Packages changed: SDL3 (3.4.16 -> 3.4.18) bluez elfutils (0.194 -> 0.196) emacs-jinx (2.10 -> 2.11) ffmpeg-8 glibc inn kernel-source (7.2.8 -> 7.2.9) libbacktrace (1.0+git20260601 -> 1.0+git20260903) libstorage-ng (4.5.359 -> 4.5.360) ncurses (6.6.20260919 -> 6.6.20260926) nvidia-open-driver-G07-signed (595.104.02_k7.2.8_1 -> 595.104.02_k7.2.9_1) nvidia-open-driver-G07-signed-cuda (615.71.09_k7.2.8_1 -> 615.71.09_k7.2.9_1) openSUSE-release (20261003 -> 20261007) passt (20260612.a9c61ff -> 20261002.cba3570) python-M2Crypto (0.49.0 -> 0.50.0) python-dbus-python python-idna (3.19 -> 3.20) python-msgpack (1.2.2 -> 1.2.3) python-mysqlclient (2.2.8 -> 2.3.0) python-pycairo (1.29.1 -> 1.29.2) python-tzdata (2026.2 -> 2026.5) samba (4.24.6+git.488.e38f6c96c62 -> 4.25.0+git.473.e78e78fbf4) sdl12_compat (1.2.76 -> 1.2.78) sdl2-compat (2.32.72 -> 2.32.74) selinux-policy (20261002 -> 20261006) subversion upower (1.91.3 -> 1.91.4) vim xapian-core (1.4.27 -> 1.4.32) xdmbgrd yast2-trans (84.87.20260923.cade5cf3bd -> 84.87.20261004.92ae53d41b) zenity === Details === ==== SDL3 ==== Version update (3.4.16 -> 3.4.18) - Update to release 3.4.18 * Fixed a crash at shutdown if X11 IME services restarted during the session * Fixed KMSDRM initialization on some systems including i.MX 6 hardware * Added SDL_GAMEPAD_TYPE_STEAM for Steam Controllers * Added support for the Flydigi Apex 6 controller * Fixed the Keychron Q6 System Control showing up as a gamepad * The pen device type is included with pen events * Correctly report the eraser in pen events on Wayland * Fixed handling time values before the UNIX epoch (January 1, 1970) ==== bluez ==== Subpackages: bluez-auto-enable-devices bluez-cups bluez-obexd bluez-zsh-completion libbluetooth3 - Add a2dp-fix-loading-of-remote-SEP-from-cache.patch Without this, Pipewire forces AVDTP Discover on every reconnect, causing codec negotiation failures on some LE Audio headsets. * Upstream issue: https://github.com/bluez/bluez/issues/2321 * Upstream commit: https://github.com/bluez/bluez/commit/b7d71e5067856b0daf2f1f73b3fc95483236610e ==== elfutils ==== Version update (0.194 -> 0.196) Subpackages: libasm1 libdw1 libelf1 - Update to 0.196: debuginfod: The $DEBUGINFOD_TIMEOUT environment variable is now enforced when establishing a connection to a server. libdw: New functions dwarf_begin_type, dwarf_begin_elf_type and dwarf_get_type plus new enum Dwarf_Type. Used to select between plain DWARF, split DWARF (.dwo/.dwp) and GNU LTO when opening a file. Added support for DWARF5 supplementary files (.debug_sup) and associated DW_FORM_ref_sup4/8 and DW_FORM_strp_sup forms. Added support for split DWARF debug data when contained in the same file as the skeleton. libdwelf: New functions dwelf_dwarf_debug_sup and dwelf_dwarf_debug_dwp for querying .debug_sup and .debug_dwp section data. libdwfl: Now correctly handles Linux kernel module sections that are not present in sysfs. libdwfl_stacktrace: New functions dwflst_arch_from_uname, dwflst_arch_expected_frame_nregs, dwflst_arch_sp_dwarf_reg and dwflst_arch_sp_perf_reg providing per-architecture constants. The libdwfl_stacktrace interface is experimental and may be subject to API/ABI changes. stackprof: New profiling tool for collecting systemwide stacktrace profiles. Replaces the eu-stacktrace tool. Requires a C++20 capable compiler. stacktrace: This experimental tool has been removed and replaced with eu-stackprof. srcfiles: Now handles CU names and files from split DWARF. strip: Fixed bug where a section's sh_link or sh_info reference could be missing from the debug file. version.h: New macro _ELFUTILS_THREAD_SAFE added to . Defined to 1 when the elfutils libraries are built with thread safety support enabled. Otherwise it is left undefined. Thread safety support is experimental and is not yet officially supported. - Skipped update to 0.195: CONTRIBUTING: elfutils has adopted a policy on the use of Large Language Models (LLMs). Contributions containing output generated by LLMs are not currently being accepted. debuginfod: Introduce --home-redirect and --home-html switches allowing for redirecting to custom URL and/or serving a custom html file, if document root is requested. Related: PR33635. New command line option --max-depth that limits scanner depth. Metadata queries now support lookup by build-id. New function debuginfod_default_progressfn added to libdebuginfod. debuginfod-find: Fixed bug where DEBUGINFOD_PROGRESS environment variable was ignored if debuginfod-find was invoked without -v. elflint: Recognize .debug_*.dwo sections, .relro_padding sections as well as SHT_AARCH64_ATTRIBUTES, SHT_LLVM_LTO and SHT_LLVM_ADDRSIG. Accept R_X86_64_DTPOFF64 in ET_REL files. Add lints for PT_LOAD, PT_INTERP and PT_PHDR segments. libdw: Added language constants for Erlang, Elixir and Gleam. Fixed bug that caused sections in DWARF package files (.dwp) to be missed if section .debug_dwp is present. libdwfl: Improved handling of Linux kernel object files with sh_addr fields set to non-zero. libdwfl_stacktrace: AArch64 and 32-bit ARM support added. The libdwfl_stacktrace library interface is experimental and may be subject to API/ABI changes. libelf: New man pages for gelf.h functions. Fixed gelf_getmove and gelf_update_move assertion failures caused by incorrect ELFCLASS32/ELFCLASS64 handling. elf_update now correctly handles binaries with 65280+ sections when section zero headers aren't loaded. readelf: Improved support for DWARF Package Files (.dwp) sections. Improved output format for .gcc_except_table. stacktrace: This experimental tool is scheduled to be removed in the next release and replaced with the upcoming eu-stackprof tool. - Remove upstreamed patch: * elfutils-fix-const-correctness.patch - Add upstream patch to fix build on aarch64 Leap 16.0: * fix_aarch64_build.patch ==== emacs-jinx ==== Version update (2.10 -> 2.11) - Update to version 2.11: * New command jinx-occur which lists all misspelled words in a separate buffer ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Add aptx/aptx_hd to enable_decoders/encoders. - Adjust work-around-abi-break.patch to support a few programs (e.g. OpenJFX) built against unmodified ffmpegs. [boo#1282855] - Enable apv encoder support, add pkgconfig(oapv) BuildRequires and pass enable-liboapv to configure. - Correct version in "mini" part of spec. - Add ability to disable ABI work-around patch using --without switch ==== glibc ==== Subpackages: glibc-devel glibc-extra glibc-gconv-modules-extra glibc-locale glibc-locale-base - resolv-search-list-trunc.patch: resolv: Fix assertion failure on search list truncation (CVE-2026-8674, bsc#1281297, BZ #31026) - elf-origin-open-normalized.patch: elf: Open the normalized $ORIGIN rpath in AT_SECURE programs (CVE-2026-86805, bsc#1282509, BZ #34360) - power8-strncasecmp-overread.patch: powerpc: Fix one byte overread in strncasecmp (CVE-2026-97399, bsc#1283147, BZ #34683) - realloc-mmap-non-mremap.patch: realloc: Fix mmap non-mremap reallocation case (BZ #34697) ==== inn ==== - Drop obsolete -fstack-protector from CFLAGS (added 2006, predates distro - fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== kernel-source ==== Version update (7.2.8 -> 7.2.9) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.2.6-0018-smb-server-fix-tree-connection-leak-in-smb2_tr.patch (bsc#1012628 CVE-2026-98162 bsc#1283790). - Update patches.kernel.org/7.2.6-0022-nvdimm-pmem-keep-PREFLUSH-before-data-writes.patch (bsc#1012628 CVE-2026-98161 bsc#1283791). - Update patches.kernel.org/7.2.6-0235-staging-rtl8723bs-fix-mismatched-free-of-HalDa.patch (bsc#1012628 CVE-2026-98160 bsc#1283276). - Update patches.kernel.org/7.2.6-0392-firmware-arm_scmi-Publish-channel-state-before.patch (bsc#1012628 CVE-2026-93093 bsc#1284062). - Update patches.kernel.org/7.2.6-0394-firmware-arm_scmi-Quiesce-notifications-before.patch (bsc#1012628 CVE-2026-93091 bsc#1284033). - Update patches.kernel.org/7.2.6-0395-firmware-arm_scmi-Clean-up-channels-on-setup-f.patch (bsc#1012628 CVE-2026-93090 bsc#1284032). - Update patches.kernel.org/7.2.6-0396-firmware-arm_scmi-Free-transport-channel-on-ID.patch (bsc#1012628 CVE-2026-93089 bsc#1284031). - Update patches.kernel.org/7.2.6-0397-firmware-arm_scmi-Avoid-IDR-updates-while-clea.patch (bsc#1012628 CVE-2026-93086 bsc#1284024). - Update patches.kernel.org/7.2.7-002-wifi-mt76-mt7921-validate-CLC-firmware-records.patch (bsc#1012628 CVE-2026-98159 bsc#1283416). - Update patches.kernel.org/7.2.7-005-ppp_async-drop-the-errored-frame-instead-of-res.patch (bsc#1012628 CVE-2026-98158 bsc#1283933). - Update patches.kernel.org/7.2.7-011-EDAC-device_sysfs-Use-kstrtouint-for-poll_msec-.patch (bsc#1012628 CVE-2026-98157 bsc#1283792). - Update patches.kernel.org/7.2.7-013-drm-virtio-use-the-DMA-API-for-resource-backing.patch (bsc#1012628 CVE-2026-98156 bsc#1283982). - Update patches.kernel.org/7.2.7-014-accel-qaic-Address-potential-out-of-bounds-read.patch (bsc#1012628 CVE-2026-98155 bsc#1283288). - Update patches.kernel.org/7.2.7-015-nvme-rdma-fix-EIO-cleanup-order-in-queue_rq.patch (bsc#1012628 CVE-2026-98154 bsc#1283418). - Update patches.kernel.org/7.2.7-018-nvme-fix-racy-access-to-FDP-placement-id-array.patch (bsc#1012628 CVE-2026-98153 bsc#1283800). - Update patches.kernel.org/7.2.7-019-nvmet-rdma-fix-queue-leak-when-connect-backlog-.patch (bsc#1012628 CVE-2026-98152 bsc#1283755). - Update patches.kernel.org/7.2.7-023-bpf-Fix-REG-INVARIANTS-VIOLATION-on-speculative.patch (bsc#1012628 CVE-2026-98151 bsc#1283801). - Update patches.kernel.org/7.2.7-024-bpf-Fix-BPF_F_CPU-validation-for-sparse-CPU-IDs.patch (bsc#1012628 CVE-2026-98150 bsc#1283419). - Update patches.kernel.org/7.2.7-025-bpf-Fix-percpu-map-update-indexing-with-sparse-.patch (bsc#1012628 CVE-2026-98149 bsc#1283420). - Update patches.kernel.org/7.2.7-027-drm-gud-validate-GUD_ROTATION_0-is-present-in-s.patch (bsc#1012628 CVE-2026-98148 bsc#1283421). - Update patches.kernel.org/7.2.7-028-printk-Don-t-WARN-on-kthread_run-failure.patch (bsc#1012628 CVE-2026-98147 bsc#1283799). - Update patches.kernel.org/7.2.7-030-accel-amdxdna-reject-a-command-chain-that-carri.patch (bsc#1012628 CVE-2026-98145 bsc#1283422). - Update patches.kernel.org/7.2.7-031-accel-amdxdna-put-the-chained-BO-when-its-mappi.patch (bsc#1012628 CVE-2026-98144 bsc#1283423). - Update patches.kernel.org/7.2.7-034-accel-ethosu-Don-t-read-the-U65-rounding-mode-a.patch (bsc#1012628 CVE-2026-98143 bsc#1283430). - Update patches.kernel.org/7.2.7-036-drm-cirrus-qemu-Validate-BAR0-size-during-probe.patch (bsc#1012628 CVE-2026-98142 bsc#1283819). - Update patches.kernel.org/7.2.7-038-ntfs-propagate-reparse-index-insertion-failure.patch (bsc#1012628 CVE-2026-98141 bsc#1283431). - Update patches.kernel.org/7.2.7-042-ntfs-fix-kmap_local-leak-in-write_mft_record_no.patch (bsc#1012628 CVE-2026-98140 bsc#1283417). - Update patches.kernel.org/7.2.7-043-ntfs-only-count-successfully-cleared-runs-when-.patch (bsc#1012628 CVE-2026-98139 bsc#1283433). - Update patches.kernel.org/7.2.7-045-ntfs-do-not-mark-the-volume-clean-in-sync_fs-wh.patch (bsc#1012628 CVE-2026-98138 bsc#1283440). - Update patches.kernel.org/7.2.7-046-ntfs-treat-any-nonzero-dio-zero-range-return-as.patch (bsc#1012628 CVE-2026-98137 bsc#1283441). - Update patches.kernel.org/7.2.7-047-ntfs-bound-AttrDef-table-walk-to-the-loaded-tab.patch (bsc#1012628 CVE-2026-98136 bsc#1283442). - Update patches.kernel.org/7.2.7-048-ntfs-reject-invalid-sectors_per_cluster-in-the-.patch (bsc#1012628 CVE-2026-98135 bsc#1283434). - Update patches.kernel.org/7.2.7-049-bpf-check_cond_jmp_op-properly-infer-if-registe.patch (bsc#1012628 CVE-2026-98134 bsc#1283839). ... changelog too long, skipping 1926 lines ... - commit f0bad6b ==== libbacktrace ==== Version update (1.0+git20260601 -> 1.0+git20260903) - Update to version 1.0+git20260903: * New optional MOREDATA flag for backtrace_create_state, reported via BACKTRACE_SUPPORTS_MOREDATA: the callbacks then receive a struct backtrace_moredata carrying the DWARF path discriminator and the declaration line of each frame, not the plain data pointer. The int argument was previously named THREADED and is now a flags word; bit 1 keeps the old