrent modification. The prior behavior can be restored by using podman commit *-pause=false .... * The Go bindings for the REST API have removed the redundant nameOrID ... changelog too long, skipping 267 lines ... * Updated the common library to v0.68.0 ==== python-certifi ==== Version update (2026.5.20 -> 2026.7.22) - Update to 2026.7.22: - fix: update Requests docs link to canonical URL - Include tests in the source distribution ==== qemu ==== Version update (11.0.2 -> 11.0.3) - (Properly, this time for real) fix bsc#1268245: * [openSUSE][RPM] spec: properly fix bsc#1268245 (this time for real!) - Update to latest stable release (11.0.3) Full backport list here: https://lore.kernel.org/qemu-devel/20260725052155.1228635-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/arm: do not clear halting reason in has_work helper target/arm: teach arm_cpu_has_work about halting reasons hw/audio/intel-hda: restrict all DMA engine paths to memories hw/net/cadence: Return current Cadence GEM queue pointers hw/misc/applesmc: Fix a typo setting MSSD key replay: fix use of uninitialized pointer on error hw/display/qxl: validate monitors_config heads[] in phys2virt net: Correct padding check in qemu_receive_packet() hw/net/xilinx_axienet: Fix PHY register 17 link status reporting hw/usb/hcd-xhci-sysbus: Fix OOB heap access in xhci_sysbus_intr_raise() hw/usb/hcd-xhci: Fix guest-triggerable assert() in xhci_find_stream() usbredir: fix infinite loop and SIGFPE with zero max_packet_size usbredir: fix use-after-free on buffered bulk packet overflow tests/qtest: add xhci-pci unplug finalize regression test hw/usb/hcd-xhci-pci: break host link cycle so device_finalize() runs on unplug hw/usb/xhci: clamp interval exponent to avoid UB shift in xhci_init_epctx() accel/tcg: move jit thread manipulation into do_tb_phys_invalidate hw/display/virtio-gpu: Check pixman_image_create_bits() results hw/display/virtio-gpu: handle migration iov allocation failure hw/display/virtio-gpu: cap submit_3d command buffer allocation ui/vnc: validate SetPixelFormat field ranges ui/vnc: fix out-of-bounds write in lossy refresh dirty marking ui/gtk: Narrow DMA-BUF critical section ui/input-barrier: fix off-by-one in keycode bounds check ui/vnc: validate color shifts in SetPixelFormat ui/vnc: fix OOB write in vnc_refresh_lossy_rect net: only advertise passt in netdev help when CONFIG_PASST hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask() hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure hw/scsi/vmw_pvscsi: add a comment to explain the endianness hw/scsi/vmw_pvscsi: translate data endianness hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation hw/display/qxl: fix TOCTOU in cursor chunk data_size handling hw/misc/ivshmem: clear chardev handlers before freeing peers linux-user/alpha: populate AT_HWCAP from env->amask linux-user/alpha: add coredump support s390x/css: firm up handling of chained TIC CCWs s390x/sclpcpi: check event length field before reading from buffer s390x/sclp: prevent re-reading the sclp header hw/misc/stm32_rcc: Correct offset-to-irq calculation hw/display/sm501: Don't allow guest to set ram size larger than it is hw/display/sm501: Avoid overflow problems in bounds check calculations hw/display/sm501: Catch bad coordinates for RTL operations ... - Fix bsc#1273022: * hw/i386/pc: xen: reinstate the "xenfv" machine alias (bsc#1273022) ==== samba ==== Version update (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) Subpackages: libldb2 samba-ad-dc-libs samba-client samba-client-libs samba-libs - Update to 4.24.5 * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server; (bso#16083);(bsc#1271672). * CVE-2026-58224: CTDB: heap OOB read via unchecked packet length fields;(bso#16085);(bsc#1271673). * CVE-2026-58216: kpasswd service: 6-byte heap OOB read in packet parser;(bso#16087);(bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes;(bso#16115);(bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover;(bso#16147);(bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes; (bso#16148);(bsc#1271677). - Update to 4.24.4 * Use-after-free in handling acls with claims and conditions; (bso#16095). * Compilers may ignore overflow checks - Fix tautological- compare warnings; (bso#16092). * restrict anonymous = 2 breaks RODC functionality; (bso#14638). * warning: assignment discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]; (bso#16006). * Require NTLMv2 session security on Windows makes trusts to Samba unusable; (bso#16067). * winbindd stuck in init_dc_connection_rpc() returning NT_STATUS_TRUSTED_DOMAIN_FAILURE; (bso#16151). * domain\user not split when provided as username in smbc_set_credentials_with_fallback(); (bso#16149). ==== shared-mime-info ==== Version update (2.4 -> 2.5.1) - Update to version 2.5.1: + Updated translations. - Changes from version 2.5: + Add type for Git repository bundles + Add