threaded meaning, so callers passing 0 or 1 are unaffected. No new exported symbols and no ABI change. * Reading zstd-compressed debug sections no longer fails on compressed blocks that do not set the single segment flag, and RLE sequences now populate the sequence table. ==== libstorage-ng ==== Version update (4.5.359 -> 4.5.360) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Slovak) (bsc#1149754) - 4.5.360 ==== ncurses ==== Version update (6.6.20260919 -> 6.6.20260926) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20260926 + in-progress work to add new mouse functions mouse_get(), mouse_test(), and mouse_mask(), as well as mousetest(). + add attr_set.3x and attrset.3x to man_db.renames (patch by Sven Joachim). ==== nvidia-open-driver-G07-signed ==== Version update (595.104.02_k7.2.8_1 -> 595.104.02_k7.2.9_1) Subpackages: nvidia-open-driver-G07-signed-kmp-64kb nvidia-open-driver-G07-signed-kmp-default - Fix determining the kernel source directory path - fixed build against renamed -nvidia64kb flavor (bsc#1282794) - spelling police - added CVE numbers for security releases 595.91.07/615.71.09 (bsc#1270255) ==== nvidia-open-driver-G07-signed-cuda ==== Version update (615.71.09_k7.2.8_1 -> 615.71.09_k7.2.9_1) Subpackages: nvidia-open-driver-G07-signed-cuda-kmp-64kb nvidia-open-driver-G07-signed-cuda-kmp-default - Fix determining the kernel source directory path - fixed build against renamed -nvidia64kb flavor (bsc#1282794) - spelling police - added CVE numbers for security releases 595.91.07/615.71.09 (bsc#1270255) ==== openSUSE-release ==== Version update (20261003 -> 20261007) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== passt ==== Version update (20260612.a9c61ff -> 20261002.cba3570) Subpackages: passt-apparmor passt-selinux - Drop qrap from %files, removed upstream - Update to version 20261002.cba3570: * tcp: Don't fast re-transmit if only our FIN is outstanding * apparmor: Fixes for new user namespace detaching procedure * util: Make setting uidmap and gidmap errors non-fatal * selinux: Allow passt to use setgid and setuid capabilities in namespace * apparmor: allow netns paths on /tmp again * udp: Add missing @now parameter doc to udp_flow_from_tap() * apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only * pasta: Add --no-pidns to keep spawned command in caller's PID namespace * contrib/apparmor: add missing setfcap capability * vhost_user: Reset vq enable flag in vu_cleanup() * Add Zed editor settings * util, pasta: Remove some unneeded #includes * util: Add missing O_CLOEXEC for !HAS_GETRANDOM path * util: Eliminate a stray trailing whitespace * clangd: Add _GNU_SOURCE to default clangd options * udp_flow: Remove obsolete comment * parse: Convert parse_mac() to conventions of parse.c * isolation: Don't create our userns as nobody * isolation: Create helper function to enter user namespace * util, pasta: Generalise [ug]id_map creation * pasta: Include pasta.h in pasta.c * netlink: Don't warn about multiple interfaces when there's only one * isolation: Include linux_dep.h for close_range() * fwd: Don't log warnings when failing to bind "weak" ports, just debug messages * treewide: Sandbox qrap * conf, fwd: Prefer same-scope address as inbound source address from host * conf: Honour --address, --gateway, --netmask in local mode as well * pasta: Regression test for bug 216 * pasta: Do not configure ID mappings when invoked with --netns-only * pif: Add message to static_assert for C11 compliance, fix build with gcc 8 * udp, icmp: Remove unused timer_run fields from protocol contexts * main: Ensure fds 0-2 are populated * isolation: Move --fd descriptor to a number of our choosing * conf: Make conf_tap_fd() operate more like conf_mode() * isolation, conf: Set c->fd_tap from early parse of --fd * isolation: Move close_open_files() to isolate_fds() * passt: Always close pidfile_fd, not just when daemonizing * tap: Fix EAGAIN/EWOULDBLOCK check in tap_pasta_input() * passt.1, pesto.1: ::1 is an address, not a port * dhcp: Make option parsing more robust, explicitly handle options 0 and 255 * CONTRIBUTING.md: The tag is "Link:", regardless of how many we have * udp_vu: Check iov_tail_clone() return before assigning to msg_iovlen * passt: Initialise listening socket fds to -1 * fwd: Don't rewrite inbound multicast destinations * fwd: Reorder DNAPT and SNAT steps in fwd_nat_from_host() * fwd: Rework default address logic for inbound flows * udp: Validate that we have a unicast source address * fwd: Clarify semantics of --host-lo-to-ns-lo * dhcpv6: Fix reply destination to match client's source address * selinux: Access to netns for podman-build, read access for netns in general * isolation: Add --chroot-fallback option * fwd, fwd_rule: Implement configurable target address mapping * fwd_rule: Parse target addresses for forwarding rules * fwd_rule: Rewrite forward rule parsing using parse.c helpers * fwd_rule: Allow "all" port specs to be combined with other options * conf: Use new parsing tools to handle -a option * conf: Remove unnecessary mode checks from conf_addr() * conf: Move address configuration into helper function * parse: Add helpers for parsing IP addresses * parse: Move parse_port_range() to new parsing framework * parse: Add helper to parse unsigned integer values * conf: Clean up conf_ip4_prefix() * conf: Remove duplicate parsing of -F option * parse: Start splitting out parsing helpers * conf: Use parameter instead of global in conf_nat() * Makefile: Add missing PESTO_HEADERS variable * udp: Improve messages for errors getting errors * flow, treewide: Promote priority of selected flow-linked messages * flow, udp: Fix errno handling in udp_flow_sock() * flow: Include flow details with higher priority log messages * flow: Indent flow details messages * flow: Regularise flow specific logging helpers * tap: don't let overheard traffic move addr_seen when address is explicit * tap: Trim Ethernet padding from short IPv4 frames instead of dropping them * inany: Fix doc comment to match u32 field, not u64 * pif, util: Move listen(2) call from sock_l4_() to pif_listen() * fwd, pif: Remove duplicated logic between tcp_listen() and udp_listen() * Makefile: Remove unused DUAL_STACK_SOCKETS define * flow: Correct misleading signature of flowside_sock_l4() * tcp: MAX_WINDOW should be unsigned * tcp: Avoid SEQ_*() comparisons against 0 * tcp: Merge common sequence logic from tcp_{buf,vu}_data_from_sock() * cppcheck: Add workaround for cppcheck bug 14847 * cppcheck: Remove unused CPPCHECK_6936 ==== python-M2Crypto ==== Version update (0.49.0 -> 0.50.0) - update to 0.50.0: * switch to Codefloe * isolate OpenSSL providers in private contexts * disable legacy ENGINE bindings with OpenSSL 3 deprecations * manage BIO ownership when attaching to SSL connections * repair Windows CI pipeline and improve setup.py robustness * record security-related behavior changes * emit DeprecationWarning when RC4 cipher is instantiated * disable TLSv1.0 and TLSv1.1 by default * prevent out-of-bounds read in BN conversions * preserve errno from gettimeofday failures * restore timed read retries ==== python-dbus-python ==== - Drop obsolete -fstack-protector from CFLAGS (predates distro - fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== python-idna ==== Version update (3.19 -> 3.20) - update to 3.20: * Update to Unicode 18.0.0. * Better enforcement of the domain length limit in the incremental codec. * Add support for Python 3.15. ==== python-msgpack ==== Version update (1.2.2 -> 1.2.3) - Uppdate to 1.2.3: * Fix memory leaks in the C extension when map key validation or container hooks fail. See GHSA-j586-36cw-2gc2. * Fix use-after-free errors when cleaning up an incomplete or failed Unpacker.skip() after previously unpacking a nested object in the C extension. * Raise ValueError in the C extension when switching between unpacking, skipping, header readers, or read_bytes() while an object is incomplete. Resume with the same method after feeding more data; unpack() and iteration remain interchangeable. * Prevent reentrant unpacking, header reads, read_bytes(), and