application/vnd.ms-pki.seccat + Add binary magic to PKCS#7 types + Add common file extensions to PKCS and PKIX types + Add PEM identifiers from RFC 7468 + Make application/x-x509-ca-cert a subclass of application/pkix-cert + DOS batch/cmd files: add magic, tests, and *.cmd extension + Add application/x-hwpx + Add Android App Bundles + Fix APNG detection using non-fixed acTL chunk location; add APNG test cases + Add Farbfeld image support and fix its mime + Add type for LRC lyrics + Add text/vnd.plantuml + Add text/n3 + Add text/x-gradle-kts (and remove subclass for Gradle) + Add text/x-sed ("Sed script") + Add application/x-coff + Add application/vnd.ipld.car + Add application/x-brotli and fix brotli magic bytes + Add Playstation graphics (TIM) support + Add text/scriptlet + image/x-flic: fix and improve magic, add alias and generic icon + Add image/x-aseprite (LibreSprite/Aseprite image) and improve magic + Give CSV and TSV files the spreadsheet icon + application/texinfo: use IANA registered type + application/vnd.adobe.flash.movie: add ZWS magic + /matroska: use IANA registered non-x types + application/vnd.bzip3: use IANA registered type + Add PICO-8 (.p8/.p8.rom), TIC-80, Lowres NX, and CHIP-8 source/carts + Add RWL (Leica RW2) and more RAW image mime types; fix MOS mime + Add RVZ & WIA disc image files for GameCube & Wii + AWK family: recognise GNU and New AWK; awk scripts now text/x-awk + Shell scripts now text/*, like file/libmagic + Add MP4 Base Media v[2-5] alongside v1 + Add Slint language (text/slint) with magic and test + Assign video icon to application/vnd.ms-asf + Add ZX Spectrum & clone emulation formats + Add Commodore emulation file support + Add Nero Burning ROM NRG format + Add application/x-lx-executable + Add matches and test cases for .nds/.gba + application/vnd.nintendo.nitro.rom: use IANA registered type + Split audio/x-mod into correct formats; add audio/x-dsp and audio/x-ult test + Add text/x-nsis + Add support for Alpine Linux packages (.apk) + text/x-vala: add executable subclass and shebang magic support + application/x-ruby: add text/x-ruby alias + Add AMF 3D model mime-type + Add mimetypes for Simple File Format Family (SF3) files + Add mimetype for Microsoft Developer Studio files + Add HTTP Archive (HAR) json type + Add application/vnd.cyclonedx+xml and application/vnd.cyclonedx+json + Add text/spdx and application/spdx+json + Add OpenCL C and C++ for OpenCL types + image/vnd.radiance: add image/x-hdr alias; add Radiance HDR image format + Add application/x-pcapng and *.scap glob + Add mimetype for AVCI image + Detect OpenSSH public key and private key files + Add Proxy Auto-Configuration (PAC) + Add application/buildstream+yaml + Add text/x-dockerfile + Update mimetype for Typst source files + Add Portable HalfMap images + Update nushell mime type alias to text/x-nushell + Clean up matches for OLE/CFB based Word files + Add Apple Wallet passes bundle type application/vnd.apple.pkpasses + Add application/typescript; recognize *.cjs as text/javascript + Add comment and keyword magic to C-like source code + Move magic from text/x-csrc and text/x-objcsrc to text/x-objc++src + Add *.LRF glob to MPEG-4 videos + Add PFM, PXR and SCT image formats + Recognize *.sfs, *.sqfs, and *.squashfs as application/vnd.squashfs + Remove the relationship between AppImage and SquashFS + Remove redundant "MZ" magic from application/x-executable + Remove the office document icon from application/x-object + Recognize *.lib as application/x-archive + Rename back legacy OOoXML file formats + text/calendar: add *.ifb and *.icalendar globs and the calendar icon + Add text/x-nix + Add text/x-asm + Add image/x-kiss-cel + Prefer image/vnd.fpx over image/x-fpx and improve its detection + Remove text/htmlh + Add text/x-python2 and separate text/x-cython from ... changelog too long, skipping 48 lines ... - Switch to source service for tarball, and add new sub-module. ==== skopeo ==== Version update (1.22.2 -> 1.23.0) - Update to version 1.23.0: * Bump Skopeo to v1.23.0 * Bump c/common 0.68.0, c/image 5.40.0, c/storage 1.63.0 * Update common, image, and storage deps to 4a820ae * copy: add platform-based filtering via --multi-arch flag * Update module golang.org/x/term to v0.43.0 * Update common, image, and storage deps to abe824d * Update dependency golangci/golangci-lint to v2.12.2 * Update dependency golangci/golangci-lint to v2.12.1 * Update common, image, and storage deps to c03a490 * Update module github.com/Masterminds/semver/v3 to v3.5.0 * Packit: Only create dist-git PRs for rawhide * Cirrus: switch Sequoia matrix from Rawhide back to stable Fedora * Update common, image, and storage deps to b9d5b9a * Remove OWNERS file * Additional cleanup for go module changes * Move skopeo to go.podman.io * Update common, image, and storage deps to 618304d * Update module github.com/containers/ocicrypt to v1.3.0 * Update