reinitialization of the same C Unpacker while unpacking is in progress. * Reject negative sizes in Packer.pack_array_header() and Packer.pack_map_header(). * Support packing Python 3.15 frozendict objects. * Update Cython from 3.2.5 to 3.3.0. * Build wheels for Pyodide using Emscripten. * Update cibuildwheel to 4.2.1 and the QEMU setup action to 4.4.0. ==== python-mysqlclient ==== Version update (2.2.8 -> 2.3.0) - update to 2.3.0: * Concurrent use of the same Connection object from multiple threads now raises ProgrammingError immediately instead of causing undefined behavior. Applications should use separate connections for concurrent operations. * Add an optional executemany_fallback="multi" connection option. When enabled, Cursor.executemany() can batch eligible INSERT, REPLACE, UPDATE, and DELETE statements into multi- statement queries instead of executing them one at a time. This can significantly improve performance of operations such as SQLAlchemy bulk UPDATEs. The default remains "loop", and the existing multi-row INSERT/REPLACE optimization is unchanged. * Add Cursor.warning_count to expose the warning count for the last statement. * Make Cursor itself an iterator as specified by DB-API 2.0. iter(cursor) is cursor and next(cursor) fetches the next row. * Quote stored procedure names and user variable names in Cursor.callproc(), allowing names containing reserved words or special characters. * Fix conversion of datetime.timedelta values to support microseconds and negative values correctly. * Add Windows ARM64 wheels. * Test with Python 3.15 and free-threaded Python 3.15, and update the MariaDB Connector/C used for Windows wheels to 3.4.9. * Add Connection.more_results() for checking whether additional results remain after a multi-statement query. * Deprecate accessing exception classes such as ProgrammingError and OperationalError as Cursor attributes. Access them from the MySQLdb package instead. * Deprecate the reconnect parameter of Connection.ping(). Calling ping() without the parameter is unchanged. ==== python-pycairo ==== Version update (1.29.1 -> 1.29.2) - Update to version 1.29.2: * Update dependencies (cairo 1.18.4 -> 1.18.6) for the Windows wheels - Update version dependencies according to meson.build. ==== python-tzdata ==== Version update (2026.2 -> 2026.5) - update to 2026.5: * Manitoba’s 2026-03-08 spring forward was its last foreseeable clock change, as it moved to permanent -05 thereafter. Model this with its traditional abbreviation EST. Although the change to permanent -05 legally takes place on 2026-10-31, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. * In 1925 Ireland fell back on 09-20 not 10-04 (thanks to Stan Ulbrych). * Discussion on timekeeping practices in northwestern Ontario has been expanded in light of Manitoba’s recent announcement. It is not yet known whether or to what extent these areas may adapt their own timekeeping practices ==== samba ==== Version update (4.24.6+git.488.e38f6c96c62 -> 4.25.0+git.473.e78e78fbf4) Subpackages: libldb2 python3-ldb samba-ad-dc-libs samba-client samba-client-libs samba-dcerpc samba-gpupdate samba-ldb-ldap samba-libs samba-libs-python3 samba-python3 samba-winbind samba-winbind-libs - Update to 4.25.0 * persistent handles options in WHATSNEW need fixups; (bso#16234). * Bugs in Persistent Handles database layer code; (bso#16237). * smbstatus byte-range locks broken by Persistent Handle changes; (bso#16253). * "getwd cache" removal needs more work; (bso#16233). * SMB3 SESSION SETUP responses must always be signed; (bso#15962). * winbindd_child_msg_filter: talloc_get_type_abort crashes when winbind max domain connections > 1; (bso#16081). * Fix parsing of uppercase "0X" hex values in the "kdc default domain supported enctypes" smb.conf parameter; (bso#16239). * smbd temporary mkdir name can exceed NAME_MAX for otherwise valid client names; (bso#16240). * Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k; (bso#15988). * autobuild failures need to be reported in a more verbose way; (bso#16194). * samba-cluster-support