common, image, and storage deps to 129af75 * Update go.podman.io dependencies * Update module golang.org/x/term to v0.42.0 * Bump google.golang.org/grpc to v1.79.3 - CVE-2026-33186 * chore(deps): update module github.com/go-jose/go-jose/v4 to v4.1.4 [security] * fix(deps): update go.podman.io/storage digest to f0ddf1a * fix(deps): update common, image, and storage deps to 8af7873 * integration: Force amd64 on TestProxyMetadata * fix(deps): update common, image, and storage deps to 94ad023 * Try triggering an ostree image rebuild * chore(deps): update dependency golangci/golangci-lint to v2.11.4 * ci: add riscv64 to local-cross build target * cmd, proxy: use logic from the container-libs/common package * vendor: update go.podman.io/common * fix(deps): update common, image, and storage deps to ddaabae * Use --retry-times 3 for (skopeo sync) tests * Use t.Tempdir() instead of manual os.CreateTemp() in tests * Fix references to a wrong err * fix(deps): update module golang.org/x/term to v0.41.0 * Use fmt.Appendf instead of Sprintf + conversion * Use "any" instead of "interface{}" * Use WaitGroup.Go * Update to Go 1.25 * Update CI image and tests * Replace the boolean for schema1 registry with an enum * chore(deps): update dependency golangci/golangci-lint to v2.11.3 * fix(deps): update common, image, and storage deps to d48bc74 * Link to Podman's LLM policy * fix(deps): update github.com/opencontainers/image-spec digest to a4c6ade * fix(deps): update common, image, and storage deps to 854aaaf * Packit: Re-enable ELN tests * Add a --tls-details option and integration tests * Add an error return value to globalOptions.newSystemContext * Pass a SystemContext to signature.DefaultPolicy * Update container-libs after container-libs#623 * Packit: fix downstream post-modifications action * chore(deps): update dependency golangci/golangci-lint to v2.10.1 * chore(deps): update dependency golangci/golangci-lint to v2.9.0 * fix(deps): update module golang.org/x/term to v0.40.0 * fix(deps): update common, image, and storage deps to 0e2aefd * Update tests for a changed error message * fix(deps): update common, image, and storage deps to b5801a6 * fix(deps): update common, image, and storage deps to b2572af * fix(deps): update module github.com/sirupsen/logrus to v1.9.4 * fix(deps): update common, image, and storage deps to e7626b7 * fix(deps): update module golang.org/x/term to v0.39.0 * chore(deps): update dependency golangci/golangci-lint to v2.8.0 * Document the default of --retry-times * chore: fix function name in comment * skopeo: add `--require-signed` * integration/signing_test: move findFingerprint to utils_test.go * fix(deps): update common, image, and storage deps to b0f86df * Update c/common to match #2765 * fix(deps): update common, image, and storage deps to afd10d8 * chore(deps): update dependency golangci/golangci-lint to v2.7.2 * fix(deps): update module golang.org/x/term to v0.38.0 * Packit: use `post-modifications` hook to update downstream TMT plan * docs: manpage update for `skopeo inspect --manifest-digest` * inspect: --manifest-digest flag * vendor: container-libs commit 01833ef7b7f1d306205be7fa6fb36d0d6a6e3a33 * chore(deps): update dependency golangci/golangci-lint to v2.7.1 * fix(deps): update module github.com/spf13/cobra to v1.10.2 * chore(deps): update dependency golangci/golangci-lint to v2.7.0 * Bump version to 1.22.0-dev * Update common, image, and storage deps to 63be353 * Try triggering an image rebuild * Update common, image, and storage deps to 22d50c5 * Update dependency golangci/golangci-lint to v2.6.2 * vendor: Fetch the latest from container-libs main * golangci-lint: enable gofumpt formatter * format the code with gofumpt * Packit: tmp disable ELN tests * fix(deps): update module golang.org/x/term to v0.37.0 ==== tar ==== - Add tar-assume-dir-size-0.patch * Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes (bsc#1271272) ==== update-bootloader ==== Version update (1.27 -> 1.28) - merge gh#openSUSE/update-bootloader#197 - fix test suite - adjust two tests - updated test results - fix command line parser (bsc#1271602) - add test case - update test result - fix and reenable ksh tests: ksh uses alts now - update ksh test results - 1.28 ==== vim ==== Subpackages: vim-data-common vim-small - Guard suse.vimrc against missing syntax without vim-data ==== wpa_supplicant ==== - Add mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch https://w1.fi/security/2026-4/ ==== wtmpdb ==== Version update (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) Subpackages: libwtmpdb0 - Update to version 0.76.0+git20260730.89c0861: * Release version 0.76.0 * CI: get rid of obsolete actions * Use _cleanup_, adjust formating * rotate: keep open entries after last boot * wtmpdb: use different variable for (const) char * * Update mkdir_p to fix error code for last call * ignore absence of systemd * ignore absense of dbus