should depend on ndr-samba; (bso#16219). * DNS scavenging happens even if fAging is FALSE; (bso#16223). * samba-tool dns zoneoptions $DC_SERVER_IP _msdcs.addom.samba.example.com -P --aging=1 gives WERR_INTERNAL_DB_ERROR; (bso#16226). * dns client problems related to EDNS usage; (bso#16225). - Update to 4.24.7 * POSIX ACL backend silently discards erros when processing NT ACLs with non-canonical ordering; (bso#16097). * dns client problems related to EDNS usage; (bso#16225). * Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k; (bso#15988). * autobuild failures need to be reported in a more verbose way; (bso#16194). * DNS scavenging happens even if fAging is FALSE; (bso#16223). * samba-tool dns zoneoptions $DC_SERVER_IP _msdcs.addom.samba.example.com -P --aging=1 gives WERR_INTERNAL_DB_ERROR; (bso#16226). * Incorrect behavior on stream create-disposition when prior handle is closed; (bso#16144). * An inactive node can run recovery resulting in inconsistent databases; (bso#16082). ==== sdl12_compat ==== Version update (1.2.76 -> 1.2.78) - Update to release 1.2.78 * Fixed flickering in SimCity 3000 * Fixed stuttering during the intro video in Majesty: The Fantasy Kingdom Sim ==== sdl2-compat ==== Version update (2.32.72 -> 2.32.74) - Update to release 2.32.74 * Fixed mouse coordinates in the Mana client ==== selinux-policy ==== Version update (20261002 -> 20261006) Subpackages: selinux-policy-targeted - Update to version 20261006: * Fix typo in screen.fc * Allow cscreend to start screen as unconfined domain (bsc#1257101) ==== subversion ==== Subpackages: libsvn_auth_gnome_keyring-1-0 libsvn_auth_kwallet-1-0 subversion-bash-completion subversion-perl - Drop obsolete -fstack-protector from CFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== upower ==== Version update (1.91.3 -> 1.91.4) Subpackages: libupower-glib3 typelib-1_0-UpowerGlib-1_0 * Release 1.91.4 - Feature: Composite keyboard backlight device for unified brightness control (!341, !335) - Fix: Fix potential segmentation fault of the upower command (!340, #354) - Fix: Avoid updating full capacity from impossible charge-readings (!338, #351) - Fix: Stop I/O watch on keyboard backlight read error (!341) - Fix: Fallback to energy_full_design when energy_full is invalid (!333, !302, #336) - Fix: Fix up-version dupe warning while generating docs (!336) - Fix: Keep every battery of a device that has several (!337, #348) - Fix: Don't install polkit policy files when it is disabled (!342, #356) ==== vim ==== Subpackages: vim-data vim-data-common xxd - do not downgrade fortify level (we're anyway at 3 now which made this ineffective) ==== xapian-core ==== Version update (1.4.27 -> 1.4.32) - update to version 1.4.32 * API: + MSet::snippet(): Fix missing escaping when parameters hi_start and hi_end are empty strings and text.size() <= length. This is essentially a missed corner case from CVE-2018-0499. * Portability: + configure: `-Wstrict-overflow=1` is no longer added to the default compiler options for GCC and clang. This option has been a no-op since GCC 8 (and has always been a no-op for clang, provided only for GCC compatibility). + Fix -Wrestrict warning from GCC 16 + configure.ac: Use $SED consistently to improve portability to platforms where the installed sed tool isn't just called `sed`. + lemon: Fix bug in -D handling. We were allocating a buffer based on an unassigned variable. The Xapian build system doesn't currently use -D so this bug is latent for us but could result in C compiler warnings during the + Remove unused includes of and . + Remove __cplusplus conditional in a header only included from C++ code. - changes from version 1.4.31 * API + Database::get_spelling_suggestion(): Remove a flawed optimisation which was rejecting candidate corrections based only on how many n-grams match. + Database::compact(): FULLER compaction now does exactly the same as FULL. + Query: Attempting to construct a pairwise Query from an operator and two `char*` or `const char*` term names failed to compile because pointers are iterator types and matched the template which allows construction from a pair of iterators which are meant to dereference to give a type convertible to std::string or Xapian::Query or Xapian::Query*. We've solved this by only enabling this template for iterators where sizeof(value_type) is not 1. + QueryParser: Improve FLAG_PARTIAL handling for stopwords. + RangeProcessor: Don't require prefix/suffix on empty bound when flag RP_REPEATED is specified (so now `..$10` and `20kg..` work). Case noted by James Aylett in the "getting started" guide. + ValueRangeProcessor: Don't require prefix/suffix on empty bound. + Fix incorrect container and iterator traits for Xapian API classes. * Testsuite: + Extend generated tests to cover newer Xapian::Weight subclasses and Xapian::Utf8Iterator. * Glass Backend: + Compacting a database with corrupt item sizes could try to copy an item outside of the allocated block. Now we throw DatabaseCorruptError in this situation. + Opening a database table now throws DatabaseCorruptError if the number of levels is non-zero but the `fake_root` flag is set. * Tools: + quest: Add --stem-strategy option. + quest: List stemming languages in --help. + quest: List valid flags/query ops if an invalid one is specified. * Debug Code: + Fix build with `--enable-assertions=partial`. + Move an assertion that a pointer is not NULL to before where we dereference it. - changes from version 1.4.30 * API: + Stem: 1.4.28 changed the English stemmer code to remove an exception for "skis" which we incorrectly thought wasn't needed. This was not intended to be a functional change, so we've restored the exception. + Stem: Fix a bug in Snowball's runtime code for decoding 4-byte UTF-8 sequences. * Portability: + Fix instance of undefined behaviour in Database::check() for glass databases. - changes from version 1.4.29 * Build System: + 1.4.28 had its library version information incorrectly set - changes from version 1.4.28 * API: + Optimise stemming algorithms. + Add dutch_porter as alias for current dutch stemmer for forward compatibility with the next release series where we will have kraaij_pohlmann as the default dutch stemmer. ==== xdmbgrd ==== - Add patch for aarch64 since default detection no longer works for aarch64: * add-aarch64.patch ==== yast2-trans ==== Version update (84.87.20260923.cade5cf3bd -> 84.87.20261004.92ae53d41b) Subpackages: yast2-trans-af yast2-trans-ar yast2-trans-bg yast2-trans-bn yast2-trans-bs yast2-trans-ca yast2-trans-cs yast2-trans-cy yast2-trans-da yast2-trans-de yast2-trans-el yast2-trans-en_GB yast2-trans-es yast2-trans-et yast2-trans-fa yast2-trans-fi yast2-trans-fr yast2-trans-gl yast2-trans-gu yast2-trans-hi yast2-trans-hr yast2-trans-hu yast2-trans-id yast2-trans-it yast2-trans-ja yast2-trans-jv yast2-trans-ka yast2-trans-km yast2-trans-ko yast2-trans-lo yast2-trans-lt yast2-trans-mk yast2-trans-mr yast2-trans-nb yast2-trans-nl yast2-trans-pa yast2-trans-pl yast2-trans-pt yast2-trans-pt_BR yast2-trans-ro yast2-trans-ru yast2-trans-si yast2-trans-sk yast2-trans-sl yast2-trans-sr yast2-trans-sv yast2-trans-ta yast2-trans-th yast2-trans-tr yast2-trans-uk yast2-trans-vi yast2-trans-wa yast2-trans-xh yast2-trans-zh_CN yast2-trans-zh_TW yast2-trans-zu - Update to version 84.87.20261004.92ae53d41b: * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (German) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Japanese) * Translated using Weblate (Slovak) * Translated using Weblate (Dutch) * Translated using Weblate (Dutch) * Translated using Weblate (Japanese) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Slovak) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Update translation files * Update translation files * Update translation files * Update translation files * Update translation files * Update translation files * Update translation files * Update translation files * Update translation files ... changelog too long, skipping 74 lines ... * New POT for text domain 'add-on'. ==== zenity ==== - Update version dependencies according to meson.build.